Posted By

user_img

Snigdha Singh

Client Manager at ABC Consultants

Last Login: 25 April 2024

178

JOB VIEWS

30

APPLICATIONS

2

RECRUITER ACTIONS

Job Code

1230876

AVP - Operational Risk Officer - BFS

12 - 17 Years.Chennai/Others
Posted 1 year ago
Posted 1 year ago

Responsibilities :

- Take ownership of the day-to-day management of the Group Technology Policy including managing the annual refresh cycle, annual policy effectiveness review and other related activities for policy management such as reviewing dispensation requests, fielding policy queries, building and executing training and awareness plans and materials, and ensuring traceability to IT standards, processes and controls for policy effectiveness measures.

- The role is key in driving attention to key-risk areas based on how prevailing risk information supports the view of policy effectiveness, particularly providing a view of prioritisation for Second Line Assurance and RCSA trigger reviews.

- In addition, the key responsibility for day-to-day policy management, the individual will have the opportunity to contribute to other OR activities performed by the wider team of second line operational risk officers:

- Risk Appetite - Provide support for monitoring risk outcomes are within Technology Risk appetite and challenge the appropriateness of treatment actions. Provide subject matter expertise in improving risk information in support of Risk Appetite.

- Scenario Analysis - Provide support for selecting appropriate scenarios, help drive workshop outcomes with other members of an expert panel and challenge appropriateness of the analysis outcomes in support of the OR-led ICAAP.

- Risk & Control Self-Assessments (RCSA) - Challenge key RCSA steps including Risk Assessments, Control Designs against Standards, Treatment Plans, Annual Reviews and Top Down Reviews. Ensure assessments are completed timely and final approvals are obtained within the required approval authorities for Elevated Risks and Treatment Plans.

- Response Framework - Challenge the 1st Line of Defence assessment of impact and treatment actions for materialised operational risk events (OREs). Challenge the appropriateness of Root Cause Reviews (RCRs) for Material Risk Events (MREs). Ensure OREs and RCRs are completed timely and final approvals are obtained within the required approval authorities for MREs.

- Committee Reporting - Provide support to Group Operational Risk Heads on actionable insight into Technology Risk matters that would benefit from escalation to Business and Function Non-Financial Risk Committees.

- Regulatory Reporting - Keep informed of regulatory developments in Technology Risk matters. Provide support for information requests on an as-needed basis.

- Change Risk Assessments - Challenge the 1st Line of Defence assessment of change delivery risks and the appropriateness of go-live readiness checks for prioritised projects.

- Second Line Assurance - Perform thematic and targeted assurance reviews for prioritised areas.

- Horizon Risk - Contribute to horizon risk scanning activities performed by Group Operational Risk and support if needed the 1st Line of Defence equivalent activities.

Provide support or act as an advocate for the wider Group Operational Risk activities:

- OR Systems and Infrastructure - Help to ensure the data quality of risk information held in the OR supporting systems(s). Get involved as needed in user acceptance testing and contribute to ideas for feature enhancements.

- Training & Awareness - Help promote the wider training available via the Group Operational Risk function and contribute as required to development of materials. Get involved as needed in developing or running training for Technology Risk.

- AskOR - Support AskOR colleagues in resolving any queries directed to the Technology Risk OR sub-risk type Risk Framework Owner delegate.

- Event Accountability (Behavioural Feedback Surveys) - Provide support on an as-needed basis for Event Reviews (i.e. Conduct accountability) for Materialised Risk Events and Behavioural Feedback for Material Risk Takers.

Key Stakeholders :

- Enterprise Risk Management, Policy Management

- TTO Technology Governance

- TTO owners of IT Standards

- TTO Technology Process Owners and Teams, via OR contacts as needed

- TTO Risk & Control Teams

- TTO CIO Domain Teams

- Group Operational colleagues

- Other Policy Owners and delegates that connect to the Technology Policy (e.g. Operational Resilience, Information & Cyber Security, End User Computing, etc).

Our Ideal Candidate :

- Demonstrate experience and exposure to policy formation and policy management.

- Comfortable working in a single contributor role and/or small team challenging risk-decisions made by more senior staff.

- Able to demonstrate a risk-based approach to focus attention on the key risks and sound judgement on matters that can be dealt with autonomously versus matters that require escalation.

- Comfortable looking beyond a purely task-driven approach and able to take ownership of the wider objective, while seeking for support when required.

- Passionate about keeping abreast of industry developments in technology risk and keen to advance their own subject matter expertise by seeking personal growth opportunities.

- Able to demonstrate Advanced (Band 5b) level of competency in Critical Thinking, Non-Financial Risk Management including Operational Risk, Managing Change and Stakeholder Management.

- Able to demonstrate previous experience in technology risk roles (1st, 2nd or 3rd line of defence) and/or practical hands-on experience in delivering technology solutions or technology support with a view to make a career move into a risk role. Candidates with experience in other non-financial risk disciplines are also encouraged to apply if able to demonstrate a strong interest and understanding of technology risk.

- Minimum 12 years' experience in financial institutions and/or highly regulated technology dependent industries.

- Experience in advisory, audit, or consulting roles that require strong stakeholder management an advantage.

- Professional Certifications related to technology risk (e.g. ISACA CRISC, CGEIT, CISA) an advantage.

- Profession Certifications related to project management, software delivery lifecycles, technology processes (e.g. ITIL) an advantage or equivalent practical "on the job" experience.

- Familiarity with modern and emerging technology techniques and an interest to stay abreast of industry developments (e.g. Agile development, DevOps, Cloud, APIs, service-orientated architectures etc).

Didn’t find the job appropriate? Report this Job

Posted By

user_img

Snigdha Singh

Client Manager at ABC Consultants

Last Login: 25 April 2024

178

JOB VIEWS

30

APPLICATIONS

2

RECRUITER ACTIONS

Job Code

1230876

UPSKILL YOURSELF

My Learning Centre

Explore CoursesArrow