The Senior IT Risk Officer is a risk and technical practitioner who can represent the IT Risk Management unit and facilitate IT risk management discussions with key relevant business/functional groups such as Information Technology, Information Security, Internal Audit, Data Privacy, and other control groups in balancing UnionBank's growth priorities and its IT risk posture. This role acts as a 2nd line of defense that performs (1) IT risk governance, (2) IT risk optimization, and (3) IT risk administration.
Duties And Responsibilities
IT Risk Governance
- Establish and implement IT Risk Management policy and procedure apt to the size and complexity of the business needs and requirements of the Bank.
- Operationalize and maintain the IT Risk Management program of the bank, including coordination and execution of activities to ensure risk assessments are performed.
- Recommend policy or procedural changes in-light of analyzed trends and systemic problems from IT risk exposures.
- Apprise and communicate IT risks to the IT Risk Management Head, executives, and business stakeholders through reports, dashboards, data analyses and materials.
IT Risk Optimization
- Design and implement IT Risk Management methodology by establishing appropriate tools to facilitate the IT risk identification, monitoring, assessment, mitigation, and risk reporting processes.
- Lead and execute the implementation of IT Risk Management tools.
IT Risk Administration
- Represent the unit in varying capacities and purpose, which may be assigned by the ITRM Head, in relation to IT Risk related matters.
- Support the ITRM Head in updating write-ups and carrying out any required internal/external reports and assessments.
- Perform other tasks and special projects as may be assigned by the ITRM Head, in relation to IT Risk Management activities of the Bank.
Qualifications
- Bachelor's degree in Accounting, Information Technology, Internal Audit, Business or any related field is required.
- Proficient in IT risk governance, risk assessment and management, compliance, cybersecurity, and IT general controls and audits.
- Experienced in finance and banking industry and its related rules, regulations, and compliance requirements.
- Experienced in cloud technology, cybersecurity, information security and IT service management.
- Knowledgeable in technology program and project management, data privacy laws and regulations, enterprise architecture, IT and cloud implementation, operations, and support, and other IT and cyber-related security processes, services, and best practices.
- Relevant experience in incident response and policy development is an advantage.
- Strong stakeholder management, communication and presentation skills.