The ideal candidate will have a strong background in controls testing within financial services and excellent analytical and problem-solving skills.
Key responsibilities:
- Design and execute controls testing strategies to evaluate the design adequacy and operating effectiveness of controls.
- Create test plan, test scripts etc. to support the delivery of GCIO controls assurance objectives.
- Prepare detailed testing documentation, workpapers and reports to highlight findings and recommendations.
- Collaborate with various departments within GCIO for control walkthroughs, sampling, evidence collection etc.
- Maintain up-to-date knowledge of industry standards and best practices related to controls testing.
- Support the creation of GCIO Controls Assurance management information (MI)
- Participate in audits and assessments, providing support and insights as needed.
- Provide training and support to junior team members on controls testing methodologies.
- Support Controls Assurance Lead to continuously identify and implement improvements within the assurance framework.
Skills Experience Required
- 8-10 years experience in controls testing and/or internal audit.
- Strong understanding of industry standards like NIST and ITIL
- Excellent analytical and problem-solving skills
- Strong understanding of regulatory requirements and industry best practices related to controls assurance, relevant to GCIO risks - such as Information Technology (IT), Information Security (IS), and/ or Data Management
- Exceptional communication skills, both verbal and written, with the ability to influence and engage stakeholders at all levels.
- Experience operating in a regulated environment and managing stakeholders across the Three Lines of Defense.
- Strong organization skills and attention to detail.
- Familiarity with cyber security, resilience and related domains preferred.
- Prior experience with Service Now Integrated Risk Management (SNOW - IRM) preferred.
Qualifications
- Bachelor s degree in Information Technology (IT), Computer Science, or a related field; relevant certification (e.g., CISA, CISSP) preferred.