AVP | Governance
Watermark - 410 North Scottsdale Road
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), the 7th largest financial group in the world. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.As part of an effective risk and control framework, Information Technology for the Americas (ITA) Risk and Control Office (RCO) documents and executes risk and control assessments across processes related to Technology functions. There is a comprehensive coverage and joint accountability model that promotes early identification and assessment of technology risk, effective design and evaluation of controls, and sustainable solutions to mitigate operational and technology risk.
The IT Governance Associate Vice President (AVP) will focus on implementing Information and Operations Risk governance frameworks designed to identify, evaluate, and report on risks and controls across the Technology function.
Responsibilities include integrating those frameworks with business operations and keeping key stakeholders across the organization informed of new or revised policies, standards and control objectives; supporting various programs, including risk and control self-assessment (RCSA); reporting on process, risk, control and procedure compliance, and Key Risk Metrics (KRMs) as well as maintaining governance control evidence and procedures.
RESPONSIBILITIES
Develop subject matter expertise to support the execution and documentation of framework governance controls for in-scope processes across technology and First Line of Defense (FLoD) business units
Partner with stakeholders, including process owners, Business Unit Risk Managers (BURMs) and control officers, to execute against framework governance procedures
Responsible for
Evaluating IT events, incidents, and losses against Threat scenarios
Performing Data Quality (DQ) reviews of risk and control or metric system of record data to ensure accuracy; communicating variances to stakeholders for review
Revise process documentation (procedures, job aids) for policy, standard, and/or control objective changes as needed
Support the
Administration of RCSA Triggers, ensuring stakeholder responses are clear, concise and timely.
Oversight of Technology procedures by ensuring timely reviews in compliance with policies, procedures, and regulatory requirements
Various assessment programs, quality control and related reporting
Iterative review and challenge of Governance controls, working with appropriate stakeholders across all lines of defense
Utilize project management tools to track and coordinate policy, standard, and/or control objective change reviews
Provide clear and concise communication to internal stakeholders throughout the process/project to keep them apprised of progress and findings, escalating when appropriate
Coordinate required meetings, reviews, and scheduling needs
QUALIFICATIONS
3-5 years experience in risk management at a bank / financial services organization
Bachelor's degree in business administration, computer science, information systems, technology management, or equivalent
Ability to adapt to an ever changing environment by ingesting multiple policies and standards and translating into viable implementation/action plans
Effective communication skills, both written and verbal
Strong analytic, planning, organizational skills, and attention to detail.
Strong Microsoft Excel skills; familiarity with Sharepoint; Experience with OpenPages or other governance, risk management, and compliance (GRC) management system
Experience drafting and publishing process documentation including procedures and workflows, and developing senior management reports/dashboards
Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities with limited oversight/information from inception to completion
Ability to identify obstacles and work in collaborative environments involving varying levels of management and employees to identify options/solutions
Preferred:
Project Management Professional (PMP) certification
Experience working with multiple IT risk and control domains such as identity and access management, network security, vulnerability management, audit logging, privacy, enterprise architecture, release management and incident response
Experience in evaluating and developing Key Risk Metrics (KRMs)
Experience providing development requirements for Tableau and Power BI dashboards
Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC)
Experience in IT external audit, IT internal audit and technology risk and/or ITGC assessment for compliance with Sarbanes-Oxley (SOX)
The typical base range for this role is between $88K and 111K per year depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.Tags: Business Intelligence CISA CISM Compliance Computer Science CRISC Governance IAM Incident response Network security Privacy Risk management SharePoint SOX Vulnerability management
Perks/benefits: Career development Competitive pay Health care Medical leave Parental leave Salary bonus Team events Wellness
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Penetration Tester jobs
- Open Cloud Security Architect jobs
- Open Security Operations Engineer jobs
- Open Principal Security Engineer jobs
- Open Information Security Officer jobs
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Senior Product Security Engineer jobs
- Open Chief Information Security Officer jobs
- Open Cyber Security Architect jobs
- Open IT Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Staff Security Engineer jobs
- Open Cyber Security Specialist jobs
- Open Security Specialist jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Senior Network Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Security Consultant jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Security Operations Analyst jobs
- Open Manager Pentest H/F jobs
- Open Information Security Architect jobs
- Open Information System Security Officer jobs
- Open Agile-related jobs
- Open Risk assessment-related jobs
- Open SOC-related jobs
- Open Network security-related jobs
- Open Analytics-related jobs
- Open CISA-related jobs
- Open ISO 27001-related jobs
- Open GCP-related jobs
- Open IAM-related jobs
- Open Application security-related jobs
- Open Pentesting-related jobs
- Open Threat intelligence-related jobs
- Open Vulnerability management-related jobs
- Open DoD-related jobs
- Open DevOps-related jobs
- Open Security Clearance-related jobs
- Open CEH-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open SaaS-related jobs
- Open Malware-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Java-related jobs
- Open TS/SCI-related jobs