
Tech Risk and Controls Lead
- São Paulo - SP
- Permanente
- Período integral
- Oversee how Infrastructure Platforms International Latin America & Canada organization adopts technology to support, enable and enhance its business objectives while complying with the Firm's global policies and it's regulatory compliance requirements.
- Understand complex regulatory and internal security requirements and be able to advise on implementation options.
- Establish and maintain strong relationships with internal and external stakeholders, including key cross-functional team leads, regulators, and auditors, to ensure compliance with legal, regulatory, and industry standards.
- Develop and maintain an understanding of IP product/platforms teams strategies, product roadmaps and key investment programs.
- Apply working experience in multiple security or risk management domains (e.g., application security, vulnerability management, data protection, encryption, logging and monitoring, network security).
- Identify technology risk impacting the business that is quantified, communicated, and managed, including recommendations for resolution, and identifying the root cause/key themes.
- Partner with Third Party Oversight teams to ensure effective vendor risk management.
- 5+ years of experience or equivalent expertise in technology risk management, information security, or related field, emphasizing risk identification, assessment, and mitigation.
- Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements.
- Proficient knowledge and expertise in data security, risk assessment & reporting, control evaluation, design, and governance, with a proven record of implementing effective risk mitigation strategies.
- Ability to work with data from disparate sources to build a cohesive view on risk.
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives.
- CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are preferred
- Risk management knowledge in public cloud provider (AWS, GCP, Azure) services