Description
CYBER & TECHNOLOGY RISK ANALYST SR
WHAT IS THE OPPORTUNITY?
The Senior Cyber and Technology Risk Analyst will oversee second line of defense End User Developed Application (EUDA) Governance Program. End-user Developed Application is an application developed and managed by end-users, such as but not limited to using spreadsheet programs (e.g., Microsoft Excel), database management programs (e.g., Microsoft Access).
The Senior Analyst will help champion the EUDA program by acting as a critical partner guiding stakeholders to embed risk management practices. Position will identify, analyze and report enterprise technology risks for executive level business, Cyber, Technology and information security leadership. The work product will be shared with the Audit and Risk Committee, Royal Bank of Canada, and CNB's regulators. The Senior Analyst will also perform challenge and oversight of the First Line of Defense as a member of the Second Line of Defense.
WHAT WILL YOU DO?
- Acts as a liaison with all three lines of defense to enhance EUDA governance program.
- Analyzes, evaluates and provides strategic guidance and direction for EUDA program to ensure alignment with regulatory requirements and acceptable risk mitigation practices.
- Develops, implements and monitors appropriate EUDA controls and procedures reflecting the standards set forth in the policies and Regulations while accounting for risks inherent in the products, services, types of customers, locations of customers, and functions of the Business Unit.
- Identifies gaps in controls, proposes solutions, and implements corrective actions.
- Drives projects to implement the necessary changes to policy, procedures and processes in order to align the Business Unit(s) to the Operational Risk practice standards.
- Effectively partners with line of business and needed business areas to solicit information and to mitigate risk.
- Provides support for regulatory examinations and audits by ensuring all requested documentation and information is provided.
- Reports to management on developments and risks/issues identified within assigned programs.
- Regularly provides reports to Manager and Program heads on progress.
- Supports Manager and Business Unit team members in the reporting and resolution of Risk related issues.
WHAT DO YOU NEED TO SUCCEED
Must-Have*
- Bachelor's Degree or equivalent
- Minimum 7 years of experience in Cyber and Technology risk assessment and analysis
- Minimum 4 years of experience with eGRC or equivalent risk or security management system
- Minimum 4 years working for a bank or financial institution.
Skills and Knowledge
- Prior experience with End User Developed Application (can be referred to as End User Computing).
- A plus in being able to manage or supervise a small team for project delivery
- Prefer experience in a Risk Management (2LOD) department along with at least 4 years in banking or financial services, or equivalent experience in a consulting capacity.
- Prefer experience with internal control frameworks for information technology, information security, IT governance frameworks, and conducting and analyzing cyber and technology risk assessments.
- Must be able to effectively articulate ideas through verbal and written communications.
- Experience with MS Excel, Word, PowerPoint, and eGRC systems, such as Archer or RSAM
- Prior experience analyzing and applying regulatory requirements to security practices.
- Familiarity with changes and trends in the regulatory landscape
- Demonstrated organization, facilitation, communication, and presentation skills.
- Demonstrated ability to lead and execute across a range of businesses and functions with differing issues and interdependencies.
- Experience in designing and executing management testing of key controls, evaluating controls for design effectiveness, operating effectiveness, and efficiency.
*To be considered for this position you must meet at least these basic qualifications
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job. Benefits and Perks At City National, we strive to be the best at whatever we do, including the benefits and perks we offer our colleagues. Get an inside look at our Benefits and Perks. INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENT
City National Bank is an equal opportunity employer committed to diversity and inclusion. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status or any other basis protected by law.' ABOUT CITY NATIONAL We start with a basic premise: Business is personal. Since day one we've always gone further than the competition to help our clients, colleagues and community flourish. City National Bank was founded in 1954 by entrepreneurs for entrepreneurs and that legacy of integrity, community and unparalleled client relationships continues to drive phenomenal growth today. City National is a subsidiary of Royal Bank of Canada, one of North America's leading diversified financial services companies.
Apply on company website