Cr\xc3\xa9dit Agricole CIB is the corporate and investment banking arm of Cr\xc3\xa9dit Agricole Group, the 10th largest banking group worldwide in terms of balance sheet size (The Banker, July 2022).
8,600 employees in more than 30 countries across Europe, the Americas, Asia-Pacific, the Middle-East and North Africa, support the Bank\'s clients, meeting their financial needs throughout the world.
Cr\xc3\xa9dit Agricole CIB offers its large corporate and institutional clients a range of products and services in capital market activities, investment banking, structured finance, commercial banking and international trade.
The Bank is a pioneer in the area of climate finance, and is currently a market leader in this segment with a complete offer for all its clients.For more information, please visit www.ca-cib.comTwitter: https://twitter.com/ca_cib
LinkedIn: https://www.linkedin.com/company/credit-agricole-cib/By working every day in the interest of society, we are a group committed to diversity and inclusion. All our positions are open to people with disabilities.Reference 2024-88260Publication date 17/04/2024Job descriptionBusiness typeTypes of Jobs - IT, Digital et DataJob titleTechnology Risk Officer (59713)Contract typePermanent ContractJob summaryRole Description:
The candidate is a 2nd LoD technology risk manager who is responsible for ensuring identification, assessment, and mitigation of technology-related risks and reporting independently risks, concerns and impact to Credit Agricole CIB SGP management via the SGP ORM channel. This involves collaborating closely with the IT application and infrastructure; Information Security stakeholders to address IT risk challenges (technology risk management framework, risk & control self-assessment) and strengthen risk culture across organization.:
1. Support the Head of ISAP IT Operations Control (IOC) in the overall effective and proactive management of technology risk and controls to ensure quality of internal control system of CACIB SGP.
2. Work closely with IT stakeholders to ensure existing Technology Risk Management Framework is regularly updated and maintained, and IT policies, procedures, and processes alignment with MAS Technology Risk Management (TRM) guidelines.
3. In order to identify potential threats and vulnerabilities in the IT infrastructure and systems conduct regular technology risk assessments on: a. Operational process and resiliency, b. Data and infrastructure security, c. Project management and application developments d. Cyber security set-up, e. IT infrastructure inventory (CMDB)
4. Drive, discuss and challenge when necessary risk assessment and adequacy of controls performed by stakeholders and IOC whilst building strong and constructive relationships with stakeholders.
5. Conduct periodic review on level of compliance with TRM guidelines as well as provide independent view to CACIB SGP Management via SGP ORM channel on the results of controls performed and RCSA assessment, recommendations for improvement and major technology risks and concerns
6. Design and implement technology risk metrics to highlight the risk exposure of information assets (data, hardware and software).
7. Promote awareness of risk among IT stakeholders and senior management and conduct training programs on technology risks trends to strengthen risk culture of CACIB SGP
8. Independently review and enhance the quality of CACIB SGP management oversight on technology risk topics as stipulated in the MAS TRMG
9. Contribute to the quality of reporting in CACIB SGP Permanent Control Committees and Internal Control Committees in relation to technology and cybersecurity related risks
10. Provides interpretation on technology risk management related banking regulations and corresponding circulars and guidelines
11. Ensures new regulatory Notices and its corresponding advisories / circulars / guidelines are being followed-up and duly analyzed for any gaps in implementation
12. Review and provide independent opinion on technology and cybersecurity risk related documents prior to their communication or submission to the MASSupplementary InformationQualifications1. University degree in information technology, computer science, or a related field2. Open to change as the team continually adopts strategy to meet evolving regulatory and controls landscape.3. Strong interpersonal, collaborative, and influencing skills required to drive active and robust stakeholder engagement.4. Good integrity, motivated and able to provide independent opinion to functional line5. Good understanding of regulatory requirements, such as MAS Technology Risk Management, Outsourcing and Notice 644, 655, 658, etc.6. At least 10 year of experience inIT domains and IT risk assessments & controls (including RCSA), and exposure to internal & external audits including regulatory inspectionsKnowledge of the banking industry is a plus.7. Autonomous, delivery focused and able to work in a fast-paced environment and tight deadlines without compromising attention to details whilst being capable of elaborating synthesis.8. Hands-on experience in the following infrastructure technology, would be desirable: servers platform, middleware technologies, micro services, virtualization, network, and database9. Strong knowledge of IT security principles, best practices, and controls10. Practitioner and holder of IT risk certification, such as CISSP, CISA, or CRISC is a requirement11. Candidate is required to liaise with French speaking stakeholders. Knowledge of French is essential.
MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.