Operational Risk Manager – Cybersecurity Risks

4 months ago


Montreal, Canada SGS Société Générale de Surveillance SA Full time

Responsibilities

The Risk Management Department contributes to the sustainable growth of the Societe Generale group through its expertise, understanding of risks, and risk management techniques. The department’s mission is to independently analyze, assess, manage and monitor risk-taking activities with the objective of achieving, together with the first line-of-defense, the best possible outcome for the bank. The department oversees the enterprise, strategic, credit, market, liquidity, operational, model, and other risks of the corporate and investment banking business activities.

Independent from the Business Lines, the Risk Management (RISQ) Division's mission is to contribute to the development of the SG Group's activity by facilitating the objectives of the Business Lines while maintaining independent oversight through risk evaluation and monitoring. The RISQ division in the US supports all the activities in the Americas Region (US, Canada and Latin America), which is almost exclusively corporate and investment banking (GBIS) oriented.

ABOUT THE JOB:

The Head of Cybersecurity Risk is looking to hire a Cybersecurity Risk Manager that will join the RISQ/OPE organization to help further define the 2nd line of defense processes, policies and tools for SG’s data and technology environments. Cyber risk coverage areas include Reference data, transaction processing, digital transformation (cloud), threat intelligence, Identity and Access Management, data protection and cybersecurity incident/response.

This role is responsible to evaluate overall cybersecurity risk, maintain an active view, and report on the actual, mitigated, and residual cybersecurity risk in the organization. This resource will also help further define the Cybersecurity Risk 2nd line of defense practices including, but not limited to assessments, life-cycle practices, operational incident/response, service delivery, and BCP. This is an individual contributor role.

What will be your DAY-TO-DAY?

Day to day responsibilities include but not limited to:

  1. Perform full range of technology and information and cyber security risk management lifecycle activities, including risk identification, assessment, reporting and oversight of remediation planning and execution. E.g. third-party, application, database, infrastructure, network penetration testing, etc.
  2. Partner with Chief Information Security Officer (CISO), and IT organizations to establish standards, policies, and develop KRIs and KPIs for measuring and monitoring cyber risks on a continuous basis.
  3. Developing and managing Information Technology & Information Security Risk Program, using standard risk taxonomy, such as FAIR.
  4. Provide and perform independent assurance and validation activities over common cybersecurity controls that include both administrative and technical.
  5. Assess the accuracy, completeness, and sufficiency of the risk management governance framework, processes and methodologies. Identify and define emerging cyber threats and risks to SG’s environment.
  6. Perform effective challenge of all critical and highly sensitive processes & controls, and business continuity.
  7. Develop cyber security risk scenarios to identify potential attack vectors and TTP (tactics, techniques and procedures) to guide the continuous improvement of firm’s cyber defense posture. Lead and support selected cyber security remediation efforts, involved with strategic planning with 1LOD.
  8. Recommend enhancements to data & technology architectures, processes and controls to improve cybersecurity, data and technology risk management capabilities for high-risk processes, regulatory reporting and risk oversight.
  9. Develop and roll-out tools for the aggregation and surveillance of cybersecurity risk, data risk & technology risk.
  10. Identify legal, regulatory, and contractual requirements, and organizational policies and standards related to data management systems to determine their potential impact on the business objectives.
  11. Expand operational risk processes, data collection and issues management tools to track and report data related operational risks and issues.
  12. Participate in and review data breaches and technology incident/response escalation processes.
  13. Develop operational resiliency scenarios for stress testing and capital planning activities.
  14. Lead or support selected cybersecurity remediation efforts.

Profile required

Must Have:

  1. Bachelor and or master’s degree in computer science, Engineering or relevant technical field.
  2. Understanding of financial services specifically within cyber and data privacy related laws, regulations, frameworks and guidelines (NYSDFS - 23NYCRR500, ECB, GDPR, GLBA, Regulation S-P, etc.).
  3. Experience in assessing design and operating effectiveness of technology controls.
  4. Solid foundation in information technology and information security principles. Familiar with common cybersecurity frameworks and standards such as NIST SP 800-53, NIST CSF, Mitre Attack, FFIEC CAT, CSC Top 20, COBIT, ISO 27000 series.
  5. Previous working experiences in cybersecurity operation and relevant security design knowledge.
  6. Previous work within Risk and/or Information Security/Cyber Security. Ideally, has worked in a 2 LOD Cyber Security Risk function.
  7. Background in IT Risk Assessment, IT Audit, Information security management.
  8. Experience integrating vulnerability and patch management tools with IT/IS risk program. Furthermore, communicate and determine vulnerability remediation priorities.
  9. Knowledge of US IT Security regulatory requirements and environment in financial services industry a plus (i.e. FFIEC, FINRA rules, SEC, NIST cybersecurity frameworks).
  10. Strong leadership skills with ability to lead by influence.

Nice to Have:

  1. IT Risk management or governance certifications (CGEIT, CRISC, CISA).
  2. CISSP, CISM, or CISA certifications.

LANGUAGE:

Ability to communicate in English, both orally and in writing, is a requirement as the person in this position will need to collaborate regularly with colleagues and partners in the United States.

Due to US Federal Securities law applying to this position, candidates who will apply for this position will be required to submit to an enhanced background screening, including the collection of their fingerprints by a third-party vendor selected by the Financial Industry Regulatory Authority ("FINRA").

OUR BENEFITS:

Competitive compensation & benefits offering, including but not limited to:

  • Minimum of 20 Vacation days+ 4 personal days
    • Supportive Maternity, paternity, parental and adoption leave policy.
    • Health spending($2,000/year) and personal spending($1,000/year) accounts with 75+ eligible reimbursement categories (health, training, electronics etc.).

Fully sponsored virtual healthcare assistance and Employee Assistance Program to you and your immediate family.

Various Employee Resource Groups (ERG) to engage with such as Pride and Allies, American Women Network, Black Leadership Network, One planet, etc.

A culture of continuous development by encouraging our employees various training programs (online training and coaching platform such as Coursera, GoFluent, Pluralsight, First Finance, and others).

#J-18808-Ljbffr

  • Montreal, Canada SGS Société Générale de Surveillance SA Full time

    ResponsibilitiesThe Risk Management Department contributes to the sustainable growth of the Societe Generale group through its expertise, understanding of risks, and risk management techniques. The department’s mission is to independently analyze, assess, manage, and monitor risk-taking activities with the objective of achieving, together with the first...


  • Montreal, Canada SGS Société Générale de Surveillance SA Full time

    ResponsibilitiesThe Risk Management Department contributes to the sustainable growth of the Societe Generale group through its expertise, understanding of risks, and risk management techniques. The department’s mission is to independently analyze, assess, manage, and monitor risk-taking activities with the objective of achieving, together with the first...


  • Montreal, Canada Société Générale Assurances Full time

    Operational Risk Manager – Cybersecurity Risks Innovation / Project / Organization Permanent contract Montreal, Quebec, Canada Reference 24000KQR Start date Immediately Publication date 2024/08/16 Responsibilities The Risk Management Department contributes to the sustainable growth of the Societe Generale group through its expertise,...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    Cybersecurity Risk Management ExpertWe are seeking a highly skilled Cybersecurity Risk Management Expert to join our team at SGS Société Générale de Surveillance SA. The ideal candidate will have a strong background in cybersecurity risk management, with experience in assessing and mitigating risks associated with data and technology environments.About...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Manager to join our team at SGS Société Générale de Surveillance SA. This is an exciting opportunity for a professional with expertise in cybersecurity risk management to contribute to our organization's success.Job DescriptionThe Cybersecurity Risk Manager will be responsible for...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    Job SummarySociete Generale seeks a highly skilled Cybersecurity Risk Management Professional to join our team in the United States. This role requires expertise in assessing and mitigating cybersecurity risks, developing risk management programs, and collaborating with IT organizations to establish standards and policies.About the JobThe successful...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the JobAt SGS Société Générale de Surveillance SA, we are seeking a highly skilled Cybersecurity Risk Manager to join our team in the Americas Region. This role is responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on actual, mitigated, and residual cybersecurity risk in the organization.The successful...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleWe are seeking an experienced Cybersecurity Risk Management Lead to join our team at SGS Société Générale de Surveillance SA. In this role, you will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual cybersecurity risk in the organization.Key...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    At SGS Societe Generale de Surveillance SA, we are seeking a skilled Cybersecurity Risk Management Specialist to join our team.About the JobThis is a critical role that requires a deep understanding of cybersecurity risks and mitigation strategies. As a Cybersecurity Risk Management Specialist, you will be responsible for evaluating overall cybersecurity...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Management Lead to join our team at SGS Société Générale de Surveillance SA. In this role, you will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on actual, mitigated, and residual cybersecurity risk in the organization.Key...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    We are seeking a highly skilled Cybersecurity Risk Management Specialist to join our team at SGS Société Générale de Surveillance SA. The successful candidate will play a key role in evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual cybersecurity risk in the organization.The ideal...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    Company OverviewSociete Generale de Surveillance SA is a leading financial services company with a strong commitment to innovation and customer satisfaction.Estimated Salary: $120,000 - $180,000 per yearThis salary range is based on national averages for IT professionals in the United States and may vary depending on location, experience, and other...


  • Montreal, Quebec, Canada National Bank Full time

    Job OverviewNational Bank is seeking a highly skilled Strategic Cybersecurity Risk Manager to join their Technology, Cyber and Data Risk Management team. This role will play a critical part in identifying and mitigating cybersecurity risks across the organization.About the RoleThis position requires an individual with 10+ years of experience in technology...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    Societe Generale is seeking an experienced IT Cybersecurity Risk Manager to join their team in the United States. This role will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual cybersecurity risk in the organization.The ideal candidate will have a solid foundation in...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the JobThe Chief Cybersecurity Risk Management Officer will join our team to help further define the 2nd line of defense processes, policies, and tools for SGS Societe Generale de Surveillance SA's data and technology environments. The role covers various cybersecurity risk areas, including Reference data, transaction processing, digital...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About SGS Societe Generale de Surveillance SASociete Generale de Surveillance SA is a leading provider of risk management and security solutions. We are committed to helping our clients achieve their business objectives while maintaining the highest standards of risk management.Job Title: Cybersecurity Risk ManagerWe are seeking an experienced Cybersecurity...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the Role: We are seeking a highly skilled Cybersecurity Risk Manager to join our team at SGS Société Générale de Surveillance SA. As a key member of our Risk Management Department, you will play a critical role in identifying and mitigating cybersecurity risks that could impact our organization.Job Summary: The successful candidate will be...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the JobWe are seeking a highly skilled Data Cybersecurity Risk Manager to join our team at SGS Société Générale de Surveillance SA. This role is responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual cybersecurity risk in the organization.


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Management Lead to join our team at SGS Société Générale de Surveillance SA.Job DescriptionThe successful candidate will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual cybersecurity risk in the...


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    Resolute Forest Products, a global leader in the forest products industry, is seeking a Cybersecurity Risk Analyst to join its team. Based in Montreal, Quebec, Canada, this full-time permanent position offers a rewarding and safe work environment with opportunities for growth and skill development.About ResoluteFounded over two centuries ago, Resolute has...