PGC GCOO Technology
Role
Overview
- Join our dynamic team as an IT Risk and Control Specialist where youll play a pivotal role in safeguarding and enhancing the technology landscape supporting our People Governance and Communications functions Youll collaborate across multiple internal teams to drive robust risk management control practices and process improvements ensuring our systems and workplace technologies remain secure efficient and resilient
Key Responsibilities
- Build Trusted Partnerships
- Develop strong working relationships with the People Governance Communications Group COO Technology ITSO community technical leads developers and architects to understand endtoend services and proactively identify control gaps
- Risk Control Leadership
- Work closely with Cybersecurity teams senior management and business stakeholders to address potential security issues and ensure best practices are embedded across all technology functions
- Process Tool Enhancement
- Contribute to the identification and improvement of processes procedures and tools that support effective risk management and control
- Lifecycle Management
- Champion best practices in Software Life Cycle Management including Identity Access Management IDAM Evergreening and Data Movement DMOV to mitigate cyber risks and ensure compliance
- Vulnerability Management
- Design and implement vulnerability reporting and monitoring solutions for key stakeholders from engineers to CIOs Liaise with technology product owners and ITSOs to support timely remediation of identified risks
- Patch Remediation Coordination
- Collaborate with cybersecurity teams to understand patching requirements and ensure vulnerabilities are addressed within agreed timelines
- Documentation Reporting
- Maintain and update process guides support control remediation activities and create insightful reports and presentations for senior stakeholders and governance forums
- Continuous Improvement
- Stay abreast of industry trends and best practices sharing knowledge and insights with the wider team to foster a culture of continuous learning and improvement
Qualifications Experience
- Solid understanding of IT Risk and Control Management including risk management frameworks
- Strong analytical skills with experience interpreting patching and vulnerability reports
- Specific experience of working with at least one of the controls would be beneficial
- Ability to assess threats controls and vulnerabilities and communicate findings effectively to both technical and business audiences
- Excellent written and verbal communication skills
- Proven experience in security concepts and principles with knowledge of network host and application security practices
- Handson experience with tools such as Cyberport Cyberflows Power BI Confluence and Jira
Skills
Mandatory Skills : BMC Control-M, Risk Management (Credit/Market/IT/Ops)