Technology Risk Analyst – 12 months contract recruitment

Description

A member of the embedded program risk function within the Asian Core Engine (ACE) Program and the APEA Operational/Project Risk Community. This role is responsible for establishing and executing a risk framework established for a large program of business change that includes parallel releases across multiple countries, partnering complexities and a high number of interdependent programs and systems.

Finance
· Seeks out and implement opportunities to reduce business costs through proactive early engagement of delivery teams from design through to deployment .

Customer
· Oversee and drive the appropriate management, reporting and review of Technology/Project Risk events, incidents or breaches and non-compliance within the areas of responsibility
· Engage impacted business unit stakeholders during Information/Technology Risk Assessment, avoiding surprises through close partnering model
· Coordinate and review the quality of risk assessments, including regular self-assessment of existing processes and of new country initiatives, including processes and projects
· Identify areas of weakness in risk and information security management and establish remediation plans and measures
· Oversee the implementation of approved processes for: (i) risk assessment, treatment, monitoring and reporting, (ii) controls assessment and verification, monitoring; (iii) audit and compliance issue tracking
· Promotes an effective risk culture, with emphasis on coaching, transparent reporting and timely escalation

People
· Undertake appropriate training, accreditation and up skilling to keep up to date with regulatory and governance risk best practice and competitor practices
· Create, maintain and deliver risk training throughout the program
· Promote an open and 'no surprises' management culture through creating an awareness of technology risk accountabilities and responsibilities
· Manage and support external specialists and consultants where required, e.g. ANZ Information Security Office

Process
· Report risk and compliance activities, initiatives, treatments and issues on a regular basis
· Drive the development of end-to-end technology risk profiles for all key streams in the program
· Ensure risks are recorded in standard repositories
· Execute a proactive, appropriate and effective monitoring and reporting structure
· Execute within the technology/project risk framework, reflecting the business units risk profile, and covering all areas of responsibility
· Contribute to analysis performed for change requests and post implementation reviews
· Ensure compliance with Group and Regional Policies
· Coordinate rollout and completion of technology risk scorecards
· Ensure all services delivered comply with ANZ Group IT strategy, policies, processes and standards and with external regulatory requirements

Risk
· Manage and ensure the implementation of all approved ACE Program Risk frameworks, protocols, programs and policies
· Facilitate Risk Forum operation
· Manage Internal Audit interaction with the Program by engaging audit during scoping and fieldwork and driving program remediation activities

Requirements
· Tertiary qualification in a relevant discipline
· Certifications in relevant disciplines (CISA, CISSP)
· Prefer a combination of Technology and risk/audit experience, 3+ years experience preferred
· Knowledge of and experience in banking and finance and how technology systems support Banking
· Outstanding communication skills both written and oral and influencing skills
· Strong organisation skills
· Ability to drive and manage team workload and operate within defined deadlines
· Strong understanding of risk management principles, fundamentals and practices
· Technology Risk and Information Security policies and standards awareness
· Operational Risk and Compliance frameworks awareness
· Strong analytical and problem solving skills to develop acceptable solutions for the business
· Knowledge of Regulatory Compliance challenges faced regionally
· Medium to large program/ project experience
· Technology risk within projects and/ or business change
· Experience working in a mixed sourcing environment, some outsourcing, some insourcing
· Leading teams, including workshop facilitation and developed influencing skills
· Ability to effectively interact with Internal Audit, Compliance, In-Country technology teams