# IT Risk & Control

**Company:** [StradIT](null/companies/gUMYmaPRJguCYquNxEjRoL.md)
**Location:** Hyderabad, India
**Workplace:** hybrid

[Apply for this job](null/view/cc4893ab-1526-4bb1-a85d-272063828c05)

## Description

**Division:**   Information Technology

**Department:**  FinSight (Hiring Dept); EADCT + IT Strategy (Coverage Areas)

**Area:**  IT Risk Management

**Department/Area Function:**

DTCC’s Information Technology (IT) Risk Management program is designed to identify, manage, measure and mitigate risks in all IT Capabilities.

·      Maintaining and enhancing IT risk management framework. The framework is comprised of tools and processes to help DTCC:

-   Identify new risks, changes in risk, or relationships between risks
-   Monitor and escalate key matters of risk and control. 

·        Support IT management in maintaining a complete and accurate Process, Risk, and Control library

·         Formulating, disseminating and administering IT risk management policy and procedures;

·         Providing process, risk and control consultation and evaluations of control effectiveness to support/ evidence management awareness of the effectiveness of the control environment (i.e., assist management in issue self-identification and issue closure validations)

·        Liaising with Technology Risk, Information Security, Technology Centers of Excellence and with other subject matter experts within the organization to ensure that risks and appropriate mitigants are identified and communicated throughout the organization.

**Position Title:**  IT Embedded Risk Manager (ERM) Senior Associate Level

**Position Summary:**

An IT ERM Senior Associate has primary responsibility for:

-   maintaining and enhancing IT management’s process, risk, and control (PRC) inventory, supporting documentation, mapping and alignment (e.g., to regulations)
-   supporting IT management’s timely response to, and remediation of, risk and control tasks which is a key indicator of IT management demonstrating an effective Risk Mindset
-   proactively identifying issues, performing root causes analysis of incidents, and assessing incidents and new initiatives for impact against enterprise risk frameworks
-   facilitating internal (e.g., internal audits, business continuity assessments) and external (e.g., regulatory examinations) reviews.

In carrying out these responsibilities, the incumbent must work collaboratively with the IT Risk Management team, other risk & control functions, as well as with IT line management. 

**Principal Responsibilities:**

-   Support efforts to identify and manage risk within the Enterprise Architecture, Data and Corp. Technology (EADCT) and IT Strategy Organizations
-   Develop and strengthen relationships with IT partners and control evaluation functions across the 3 lines of defense
-   Develop, communicate and ensure adherence to department risk policies, standards, procedures and best practices;
-   Demonstrate and embed the behaviors and competencies that create a risk management mindset in your organization;
-   Support, and eventually lead, risk management activities including review of policy and procedure documents for alignment with controls, adherence to Compliance requirements and best practices
-   Become a central point of contact for risk and compliance items throughout the EADCT and IT Strategy organizations
-   Gathering, preparing, and reviewing inputs into reporting (e.g., metrics, inherent risk assessments)

IT ERM Senior Associate will be consistently responsible for facilitating the:

-   Tracking and escalation of compliance items included on the IT Risk & Control Report/ Dashboard
-   Issue and action closure facilitation including meeting coordination, evidence gathering and review, documentation preparation and review
-   Gather, review, and prepare evidence required in support of control evaluations performed by audit and/or management control testing functions as well as regulatory exams

**Experience:**

-   6+ years experience as IT risk and control professional within a Big 4 accounting firm, financial service industry preferred.
-   Experience with operating, supporting, and/or assessing IT processes including: system development life cycle, technology vendor management, middleware technologies, and/or architectural governance and standards
-   Leading discussions with key stakeholders and staff to collect information requests.
-   Experience conducting control testing, including issue remediation testing
-   Familiarity with process mapping and control identification along with data collection and analytic skills

**Knowledge and Skills Required:**

-   Excellent analytical and problem-solving skills
-   Excellent verbal and written communication skills
-   Strong technology background with exposure to IT platforms and technologies including databases, networking, cloud environments, container platforms a plus
-   Strong IT general control background with exposure to change and release management processes and controls;  understanding of key segregation of duty risks; familiarity with functional and non-functional testing (e.g., resiliency testing)
-   Demonstrated ability to work pro-actively with all levels of management and staff
-   Highly motivated, detail-oriented, self-starter, who can set priorities, take initiative and work both independently and proactively in a dynamic team environment;
-   Ability to work under pressure, multitask and be flexible;
-   Ability/willingness to meet aggressive deadlines and objectives;
-   Excellent inter-personal skills with a highly developed customer service orientation, and ability to work effectively with all levels of internal staff, and external contacts;
-   Strong planning and project management skills;
-   Strong process mapping and data collection and analysis skills

**Education, Training &/or Certification:**

-   BA / BS or equivalent.  Advanced degree and/or certification a plus
