Manager, Risk and Control Self-Assessment (RCSA) Infrastructure

Santander Consumer USA
Dorchester Center, MA
$155K a year
Full-time
We are sorry. The job offer you are looking for is no longer available.

Manager, Risk and Control Self-Assessment (RCSA) Infrastructure

Country : United States of America

The Manager of IT Infrastructure RCSA within the first line of defense, Business Control & Risk Management team, is accountable leading the Infrastructure Technology Risk and Control Self-Assessment.

The Manager will have a team that works to identify, assess and test various Information Technology (IT) risks and controls through the defined risk program requirements.

The Manager will oversee the evaluation of key IT processes, review internal control / quality reports and participate in risk initiatives and lead opportunities for improved efficiency, effectiveness and / or efforts to reduce exposure to top / material technology risks.

S / he supports and monitors IT's adherence with corporate policies and procedures including regulatory / legal obligations.

The Manager provides leadership within the Business Control & Risk Management team(s) and IT and must be able to effectively lead and collaborate with various stakeholders while influencing strategic goals.

This Hybrid role can be located in any of our Santander US offices in Dallas, Boston, NY, or Miami and will be required to come into the office 3x's a week.

Essential Functions / Responsibility Statements :

Drive Risk Culture : Establishes expectations, ownership and accountability for risk management within the Business Line (IT).

Ensure awareness in the Business Line (IT) of risk frameworks, policies and standards.

Communication : Act as central point of contact for receipt and distribution of risk related information between SLoD risk teams and Business Line (IT).

Maintain two-way communications with SLoD. Facilitate training for Business Line (IT) to provide awareness of risk frameworks, policies, programs, processes, etc.

  • People Manager : The manager must manage their team for training, compliance, capacity and personnel issues.
  • Adherence to Risk Frameworks, Policies, and Standards : Partner with SLoD to provide input / review of frameworks, policies and standards.

Facilitate Business Line (IT) awareness of and adherence to risk frameworks, policies, and standards through internal control testing and issue validation.

Report and escalate exceptions and facilitate Business Line (IT) corrective actions.

Continuous Monitoring : Continuously monitors all sources of risk existing within the Business Line (IT) and externally.

Engage in research, peer networking, and experience to anticipate critical risk issues impacting the Business Line (IT).

Monitor Key Risk Indicators and report on negative / adverse trends in Business Line (IT). Monitor risk profile to maintain tolerance within Risk Appetite.

Issue Identification, Management, and Risk Assessment : Conduct IT RCSA responsibilities including Process Mapping, Risk & Control Matrices, Inherent Risk Assessments, and IT Control testing.

Engage and hold Business Line (IT) process owners accountable to identify and assess risks. Support Business Line (IT) in risk identification.

Ensure all issues pertaining to the Business Line (IT) are resolved within established timelines. Validate issues to ensure Business Line (IT) remediation is sufficient to address root cause and prevent recurrence.

Internal Control Testing : Implement and maintain internal control testing and control effectiveness monitoring in the Business Line (IT).

Validate the adequacy of controls, escalate deficiencies as appropriate. Identify root causes of control deficiencies / weaknesses and take appropriate action to ensure Business Line (IT)s remediate and prevent recurrence.

Exam Management : Liaison with the Business Line (IT) for all exam related activities including regulatory, Internal Audit, etc.

Review materials, responses and validate Business Line (IT) remediation work (e.g., artifacts, action plans, etc.) Qualifications : To perform this job successfully, an individual must be able to perform each essential duty satisfactorily.

The requirements listed below are representative of the knowledge, skill, and / or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education :

  • Bachelor's Degree or equivalent work experience in Information Technology, Business, Risk Management, or equivalent field.
  • Master's Degree in Information Technology, Business, Risk Management, or equivalent field. (Pref) Licenses & Certifications
  • Preferred Professional Certification such as CRISC, CISA, CISSP Work

Experience :

  • 10+ years within IT Audit or IT RCSA programs
  • Previous management experience managing small teams Skills and Abilities :
  • Proven ability to provides strategic guidance and direction for programs, policies, and procedures to ensure alignment with regulatory requirements and acceptable risk mitigation practices.
  • Experience Independently developing and documenting test procedures and / or documenting recommendations for test plan modifications that improve validation of control objectives.

Test procedure development may cover a wide range of technically diverse topics ranging from IP Network Discovery, access management, network security / operation, vulnerability management, Information Security, SDLC, Backup and others.

  • Should have extensive experience testing IT controls across multiple IT domains and evaluating both automated and manual controls related to Information Security or IT infrastructure domains.
  • Experience with Automated Test cases
  • Experience in both a cloud and legacy hardware environment
  • Ability to work on multiple concurrent assessments.
  • Ability to work under pressure and meet deadlines.
  • Strong risk assessment, negotiation and problem resolution skills.
  • Strong collaboration and relationship management skills.
  • Self-starter, able to establish relationships and transcend multiple cross-functional / divisional boundaries, largely unaided.
  • Proven ability to apply strategic thinking to multiple, complex organizational and business issues, and has ability to translate into practical plans for project execution.
  • Project management skills.
  • Knowledge and working understanding of additional auditing standards, theories, concepts, and terms (including Sarbanes-Oxley, COBIT and the COSO Integrated Control Framework)
  • High sense of urgency with ability to drive results.
  • High proficiency in PowerPoint, Word and Excel.
  • Excellent verbal and written communication / presentation skills.

Diversity & EEO Statements : At Santander, we value and respect differences in our workforce and strive to increase the diversity of our teams.

We actively encourage everyone to apply.

Santander is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, genetics, disability, age, veteran status or any other characteristic protected by law.

Working Conditions : Frequent Minimal physical effort such as sitting, standing and walking. Occasional moving and lifting equipment and furniture is required to support onsite and offsite meeting setup and teardown.

Physically capable of lifting up to fifty pounds, able to bend, kneel, climb ladders.

Employer Rights : This job description does not list all of the job duties of the job. You may be asked by your supervisors or managers to perform other duties.

You may be evaluated in part based upon your performance of the tasks listed in this job description. The employer has the right to revise this job description at any time.

This job description is not a contract for employment and either you or the employer may terminate at any time for any reason

The base pay range for this position is posted below and represents the annualized salary range. For hourly positions (non-exempt), the annual range is based on a 40-hour work week.

The exact compensation may vary based on skills, experience, training, licensure and certifications and location.

Base Pay Range

Minimum : $108,000.00 USD

$108,000.00 USD

Maximum : $155,000.00 USD

$155,000.00 USD

1 day ago
Related jobs
Promoted
Marsh McLennan
Boston, Massachusetts

Non-financial risk measurement and management, including third party risk management, fraud, and cyber risk. Oliver Wyman's Finance and Risk practice is the leading strategic risk management consultancy, engaged to solve the most challenging problems at the largest and most complex global financial ...

Promoted
Deciphera Pharmaceuticals
Waltham, Massachusetts

The Associate Director/Senior Manager, Pharmacovigilance and Risk Management, serves as a critical medical and data analytical role for the assigned investigational and/or marketed product(s). She/he must possess knowledge and skills to ensure that safety data analyses and reports are of high qualit...

Global Technical Talent
Woburn, Massachusetts

Knowledge of access and security and control risk assessment methods and technologies and/or audit experience preferred. Day to day you will evaluate internal and external risk- and control-related initiatives and their inherent impacts on the Company's risk posture. As a Risk and Controls Analyst, ...

RSM
Boston, Massachusetts

We are seeking experienced individuals with both broad and deep IAM experience and skills to join our team and deliver strategy, assessment, implementation, and managed services to RSM clients in a variety of industries and geographic locations. As leaders within the Security, Privacy and Risk consu...

Brigham and Women's Hospital
Boston, Massachusetts

Provides advice, consultation and support to hospital and professional staff on legal, risk and ethical issues. Reviews and evaluates aggregate adverse events and claims data, as well as other hospital information in order to identify high-risk activities, procedures and departments. Collaborates wi...

Vitamin T
Boston, Massachusetts

Uphold Executional Excellence standard for Brand Foundation, Brand Guidelines, and Executional Guidance. Unlock meaningful brand experiences in partnership with Brand Strategy Director and other Design functions. We’re about creating an inclusive environment—one where different backgrounds, experien...

Teradyne
North Reading, Massachusetts

You will leverage your understanding of qualitative and quantitative risk management and inherent and residual risk to properly establish, evaluate, and report on technology risk levels at the project and enterprise level. Develop and manage key performance and risk indicators and deliver executive ...

PricewaterhouseCoopers Advisory Services LLC
Boston, Massachusetts

Demonstrates thorough knowledge of leading or facilitating relevant project management or client consultations in the areas of Risk Management credit risk processes, credit analysis, risk rating, risk management policies and risk management organization structures, including security analysis and ri...

Deloitte
Boston, Massachusetts

Deloitte Risk and Financial Advisory's Financial Services Industry (FSI) Risk, Data and Regulatory professionals help organizations identify the regulatory changes impacting their business and implement effective and efficient processes to manage regulatory, capital, liquidity and interest rate risk...

Thermo Fisher Scientific
Waltham, Massachusetts

Handle risk assessment and mitigation of threats and acts of violence both in traditional and virtual environments in real time. Candidate must have a strong background in all major security domains to include physical security, risk assessment, investigations, travel security, threat management, ex...