Job Description
Roles & Responsibilities
To execute the Technology Risk Management activities by evaluating risks and providing on demand advisory to improve technology risk remediation.
1. Perform directly to rollout independent Technology Risk Assessments in the following scenarios:
- Technology Projects and Digital Transformation.
- Reviews of First Line Function effectiveness for Technology Risk controls
- On demand following technology incidents.
2. Assist risk owners on design & implementation of Technology Risk Remediation Plans by providing expertise (Technical, functional and procedural) and provide guidance for risk based decisions.
3. Identify and validate Technology Risks upon reviewing Internal & External Audit Reports, Technology Risk Notes, Technology Incidents and contribute to their associated action plans to mitigate the same.
4. Handle all of the Technology Risk Management Activities including but not limited to reviewing & qualifying the different risk notes and ensuring the relevant updates are reflected in the central risk register, communicating and notifying risk owners with relevant technology risks, coordinating with the relevant stakeholders on the different risk remediation plans.
5. Update the different Technology Risk Management Documentation Corpus
6. Assessment of metrics and Key Risk Indicators breaches to monitor the effectiveness of the controls and ensure proper risk mitigation.
7. Contribute with relevant departments to identify risks, risk gaps and early warning signals for Technology Risks that could arise from any change in systems, services, processes or procedures.
Policies, Processes, and Procedures
Follow all relevant department policies, processes, and standards operating procedures and instructions so that work is carried out in an controlled and consistent manner
8. Assist in defining, maintaining and enriching Technology Risk Managements Metrics, Taxonomy and Severity Scale as well as proficiently practice Technology Risk Management techniques, methods and tools that were designed to ensure that all Technology risks are adequately captured and managed. Moreover, prepare training materials and carry out communications activities in alignment with relevant stakeholders in order to improve mindset and knowledge.
9. Track and follow up with 1 st Line of Defense of the Technology risks, which are still under assessment in the centralized risk register.
10. Assist in reviewing the different risk treatment plans related to Technology Risk Management in cooperation with relevant stakeholders prior submitting to the relevant committees, to ensure effective response to identified technology risks
Policies, Processes, and Procedures
11.Follow all relevant department policies, processes, and standards operating procedures and instructions so that work is carried out in an controlled and consistent manner
Day-to-Day Operations
12.Follow the day-to-day operations related to own jobs in the Security & Technology Risk Management department to ensure continuity of work
Compliance
13.Comply with all relevant CBE regulations, banking laws, AML regulations and internal CIB policies and code of conduct in order to maintain CIB s sound legal position and mitigate any potential risks
Desired Candidate Profile
- Bachelor of Engineering, Computer Science, Information Technology or its equivalent.
- For Officer: 3-5 years in Information Technology, internal or external IT audit or a related discipline with Risk Management background.
- For Senior Officer: 5-8 years in Information Technology, internal or external IT audit or a related discipline with Risk Management background.
- Good knowledge of the Banking business environment, technology controls and Risk Management.
- Knowledge & experience with at least one of the Risk Management Framework: ISO31K, FAIR.
- Recommended relevant industry certifications, including but not limited to: Risk Manager, ISO 27005, IT Infrastructure Library (ITIL) Foundation, GIAC Critical Controls Certification (GCCC), Certified Information System Auditor (CISA), Certified Risk and Information Systems Control (CRISC)
الوصف الوظيفي
الأدوار والمسؤوليات
تنفيذ أنشطة إدارة مخاطر التكنولوجيا من خلال تقييم المخاطر وتقديم الاستشارات عند الطلب لتحسين إجراءات تصحيح مخاطر التكنولوجيا.
1. التنفيذ مباشرة لإطلاق تقييمات مستقلة لمخاطر التكنولوجيا في السيناريوهات التالية:
- مشاريع التكنولوجيا والتحول الرقمي.
- مراجعات فاعلية أول خط من الوظائف للتحكمات في مخاطر التكنولوجيا
- عند الطلب بعد حوادث تكنولوجية.
2. مساعدة أصحاب المخاطر في تصميم وتنفيذ خطط معالجة مخاطر التكنولوجيا من خلال توفير الخبرة (التقنية والوظيفية والإجرائية) وتقديم إرشادات لاتخاذ قرارات قائمة على المخاطر.
3. تحديد وتصديق مخاطر التكنولوجيا عند مراجعة تقارير التدقيق الداخلية والخارجية، وملاحظات مخاطر التكنولوجيا، وحوادث التكنولوجيا والمساهمة في خطط العمل المرتبطة بها ليتسنى تقليلها.
4. التعامل مع جميع أنشطة إدارة مخاطر التكنولوجيا بما في ذلك على سبيل المثال لا الحصر مراجعة وتأهيل ملاحظات المخاطر المختلفة والتأكد من أن التحديثات ذات الصلة مفعلة في سجل المخاطر المركزي، والتواصل مع أصحاب المخاطر وإخطارهم بالمخاطر التكنولوجية ذات الصلة، والتنسيق مع أصحاب المصلحة المعنيين بشأن خطط معالجة المخاطر المختلفة.
5. تحديث مجموعة وثائق إدارة مخاطر التكنولوجيا المختلفة
6. تقييم الانتهاكات المتعلقة بالقياسات ومؤشرات المخاطر الأساسية لمراقبة فعالية الضوابط وضمان التخفيف الصحيح للمخاطر.
7. المساهمة مع الأقسام المعنية لتحديد المخاطر والفجوات الإشارية المبكرة لمخاطر التكنولوجيا التي قد تنشأ من أي تغيير في الأنظمة أو الخدمات أو العمليات أو الإجراءات.
السياسات والعمليات والإجراءات
اتباع جميع سياسات القسم ذات الصلة والعمليات والمعايير وإجراءات التشغيل والتعليمات حتى يتم العمل بطريقة محكومة ومتسقة
8. المساعدة في تعريف وصيانة وإثراء مقاييس إدارة مخاطر التكنولوجيا والتصنيف ومقياس شدة المخاطر وكذلك ممارسة تقنيات وطرق وأدوات إدارة مخاطر التكنولوجيا بشكل ماهر لضمان التقاط وإدارة جميع مخاطر التكنولوجيا بشكل كاف. علاوة على ذلك، إعداد مواد تدريبية وتنفيذ أنشطة اتصالات بما يتماشى مع أصحاب المصلحة المعنيين من أجل تحسين التفكير والمعرفة.
9. تتبع والمتابعة مع خط الدفاع الأول للمخاطر التقنية التي لا تزال قيد التقييم في سجل المخاطر المركزي.
10. المساعدة في مراجعة خطط العلاج المختلفة المرتبطة بإدارة مخاطر التكنولوجيا بالتعاون مع أصحاب المصلحة المعنيين قبل تقديمها إلى اللجان المعنية لضمان الاستجابة الفعالة للمخاطر التكنولوجية المكتشفة
السياسات والعمليات والإجراءات
11. اتباع جميع سياسات وقسم وإجراءات التشغيل والمعايير ذات الصلة والتعليمات حتى يتم العمل بطريقة محكومة ومتسقة
العمليات اليومية
12. اتباع عمليات التشغيل اليومية المرتبطة بالوظائف الخاصة في قسم الأمن وإدارة مخاطر التكنولوجيا لضمان استمرارية العمل
الامتثال
13. الامتثال لجميع الأنظمة المصرفية واللوائح المصرفية، ولوائح مكافحة غسل الأموال، وسياسات داخلية في بنك أبوظبي التجاري (CIB) وقواعد السلوك للحفاظ على الوضع القانوني السليم للبنك والتخفيف من أي مخاطر محتملة
الملف المرشح المطلوب
- بكالوريوس في الهندسة أو علوم الحاسوب أو تكنولوجيا المعلومات أو ما يعادلها.
- للموظف: 3-5 سنوات في تكنولوجيا المعلومات، تدقيق داخلي أو خارجي لتكنولوجيا المعلومات أو تخصص ذات صلة مع خلفية إدارة المخاطر.
- للدرجة العليا: 5-8 سنوات في تكنولوجيا المعلومات، تدقيق داخلي أو خارجي لتكنولوجيا المعلومات أو تخصص ذات صلة مع خلفية إدارة المخاطر.
- معرفة جيدة ببيئة الأعمال المصرفية، وضوابط التكنولوجيا وإدارة المخاطر.
- معرفة وخبرة مع إطار إدارة المخاطر على الأقل واحد من: ISO 31K، FAIR.
- شهادات صناعية ذات صلة موصى بها، بما في ذلك على سبيل المثال لا الحصر: مدير المخاطر، ISO 27005، ITIL Foundation، GIAC Critical Controls Certification (GCCC)، Certified Information System Auditor (CISA)، Certified Risk and Information Systems Control (CRISC)