Talent.com
Control and Risk Assessment Lead- E
Control and Risk Assessment Lead- EConfidential • India, Cochin / Kochi / Ernakulam
Control and Risk Assessment Lead- E

Control and Risk Assessment Lead- E

Confidential • India, Cochin / Kochi / Ernakulam
1 day ago
Job description

At EY, we're all in to shape your future with confidence.

We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help to build a better working world.

Control & Risk Assessment Leader

Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

The Technology Assurance, Risk, and Policy (TARP) function within Information Security strives to create and promote a holistic Governance, Risk, and Compliance (GRC) program by creating a robust, resilient, and proactive governance framework, supported by a strategic risk management approach and stringent compliance structures. It aims to integrate and align its GRC initiatives in line with the global firm's objectives and emerging threats within the cybersecurity landscape.

Furthermore, the Policy, Risk, and Controls (PRC) Enablement & Awareness team aims to establish policies and procedures that reflect the value we place on safeguarding our digital environment, while ensuring that these policies are effectively communicated and enforced across all levels of the organization. The Control & Risk Assessment team sits within PRC Enablement & Awareness and aims to directly enables the GRC program by designing control testing and risk assessment methodology to measure and quantify compliance to policies and control objectives.

Your Key Responsibilities

The Control & Risk Assessment Leader will be responsible for building and owning a control testing and risk assessment program, following the model for 1st line and 2nd line testing best-practice strategies, that routinely tests and assesses the effectiveness and efficiency of Information Security controls put in place to mitigate risks to determine if they are supporting the desired business outcomes. They will need to rank and prioritize Information Security and Information Technology controls based on their risk profiles and design testing plans, inclusive of testing procedures, which will be used to measure effectiveness while, simultaneously looking for opportunities to enhance and improve EY's control landscape. In certain instances, they will need to plan and execute risk assessments to quantify assumptions over the risk profiles.

The Control & Risk Assessment Leader is responsible for building a team of experienced professionals to assist in executing the strategic vision and objectives of the Control & Risk Assessment testing and assessment program. The Control & Risk Assessment team will work collectively to support the Information Security Program in the areas of risk assessment methodology development and execution of risk assessments, control testing design and execution, and identification of gaps and areas of improvement utilizing testing and assessment results.

Collaboration with other Information Security groups and external stakeholders across EY is key to this role. The Control & Risk Assessment Leader will need to build a network of multi-departmental and multi-level stakeholders inclusive of, but not limited to Information Security, Client and Enterprise Technology, Data Protection, Global and Enterprise Risk Management, Internal Audit, Area and Regional Risk & Data teams, Service Line Quality Leaders, etc

Skills And Attributes For Success

  • Own and build multi-year roadmap to establish and mature the Control & Risk Assessment program. This includes development of the team's charter, identification of resource needs, ongoing monitoring systems and tool requirements, performance metrics, and workstream prioritization.
  • Build and manage control testing and risk assessment service offerings aimed at identifying potential risks and validates mitigation controls by conducting regular and systematic assessments of the organization's IT infrastructure, including networks, systems, applications, and data processes.
  • Based on results of assessments and testing, assist control owners with the design and implementation of their controls in the organization's IT environment. Strategize on the appropriate amount of preventive, detective, or corrective controls which will have the most impact on reducing overall risk for the firm.
  • Create a 1st Line Testing framework that can be shared with control owners that will enhance security culture and support control ownership roles and responsibilities. Conduct training and awareness campaigns to facilitate the adoption of the framework.
  • Appropriately balance firm security needs with business impact and benefit when recommending advancements in policy and control objectives and directing those efforts to completion.
  • Think strategically to assist with the development of a long-term vision for Information Security's Technology Assurance, Risk, and Policy direction inclusive of its program improvement, technology adoption, and integration of security solutions into business objectives.
  • Act as a thought leader in the firm, staying informed of changes in information security, regulatory requirements, audit standards, and industry trends, adjusting strategies, as necessary.
  • Build and maintain appropriate relationships with internal and external leaders to ensure awareness and understanding of potential strategic directions.
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change.
  • Outstanding management, interpersonal, communication, organizational, and decision-making skills.
  • Ability to understand and integrate cultural differences and motives and to lead cross cultural teams.
  • Demonstrate integrity and judgment within a professional environment.
  • Evaluate, counsel, mentor and provide feedback on performance of others.
  • Plan the training and development of staff to develop their skills and maintain state-of-the-art knowledge in information security.

To qualify for the role you must have

  • 12+ years of experience in the Information Technology, Information Security and / or Risk Management field(s).
  • Audit experience or a demonstrated ability to design and test technology controls.
  • 5+ years of experience in managing and mentoring junior and senior level staff.
  • Experience leading global and virtual teams.
  • High proficiency in technical and general writing skills in English.
  • An advanced degree in Computer Science, Information Security, or a related field; equivalent work experience will be considered on a case-by-case basis.
  • One or more of the following or equivalent certifications preferred : Certified Risk and Information Systems Control (CRISC), Certified Information Systems Security Processional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), Certified Internal Auditor (CIA), Global Information Assurance Certification (GIAC) in related area, CIPP, CIPT.
  • Ideally, you'll also have

  • A working knowledge of external control standards like ISO 27001, NIST 800-53, COBIT, etc and regulatory requirements like GDPR and SOX.
  • Skilled in Microsoft Office and M365 products; primarily Word, Excel, PowerPoint, SharePoint, PowerApps, and PowerBI.
  • Experience with RSA Archer or other GRC tools.
  • Flexibility to work outside of normal business hours when engaging with team members and stakeholders in various time zones.
  • What We Offer

    As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial and social well-being. Your recruiter can talk to you about the benefits available in your country. Here's a snapshot of what we offer :

  • Continuous learning : You will develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you : We will provide the tools and flexibility, so you can make a significant impact, your way.
  • Transformative leadership : We will give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture : You will be accepted for who you are and empowered to use your voice to help others find theirs.
  • We ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions and to receive other benefits and privileges of employment. Please contact us to request accommodations.

    EY is committed to being an inclusive employer, and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance.

    EY | Building a better working world

    EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

    Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

    EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

    Skills Required

    Gdpr, Risk Assessment, Iso 27001, Cobit, control testing , Microsoft Office, Sox, Rsa Archer

    Create a job alert for this search

    Risk Assessment Lead • India, Cochin / Kochi / Ernakulam

    Related jobs
    Business Risk Manager (Technology)

    Business Risk Manager (Technology)

    Revolut • Kochi, IN
    People deserve more from their money.More visibility, more control, and more freedom.Since 2015, Revolut has been on a mission to deliver just that. Our powerhouse of products — including spending, ...Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.ai • Kochi, IN
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show more
    Last updated: 30+ days ago • Promoted
    Corporate Assurance and Governance

    Corporate Assurance and Governance

    V-Guard • Kochi, Kerala, India
    Conduct follow-up audit to ensure implementation of controls suggested by co-sourced auditors.Conducts risk assessments and identifies controls in place to mitigate identified risks.To Coordinate w...Show more
    Last updated: 30+ days ago • Promoted
    SOX Business Controls Tester

    SOX Business Controls Tester

    VOIS • Kochi, IN
    Hiring SOX Business Controls Tester with Vodafone Intelligent Solutions (_VOIS).Required Qualification : CA / CMA.The Manager – SOX Compliance is responsible for the execution of SOX (Sarbanes-Oxley A...Show more
    Last updated: 22 days ago • Promoted
    Forward Deployed Analyst (Ex-IB / PE / HF / Buyside)

    Forward Deployed Analyst (Ex-IB / PE / HF / Buyside)

    Arcana • Kochi, IN
    Forward-Deployed Analyst – Portfolio Intelligence.Arcana builds institutional-grade analytics for leading hedge funds and asset managers. We’re hiring exceptional analysts to partner with portfolio ...Show more
    Last updated: 30+ days ago • Promoted
    Vice President - Model Developer (Wholesale Risk)

    Vice President - Model Developer (Wholesale Risk)

    Mashreq • Kochi, IN
    The main purpose of the role is to lead the wholesale Risk model development team and assist the Head of Risk Analytics and Capital Management in execution of risk governance and practices around q...Show more
    Last updated: 30+ days ago • Promoted
    Business Risk Manager (Fincrime)

    Business Risk Manager (Fincrime)

    Revolut • ernakulam, kerala, in
    People deserve more from their money.More visibility, more control, and more freedom.Since 2015, Revolut has been on a mission to deliver just that. Our powerhouse of products — including spending, ...Show more
    Last updated: 10 days ago • Promoted
    Process Excellence Lead ( Risk / Change Management)

    Process Excellence Lead ( Risk / Change Management)

    Innodata Inc. • Kottayam, IN
    Qualifications and Requirements.Bachelor’s degree in Business Administration, Engineering, Operations Management, or related field required. Master’s degree or MBA preferred.Lean Six Sigma Black Bel...Show more
    Last updated: 13 days ago • Promoted
    EHS Enablon Technical Consultants

    EHS Enablon Technical Consultants

    ADR Application Development Resources, Inc. • Kochi, IN
    If you are interested, please email me your CV at linda.There are 4 openings for EHS Technical Consultants in India It is a Remote positions. Enablon solution will support internal and external r...Show more
    Last updated: 30+ days ago • Promoted
    Test Lead

    Test Lead

    Indium • Kottayam, IN
    We are looking for a 10+ years skilled Senior Test Lead with strong expertise in.Should be capable of translating business requirements into effective test scenarios, collaborating closely with sta...Show more
    Last updated: 13 days ago • Promoted
    ARM Design Verification Lead

    ARM Design Verification Lead

    L&T Technology Services • Kottayam, IN
    You should be a verification engineer with a knowledge of SoC integration verification, SoC scenario verification, SoC performance verification, CHI / PCIe / CXL, DDRx / LPDDRx integration verification i...Show more
    Last updated: 30+ days ago • Promoted
    Sr SAP EHS Functional

    Sr SAP EHS Functional

    KATBOTZ® • Kochi, IN
    We are seeking a highly skilled.SAP Environment, Health, and Safety (EHS) solutions.The ideal candidate will have deep knowledge of SAP EHS modules, regulatory compliance requirements, and process ...Show more
    Last updated: 14 days ago • Promoted
    Process and Compliance Analyst

    Process and Compliance Analyst

    Innodata Inc. • Kottayam, IN
    The Process and Compliance Analyst is a key contributor to driving operational excellence, regulatory compliance, and continuous improvement across the organization. This role sits at the intersecti...Show more
    Last updated: 7 days ago • Promoted
    Senior Portfolio Risk Analyst

    Senior Portfolio Risk Analyst

    Arcana • Kochi, IN
    Arcana is a portfolio intelligence platform used by hedge funds and asset managers to analyze performance and risk.We’re rethinking the tools institutional investors rely on—and we’re hiring analys...Show more
    Last updated: 19 hours ago • Promoted • New!
    ALM Risk Management

    ALM Risk Management

    FORWARD • Kottayam, IN
    Experience of minimum 10+ years plus, working in a bank or a reputed consulting firm in the areas of Liquidity risk management, Liquidity reporting, ALM s FTP, RAROC. Comprehensive understanding of ...Show more
    Last updated: 2 days ago • Promoted
    eDiscovery Project Manager (Remote)

    eDiscovery Project Manager (Remote)

    KLDiscovery • Kochi, IN
    Remote
    KLDiscovery, a leading global provider of electronic discovery, information governance and data recovery services, is currently seeking a eDiscovery Project Manager. The position is responsible for ...Show more
    Last updated: 6 days ago • Promoted
    Business Risk Manager (Savings)

    Business Risk Manager (Savings)

    Revolut • Kottayam, IN
    People deserve more from their money.More visibility, more control, and more freedom.Since 2015, Revolut has been on a mission to deliver just that. Our powerhouse of products — including spending, ...Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer

    Lead Security Engineer

    Arcana • Kochi, IN
    As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show more
    Last updated: 30+ days ago • Promoted