Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 1
AWS @ 3
Audit @ 6
Communication @ 6
Compliance @ 6
DevOps @ 3
GCP @ 3
GDPR @ 6
Kubernetes @ 3
Machine Learning
Project Management @ 3
R
Terraform @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Responsibilities
-
Develop, implement, and maintain internal control frameworks aligned with industry best practices and applicable regulatory requirements (e.g., SOX, COSO, COBIT, NIST, ISO 27001, other compliance frameworks)
-
Collaborate with 2nd line Risk partners, process owners, control owners and management to ensure the frameworks are practical, effective and tailored to business needs
-
Maintain a central repository of policies, procedures, control matrices
-
Develop RACI and standardized approach for implementation including training and communication
-
Develop approach for ongoing review & continuous improvement
-
Enable business partners with guidelines, templates and tooling
-
Maintain a central register of all framework documents
-
Contribute to risk and control reporting and assurance in the business unit
-
Act as SOX design authority
-
Partner with R&C and ABU business and IT stakeholders by providing guidance and ensuring that critical SOX controls are adequately designed and documented
-
Provide SME guidance to R&C and ABU business and IT stakeholders and 1st line business owners in relation to observations and deficiencies, from initial assessment/triage through to mitigation and remediation
-
Support Audit management—act as an SME to support critical audit management activities such as audit planning and issue management
-
Support testing of business and IT controls and management certification (SOX Section 302 and 404, other compliance frameworks) by providing guidance to the testing team and reviewing testing documentation
-
Collaborate with GRC team and 1st/2nd line Risk partners to develop solutions and improve how risks, controls and issues are maintained in the GRC platform
-
Act as a risk ambassador to further enhance risk awareness and culture, including by facilitating formal training sessions
Requirements
- 6+ years of previous work experience in internal controls, audit, risk management, or compliance
- Bachelor’s degree or higher in a relevant field (Master’s Degree is preferable)
- Strong knowledge of internal control frameworks (e.g., COSO, COBIT, NIST, ISO 27001) and regulatory requirements (e.g., SOX, GDPR, DMA, DSA), and experience in applying them in various business areas/functions
- Qualifications related to any of the above are advantageous (incl. CISM, CRISC, ACCA, CIA, CISA)
- Experience with Data Governance, Cloud platforms, SaaS applications, business continuity management, and emerging technologies (AI/ML, RPA) is a plus
- Comfortable with modern tech environments such as DevOps (Kubernetes, GitLab, terraform etc.) and also cloud based (AWS, GCP etc.)
- Good stakeholder management skills
- Flexibility to adapt to an ever-evolving and dynamic work environment
- Self-starter with strong sense of responsibility
- Energetic and very proactive
- Process, problem solving and action oriented mindset
- Strong communication and relationship building skills
- High level of integrity, confidentiality & professionalism
- Ability to develop strong relationships with business partners in order to drive risk management culture and implementation
- Fluent in English, both written and spoken (other languages would be a plus)
- Project management skills a plus