GRC/Risk & Compliance Project Manager
Location: New York
Responsibilities:
- Lead the development and implementation of GRC frameworks and policies to ensure compliance with relevant regulations and standards.
- Conduct risk assessments to identify vulnerabilities and threats to information security, and develop strategies to mitigate these risks.
- Collaborate with cross-functional teams to integrate risk management practices into business processes and decision-making.
- Monitor and report on compliance status, risk exposure, and the effectiveness of risk management strategies to senior management.
- Facilitate training and awareness programs to promote a culture of compliance and risk management across the organization.
- Stay updated on industry trends, regulatory changes, and best practices in GRC and information security.
- Manage relationships with external auditors and regulatory bodies to ensure compliance and address any findings or recommendations.
- Develop and maintain documentation related to risk management processes, compliance activities, and audit trails.
Job Role Overview
- Title options: Risk Program Manager, Business Risk & Controls Manager, Operational Risk Program Officer
- Department: Enterprise Risk Management, Compliance, or First/Second Line of Defense Business Unit Control
- Core Goal: Align business execution with bank risk appetite and regulatory standards
Key Responsibilities
- Project & Program Management of significant Change Initiatives i.e. SS&A, Compass, BVA, etc.
- Roadmap Management, Dependency Management, Cross Product Management, Status Reporting and Release Coordination
- Program execution: Drive cross-functional risk and control projects from design to implementation.
- Control testing: Validate that operational and financial controls are designed well and work effectively.
- Issue remediation: Track self-identified audit issues, corrective actions, and overdue milestones.
- Risk reporting: Build dashboards, key risk indicators (KRIs), and executive committee presentations.
- Stakeholder management: Partner with business line leaders, legal, audit, and external examiners
Mandatory Skills:
- Strong knowledge of Risk Management principles, particularly in Information Security.
- Proficiency in GRC tools and frameworks, including ISO 27001, NIST, and COBIT.
- Experience in conducting risk assessments and developing risk mitigation strategies.
- Excellent analytical and problem-solving skills, with the ability to interpret complex data and make informed decisions.
- Strong communication and interpersonal skills, capable of engaging with stakeholders at all levels.
Maddula Venkateshwara Reddy | ICS Global Soft
Senior. US IT RECRUITER
venkatreddy61996@gmail.com