Continuous Control Monitoring (CCM) Lead, VP

Mitsubishi UFJ Financial GroupJersey City, NJ
2dHybrid

About The Position

We are seeking a Vice President to lead our Continuous Control Monitoring (CCM) program within the Cybersecurity GRC organization. This role will design and implement automated control testing capabilities that provide real-time assurance across critical technology and security domains. The ideal candidate combines deep knowledge of regulatory frameworks (e.g., CRI 2.1, NIST CSF, FFIEC) with hands-on experience in data-driven control automation, dashboards, and GRC integration.

Requirements

  • 8+ years in cybersecurity, technology risk, or IT audit, with at least 3 years in control automation or CCM programs.
  • Strong understanding of CRI 2.1, NIST CSF, and financial sector regulatory requirements.
  • Hands-on experience with data pipelines, APIs, and automation tools for control testing; familiarity with SIEM, CSPM, vulnerability management, and identity platforms.
  • Proficiency in dashboarding and reporting tools (Power BI, Tableau) and integration with GRC solutions (ServiceNow, Archer, MetricStream).
  • Strong technical skills including ability to write SQL and script or code in any of the following: PowerShell, DAX/MDX, Python.
  • Knowledge of cloud security controls across AWS, Azure, or GCP.
  • Excellent communication skills with the ability to influence senior stakeholders and regulators.

Nice To Haves

  • Relevant certifications are preferred: CISSP, CISM, CISA, or cloud security certifications.

Responsibilities

  • Build and scale CCM capabilities to continuously test key technology and security controls across infrastructure, cloud, and application environments.
  • Develop monitoring use cases by onboarding systems of record and telemetry sources (IAM, vulnerability, logging, CMDB, cloud posture) into automated pipelines.
  • Translate control requirements and CRI Diagnostic Statements into machine-testable rules with clear pass/fail logic and evidence capture.
  • Aggregate automated test results into dashboards and scorecards for executives, control owners, and risk partners; integrate results into GRC platforms for issue management and regulatory reporting.
  • Maintain a traceability model from control objectives to automated tests and evidence artifacts to support audits and regulatory exams.
  • Partner with Compliance, Internal Audit, and Technology teams to ensure CCM outputs meet attestation and examination standards.
  • Drive continuous improvement by monitoring emerging threats, regulatory expectations, and industry best practices for CCM.

Benefits

  • comprehensive health and wellness benefits
  • retirement plans
  • educational assistance and training programs
  • income replacement for qualified employees with disabilities
  • paid maternity and parental bonding leave
  • paid vacation, sick days, and holidays
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service