The Risk Associate role supports the operationalization of the second line of defense Risk oversight of information technology, cybersecurity, and data risk for the SMBC Group Americas Division (AD) by performing independent review, effective challenge, and risk analysis in alignment with regulatory expectations, internal/head office policies, and industry standards. The Risk Management Department (RMDAD) is the second line of defense in its role of monitoring and assessing business practices as related to the risk appetite framework for SMBC. Within the RMDAD, the Tech, Data and Cyber Risk Oversight (TDCRO) establish technology, data and cyber risk management policies and framework with defined roles and responsibilities across first and second lines. Role Objectives: DeliverySupports the TDCRO management in ensuring IT, data management, and cybersecurity risks are adequately governed, managed and controlled. Supports the independent review and credible challenge of 1st Line of Defense risk assessments, controls, metrics, and remediation plans related to IT, data, and cyber risk domains. Assist in the maintenance and periodic update of technology, data, and cybersecurity risk management frameworks, policies, standards, and procedures. Provides review and challenge on IT, data management and cybersecurity policies, standards, control framework, risk metrics/indicators, risk and control self-assessment (“RCSA”). Support the preparation of technology, data, and cybersecurity risk reporting for management and risk committees, including issue tracking and escalation. Collaborate with cross-functional stakeholders across risk, technology, cybersecurity, and data teams
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees