San Juan, PR
Risk Analyst - IT, Cyber Risk & Assurance
Full Time Opportunity
General Description
This role will support the expansion of the second-line IT and Cyber risk monitoring program to identify and monitor technology and cybersecurity risks.
Essential Duties and Responsibilities
IT & Cyber Risk Framework & Governance:
• Support the development and maintenance of the IT & Cyber Risk and Control Matrix in alignment with regulatory requirement and industry best practices dictated by frameworks such as NIST, COBIT, FFIEC, CCM, and others.
• Prepare, generate, and provide materials (e.g., risk scorecards, dashboards, dashboards, and metrics required for various Risk Committees, Senior Management Team and Executives by the required due dates.
• Monitor compliance with mitigation and remediation plans adopted by the Cybersecurity and IT business units.
Risk Oversight & Advisory:
• Review and provide second line effective challenge on policies, standards, risk acceptances and escalations, and control implementations related to the IT and Cybersecurity domain to ensure alignment with the IT & Cyber Risk and Control Matrix.
• Provides guidance and assistance in the execution of the IT & Cybersecurity Risk and Control Self-Assessments (RCSAs), translates control deficiencies into action plans and provides recommendations to Management on how to better enhance controls.
• Support Management in regulatory interactions by coordinating meetings, preparing and reviewing documentation and meeting materials, and facilitating onsite meetings.
• Develop and conduct training to business unit’s liaisons on the various Cybersecurity and IT topics.
Key Risk Indicators:
• Develop, calculate, and review key risk indicators and other reporting metrics while defining data quality and integrity checks over the data.
• Perform trends analysis to identify potential issues and perform root cause analysis to provide recommendations to Management on how to better manage their IT & Cyber risk posture.
Education
Bachelor’s degree in business administration (B. A.) with major in Information Technology, or Computer Engineering/Computer Science.
Experience
• At least 3 years of working experience in IT controls testing, IT Risk, IT Audit and/or Cybersecurity positions; or in consulting IT/Cyber role with a broad view of Information Technology or Information Security controls.
• Working Knowledge of IT and cyber frameworks and financial institutions laws and regulations (E.g. NIST, COBIT, FFIEC, etc.). Experience defining, reviewing and documenting IT / Cyber policies and procedures.
• IT or Cyber certifications preferred (e.g. CISA, CISM, CISSP, CGEIT, CRISC, etc)
Other Qualifications
• Excellent analytical skills to identify situations, look for alternatives and make good decisions. Medium to Advance Knowledge in Excel is preferred
• Excellent written and verbal communication in English and Spanish
• Critical thinking ability.
• Excellent organizational skills are required to establish priorities, multitask, work under pressure, and meet deadlines.
• Excellent interpersonal skills and teamwork.
• Proficient in Microsoft Office: Word, Excel, PowerPoint, and Outlook
Values
Important: The candidate must provide evidence of academic preparation or courses related to the job posting, if necessary.
Our hybrid work model benefit applies to certain positions and is subject to changes based on the organizational needs.
Applicants must be authorized to work for any employer in the United States. This position is not open to applicants who need visa sponsorship or transfer of visa sponsorship at this time.
ABOUT US
Popular is Puerto Rico’s leading financial institution and have been evolving since it was founded over a century ago. From a small bank it has developed into a large corporation that offer a wide variety of services and financial solutions to our customers, with presence in the United States, the Caribbean and Latin America.
As employees, we are dedicated to making our customers dreams come true by offering financial solutions in each stage of their life. Our extensive trajectory demonstrates the resiliency and determination of our employees to innovate, reach for the right solutions and strongly support the communities we serve; therefore, we value their diverse skills, experiences and backgrounds.
We reaffirm our commitment to always offer essential financial services and solutions for our customers and communities, including during emergency situations and/or natural disasters. Popular’s employees are considered essential workers, whose role is critical in the continuity of these important services even under such circumstances. By applying to this position, you acknowledge that Popular may require your services during and immediately after any such events.
If you have a disability or need more information about requesting an accommodation, please contact us at asesorialaboral@popular.com. This email inbox is monitored for such types of requests only. All information you provide will be kept confidential and will be used only to the extent required to provide needed exemptions or reasonable accommodations. Any other correspondence will not receive a response.
Are you ready for a rewarding career?
Popular is an Equal Opportunity Employer, including Disability/Vets
Learn more about us at www.popular.com and keep updated with our latest job postings at www.jobs.popular.com.
Connect with us!
LinkedIn | Facebook | Twitter | Instagram
If you are a California resident, please click here to learn more about your privacy rights.
Job Segment:
Compliance, Law, Legal