Senior Associate - Tech Risk & Controls - CORE
Join our dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in our firm's robust risk strategy.
As a Tech Risk & Controls Senior Associate in Global Technology, you will contribute to the successful management of technology-aligned aspects of Governance, Risk, and Compliance in line with the firm's standards. Leverage your broad knowledge in risk management principles and practices to assess and monitor risks and implement effective controls. Your role in risk identification, control evaluation, and security governance is crucial in advising on complex situations and enhancing the firm’s risk posture. Through collaboration and analytical skills, you will contribute to the overall success of the Technology Risk & Services team and ensure compliance with regulatory obligations and industry standards.
Job responsibilities
- Provide expert guidance on all aspects of CORE, ensure alignment to firmwide CORE standards/procedures, and strengthen Operational Risk representation in CORE across Global Technology.
- Support Technology Control Managers with day-to-day CORE activities, manage data input/uploads with accuracy/integrity, and review/close out program and self-identified CORE hygiene items.
- Assess and monitor technology risks, ensuring compliance with firm standards, regulatory requirements, and industry best practices
- Support implementation of effective controls in CORE with cross-functional teams and stakeholders
- Support data quality analysis, reporting and input/upload into CORE, maintaining accuracy and integrity.
- Uses enterprise-authorized AI capabilities within the work environment to accelerate synthesis of risk/control evidence and draft remediation recommendations, validating outputs and handling data according to sensitivity and security requirements.
Promotes reuse-first, AI-assisted approaches to streamline recurring control testing and reporting routines, ensuring human review and alignment to governance standards.
Required qualifications, capabilities, and skills
- Obtain 3 plus years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk identification, assessment, and mitigation
- Experience in risk identification, assessment, and control evaluation, with a strong understanding of industry standards
- Must be proficient in Alteryx, Microsoft Suites (PowerPoint, Word, Excel etc.) and in Compliance and Operational Risk Evaluation (CORE) system.
- Proficient knowledge of risk management frameworks, regulations, and industry best practices
- Demonstrated experience using enterprise-authorized AI capabilities within the work environment to support technology risk and controls workflows with strong validation habits and awareness of data sensitivity.
- Ability to review and validate AI-assisted risk summaries and recommendations before use, escalating when uncertain and following data handling expectations.
Preferred qualifications, capabilities, and skills
- CISM, CRISC, CISSP, or other industry-recognized risk certifications
- Must be proficient in Alteryx and prior experience in Control Management
- Proven track record in data management and quality analysis.
#CTC