Risk and Controls Testing Expert – Digital Operational Resilience
We are seeking a highly skilled Risk and Controls Testing Expert to join our Digital Operational Resilience team. This role is critical in ensuring that our organization maintains robust operational resilience in line with regulatory requirements and industry best practices. The successful candidate will design, execute, and report on control testing activities to assess the effectiveness of compliance and risk management frameworks, focusing on systems, platforms, policies and processes.
________________________________________
Key Responsibilities:
• Control Testing & Assurance
o Develop and execute comprehensive testing plans for operational resilience controls across our environments.
o Perform independent assessments of control design and operating effectiveness.
o Identify gaps, weaknesses, and areas for improvement in resilience controls.
• Risk Management & Compliance
o Ensure alignment with regulatory frameworks such as Swift Oversight Law, DORA (Digital Operational Resilience Act) and internal audit, compliance and risk policies.
o Support risk assessments and contribute to the development of remediation plans for identified issues in close collaboration with the programme manager.
• Reporting & Documentation
o Prepare detailed reports on testing outcomes, including findings, recommendations, and risk ratings.
o Maintain accurate documentation of testing methodologies and evidence for audit and regulatory reviews.
• Stakeholder Engagement
o Collaborate with colleagues in Technology Platform and security, Core Operations, Product, audit and risk teams to strengthen resilience capabilities.
o Provide expert guidance on control improvements and risk mitigation strategies.
________________________________________
Qualifications & Skills:
• Education: Bachelor’s degree in Risk Management, Information Security, IT, or related field.
• Experience:
o 5+ years in risk management, internal controls testing, or operational resilience within financial services or regulated industries.
o Strong understanding of digital operational resilience frameworks and regulatory requirements (e.g., DORA, BIS2, ISO 27001, etc.).
o Fluent English
• Technical Skills:
o Familiarity with IT systems, cybersecurity controls, and resilience testing methodologies.
o Proficiency in risk assessment tools and reporting platforms. Knowledge of Jira and SNOW is an asset.
• Soft Skills:
o Analytical mindset with attention to detail.
o Strong communication and stakeholder management skills.