Job Description:
Position Description:
Identifies risk by performing readiness assessments for externally audited systems. Provides technical assistance on risk related systems issues and serves as a liaison for technology risk management. Determines appropriate KPIs/KRIs for IT risk monitors. Oversees the management of controls and the mitigation of risk related to the technology environment, systems, and processes. Works closely with technology and business owners, compliance and cybersecurity teams, Information Security Officers (ISOs), and external auditors and regulators. Keeps abreast of the updates in industry standards, frameworks, and methodologies.
Primary Responsibilities:
Performs proactive risk and control assessments, monitors technology controls, documents and oversees remediation plans, consults on technology control readiness, and engages with internal/external audit.
Assesses the various information technology risks that the business faces in its operations and implements action plans, policy and procedural changes for risk avoidance and mitigation.
Provides technical assistance on risk-related technology controls.
Evaluates control maturity by performing control design and operates effectiveness reviews and peer reviews as needed.
Conducts in-depth information technology risk assessments including documents controls, identifies potential gaps and/or inconsistencies and makes sound recommendations for improvement and/or mitigation.
Consults on information security standards and industry best practices.
Answers questions from internal and external audit on information technology controls.
Tracks action steps and ensures that findings are remediated appropriately and in a timely manner.
Participates, develops and leads application code and test code reviews with Analytics team.
Builds and maintains collaborative working relationships with Information Technology and Business personnel to design and assist in the execution of appropriate controls design and monitors.
Develops communications for both internal and external audiences.
Education and Experience:
Bachelor’s degree (or foreign education equivalent) in Computer Science, Engineering, Information Technology, Information Systems, Mathematics, Physics, or a closely related field and three (3) years of experience as a Senior Technology Risk Analyst (or closely related occupation) defining and executing technology strategy and risk management using a comprehensive governance, risk, and compliance (GRC) platform in a financial services environment.
Or, alternatively, Master’s degree (or foreign education equivalent) in Computer Science, Engineering, Information Technology, Information Systems, Mathematics, Physics, or a closely related field and one (1) year of experience as a Senior Technology Risk Analyst (or closely related occupation) defining and executing technology strategy and risk management using a comprehensive governance, risk, and compliance (GRC) platform in a financial services environment.
Skills and Knowledge:
Candidate must also possess:
Demonstrated Expertise (“DE”) auditing internal controls and examining regulatory (ISO27001, ISO27701, and ISO27017) standards and financial risk (SOC1, SOC 2, and SOX 404) for institutional and asset management business units (managed accounts, treasury, advisory, fixed, and high-income securities) and mutual fund operations (fund accounting and money movement) using ICOFR, AICPA, COSO Internal control, and COBIT frameworks.
DE identifying suitable KPIs and KRIs; performing Information Technology Application Controls (ITACs) and Information Technology General Controls (ITGCs) audits to evaluate internal controls’ effectiveness, physical and logical access, change management, program development, and computer operations; and assessing business-facing IT risks and implementing action plans using access management tools (Access Hub, and SailPoint), configuration management tools (ServiceNow) and data analytic tools (PowerBI and Alteryx).
DE evaluating data integrity controls for REST API interfaces and ETL applications using Informatica and Control M; assessing completeness and accuracy of OBIEE and Oracle Database reporting; conducting proactive risk and control assessments for financial performance calculations; and evaluating security controls on technology infrastructure in Windows and Mainframe environments.
DE documenting audit findings, collaborating with various business stakeholders, implementing controls to ensure IT systems and processes comply with relevant regulations and standards, and creating and monitoring controls using Archer and Workiva; and overseeing remediation plans, consulting on technology control readiness, and providing recurring management status to the senior management.
#PE1M2
#LI-DNI
Certifications:
Category:
Information TechnologyFidelity’s hybrid working model blends the best of both onsite and offsite work experiences. Working onsite is important for our business strategy and our culture. We also value the benefits that working offsite offers associates. Most hybrid roles require associates to work onsite every other week (all business days, M-F) in a Fidelity office.
Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.