NIST CSFISO 27001COBITMicrosoft ExcelMicrosoft OfficePower BI
Full Job Posting
Key Roles & Responsibilities
Second Line Oversight & Framework Integration
Define and embed Technology Risk (IT & Information Security) appropriately within the Operational Risk Taxonomy and Framework, ensuring clear, documented delineation of 1LOD vs 2LOD accountability in line with company’s governance models.
Provide independent 2LOD oversight of the Technology Risk Management Framework, assessing its alignment and interdependency with first-line control frameworks (e.g. Third-Party Risk Management, IT Controls, Cybersecurity, etc.) and ensuring coherence with second line Operational Risk and Resilience frameworks.
Support the maturation of a consistent service-based view of technology risk by challenging 1LOD mapping of applications, infrastructure and third-party ICT services to internal and client-facing business services.
Risk Identification, Assessment & Challenge
Review and challenge first line identification and assessment of technology risks, including (i) application risk (ii) infrastructure dependencies (iii) information security risks and (iv) third-party technology dependencies, ensuring consistency with the company’s risk taxonomy and regulatory expectations.
Assess the quality, completeness, and consistency of Technology Risk Registers, control inventories, incident remediation activities and impact analysis.
Provide credible 2LOD challenge where risk assessments, severity ratings, or residual risk conclusions are not sufficiently supported.
Operational Resilience
Support integration of technology risk into the firm’s Operational Risk & Resilience frameworks, including regulatory/jurisdictional aligned frameworks including:
i) mapping of technology dependencies to important business services
ii) assessment of ICT/technology-related incidents and materiality thresholds
iii) align on incident classification and escalation decisions with reporting standards ensuring impacts both technically and operationally are appropriately assessed and captured on associated incident reporting portals.
Provide second line review and challenge of technology related incidents, including severity, client impact, and regulatory reporting considerations.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Accurately process transactions in our accounting system as required, understanding their impact on the NAV of the fund.
Prepare Net Asset Value packages and all supporting scheduled to be reviewed by senior members of t
Contribute and support with resilience testing and scenario analysis from a technology dependency perspective.
Third Party & Technology Dependency Risk
Provide 2LOD oversight of technology-related third-party risks, ensuring:
i) appropriate risk identification where services rely on externally procured applications or infrastructure
ii) alignment between Technology Risk and Third-Party Risk Management outcomes
Review dependency and concentration risk associated with critical technology vendors.
Change & Control Environment Oversight
Provide oversight and challenge of technology-related change activities, including:
i) IT BAU change, including change risk assessments and post-implementation validations
ii) technology elements of business change
iii) changes impacting critical services or client-facing platforms
Conduct thematic reviews of incidents, audit findings, or control weaknesses, and assess whether these indicate systemic risk or control gaps.
Governance & Reporting
Draft and peer review committee papers and support where required the delivery of periodic reporting to management and governance forums.
Deliver on annual requirement to report and present the second line technology framework (i.e. annual DORA attestation) as well as contribute risk reporting on technology risk themes for senior management and risk committees.
Translate technical risk information into clear, business-relevant risk insights for non-technical stakeholders.
Support the Head of Risk in setting, monitoring, and challenging technology-related risk appetite. Stakeholder Engagement & Collaboration:
Partner with senior first line leaders and control functions to embed risk and resilience principles in business planning and oversee and support the development of technology risk reporting. ·
Candidate should be comfortable facing challenges from CISO/CIO/CTO levels in addition to demonstrated ability to manage relationships within a parent company structure involving cross-collaboration within Risk, such as Enterprise, Data, Operational Risk & Resilience.
Education Requirements
Post-secondary degree in technology, business or a related discipline plus qualification in CRISC, CISSP, CISM
Fluency with frameworks such as NIST CSF, ISO 27001 / 27002, COBIT to facilitate an oversight role
Professional qualification in risk or a related discipline would be preferred but not essential
Work Experience
10+ years’ experience operating in a second line or independent risk oversight role overseeing Technology Risk, IT Risk, Cyber Risk in a financial institution or compatible industry
Experience within governance, oversight programs of IT Architecture, Application and EUC development and deployment
Familiarity with information management frameworks through the lens of technology risk (inclusive of cyber and information security)
Experience engaging credibly with senior technology and business stakeholders
Strong written and verbal communication skills, particularly in translating technical issues into business risk
Functional/Technical Skills and Knowledge Requirements
Essential
Experience with DORA, operational resilience, or similar regulatory regimes
Experience working in fund services, asset servicing, or regulated financial services
Exposure to multi-entity or cross-jurisdictional regulatory environments (e.g. Ireland / Cayman)
Proactive, solution-oriented mindset with the ability to work effectively in a fast-paced environment.
Advanced proficiency in Microsoft Excel and experience of onboarding new systems / technology are preferred
Strong IT skills with strengths in Microsoft Office products
Preferred
Proficiency in Power BI, Tableau, and Power Apps for data visualisation and dashboard creation.
Experience with Excel, SharePoint, and Microsoft 365 tools for workflow automation
Take a look at our careers site and you’ll find everything you’d expect from a career with the fastest-growing business at one of the world’s largest financial groups. Now take another look. Because it’s how we defy expectations that really defines us. You’ll feel that difference in all kinds of ways. Our vibrant CULTURE. Connected team. Love of innovation, laser client focus, and next-level LEARNING & DEVELOPMENT.
So, why settle for the ordinary? Apply now for a Brilliantly Different career.
We thank all candidates for applying; however, only those proceeding to the interview stage will be contacted.
About MUFG Investor Services
Banking2200 employeesFounded 2013
Private MUFG subsidiary providing fund administration and asset-servicing solutions to public and private alternative-investment funds.