Jobs
>
Bengaluru

    Control & Risk Assessment Leader - Bengaluru, India - EY

    EY
    EY background
    Description
    EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

    Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.

    Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

    The opportunity

    The Technology Assurance, Risk, and Policy (TARP) function within Information Security strives to create and promote a holistic Governance, Risk, and Compliance (GRC) program by creating a robust, resilient, and proactive governance framework, supported by a strategic risk management approach and stringent compliance structures. It aims to integrate and align its GRC initiatives in line with the global firm's objectives and emerging threats within the cybersecurity landscape.

    Furthermore, the Policy, Risk, and Controls (PRC) Enablement & Awareness team aims to establish policies and procedures that reflect the value we place on safeguarding our digital environment, while ensuring that these policies are effectively communicated and enforced across all levels of the organization. The Control & Risk Assessment team sits within PRC Enablement & Awareness and aims to directly enables the GRC program by designing control testing and risk assessment methodology to measure and quantify compliance to policies and control objectives.

    Your key responsibilities

    The Control & Risk Assessment Leader will be responsible for building a control testing and risk assessment program, following the model for 1st line and 2nd line testing best-practice strategies, that routinely tests and assesses the effectiveness and efficiency of Information Security controls put in place to mitigate risks to determine if they are supporting the desired business outcomes. They will need to rank and prioritize Information Security controls based on their risk profiles and design a testing plan to inclusive of testing procedures which will be used to measure effectiveness while, simultaneously looking for opportunities to enhance and improve EY's control landscape. In certain instances, they will need to plan and execute risk assessments to quantify assumptions over the risk profiles.

    The Control & Risk Assessment Leader is responsible for building a team of experienced professionals to assist in executing the strategic vision and objectives of the Control & Risk Assessment testing and assessment program. The Control & Risk Assessment team will work collectively to support the Information Security Program in the areas of risk risk assessment methodology development and execution of risk assessments, control testing design and execution, and identification of gaps and areas of improvement utilizing testing and assessment results.

    Collaboration with other Information Security groups and external stakeholders across EY is key to this role. The Control & Risk Assessment Leader will need to build a network of multi-departmental and multi-level stakeholders inclusive of, but not limited to Information Security, Client and Enterprise Technology, Data Protection, Global and Enterprise Risk Management, Internal Audit, Area and Regional Risk & Data teams, Service Line Quality Leaders, etc.

    Skills and attributes for success

    • Plan and build multi-year roadmap to establish and mature the Control & Risk Assessment team. This includes development of the team's charter, identification of resource needs, ongoing monitoring systems and tool requirements, and workstream prioritization.
    • Build a Control and Risk Assessment program that identifies potential risks and validates mitigation controls by conducting regular and systematic assessments of the organization's IT infrastructure, including networks, systems, applications, and data processes.
    • Based on results of assessments and testing, assist control owners with the design and implementation of their controls in the organization's IT environment. Strategize on the appropriate amount of preventive, detective, or corrective controls which will have the most impact on reducing overall risk for the firm.
    • Create a 1st Line Testing framework that can be shared with control owners that will enhance security culture and support control ownership roles and responsibilities. Conduct training and awareness campaigns to facilitate the adoption of the framework.
    • Appropriately balance firm security needs with business impact and benefit when recommending advancements in policy and control objectives and directing those efforts to completion.
    • Think strategically to assist with the development of a long-term vision for Information Security's Technology Assurance, Risk, and Policy direction inclusive of its program improvement, technology adoption, and integration of security solutions into business objectives.
    • Act as a thought leader in the firm, staying informed of changes in information security, regulatory requirements, audit standards, and industry trends, adjusting strategies, as necessary.
    • Build and maintain appropriate relationships with internal and external leaders to ensure awareness and understanding of potential strategic directions.
    • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change.
    • Outstanding management, interpersonal, communication, organizational, and decision-making skills.
    • Ability to understand and integrate cultural differences and motives and to lead cross cultural teams.
    • Demonstrate integrity and judgment within a professional environment.
    • Evaluate, counsel, mentor and provide feedback on performance of others.
    • Plan the training and development of staff to develop their skills and maintain state-of-the-art knowledge in information security.

    To qualify for the role you must have

    • 10+ years of experience in the Information Technology, Information Security and/or Risk Management field(s).
    • Audit experience or a demonstrated ability to design and test technology controls.
    • 5+ years of experience in managing and mentoring junior and senior level staff.
    • Experience leading global and virtual teams.
    • High proficiency in technical and general writing skills in English.
    • An advanced degree in Computer Science, Information Security, or a related field; equivalent work experience will be considered on a case-by-case basis.
    • One or more of the following or equivalent certifications preferred: Certified Risk and Information Systems Control (CRISC), Certified Information Systems Security Processional (CISSP), Certified Information Security Manager (CISM), Certified Information System Auditor (CISA), Certified Internal Auditor (CIA), Global Information Assurance Certification (GIAC) in related area, CIPP, CIPT.

    Ideally, you'll also have

    • A working knowledge of external control standards like ISO 27001, NIST 800-53, COBIT, etc. and regulatory requirements like GDPR and SOX.
    • Skilled in Microsoft Office and M365 products; primarily Word, Excel, PowerPoint, SharePoint, PowerApps, and PowerBI.
    • Experience with RSA Archer or other GRC tools.
    • Flexibility to work outside of normal business hours when engaging with team members and stakeholders in various time zones.


    What we offer

    The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges.

    We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The salary range for this job in most geographic locations in the US is $136,300 to $254,900. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $163,600 to $289,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
    • Continuous learning: You'll develop the mindset and skills to navigate whatever comes next.
    • Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
    • Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs.
    • Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs.


    If you can demonstrate that you meet the criteria above, please contact us as soon as possible.

    The exceptional EY experience. It's yours to build.

    EY | Building a better working world

    EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

    Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

    Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

    EY is an equal opportunity, affirmative action employer providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

    EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, type Option 2 (HR-related inquiries) and then type Option 1 (HR Shared Services Center), which will route you to EY's Talent Shared Services Team or email SSC Customer Support at


  • NASDAQ Bengaluru, Karnataka, India

    Group Risk Management (GRM) collaborates with businesses as a trusted advisor, facilitating well-informed decisions that support Nasdaq's strategic objectives. GRM manages and continues to enhance the Enterprise Risk Management, Internal Control, Business Continuity, Crisis Manag ...

  • CSG Talent

    Iot Pentester

    2 days ago


    CSG Talent Bengaluru, India

    **IoT Penetration Tester - Hybrid** · **Are you an experienced IoT penetration tester with product security?** · **Would you like to make an impact and champion a growing world leader within the TIC industry, focused on product security? s** · *** · CSG Talent has established a s ...


  • ADCI - Karnataka Bengaluru, Karnataka, India

    Bachelor's degree, or equivalent experience with 4+ years in HR/ business partnering. · - Demonstrates business and HR acumen, including problem-solving skills, critical thinking, and analytical acuity. · - Proficient in partnering effectively with senior leaders through skillful ...

  • Microsoft

    Account Executive

    2 days ago


    Microsoft Bengaluru, Karnataka, India

    **Overview**: · Microsoft's mission is to empower every person and organization on the planet to achieve more. Our culture is centered on embracing a growth mindset, being diverse and inclusive and encouraging teams and leaders to bring their best each day. Growth mindset encoura ...

  • Capgemini

    Financial Planning

    6 days ago


    Capgemini Bengaluru, India

    Preparation of annual budget and monthly rolling forecast · - Variance Analysis · - Manage and track the Key Performance Indicators (KPI's) along with operations and business leaders · - Create and Build dashboards · - Assessment of risks and opportunities associated with the acc ...

  • Capgemini

    Financial Planning

    5 days ago


    Capgemini Bengaluru, India

    **Job Description**: · - Preparation of annual budget and monthly rolling forecast · - Variance Analysis · - Manage and track the Key Performance Indicators (KPI's) along with operations and business leaders · - Create and Build dashboards · - Assessment of risks and opportunitie ...


  • Capgemini Bengaluru, India

    Experience in core IT Risk, Compliance, and security projects. · - Strong familiarity with industry frameworks such as ISO standards, GDPR, NIST, PCI DSS. Broad understanding of cyber security concepts and risks. · - Experience in assessment of audit findings / gaps including con ...

  • Texmo Industries

    Warehouse Assistant

    1 week ago


    Texmo Industries Bengaluru, Karnataka, India

    Job Description: We are seeking a talented and motivated Frontend performer with expertise in Accounts / supply chain function, Basic Excel, Communication & Presentation skill to join our dynamic SCT team. As Branch accountant, you will play a pivotal role in accounts and supply ...

  • Eurofins India NSC

    Internal Auditor

    2 days ago


    Eurofins India NSC Bengaluru, India

    Company Description · Eurofins Scientific is an international Group of life sciences companies which provide a unique range of analytical testing services to clients across multiple industries. · The Group believes it is the global leader in food, environment, pharmaceutical and ...

  • Koch Global Services

    HRbp

    1 day ago


    Koch Global Services Bengaluru, India

    **Description** · Koch Industries, Inc. has an HR Business Partner opportunity. This position will work to build strong rapport and relationships alongside employees and leaders in the location while empowering supervisors to grow and transform with the business. They will be cru ...


  • JPMorgan Chase Bank, N.A. Bengaluru, India

    Primary Responsibilities · - Perform independent Quality review activities to validate quality, completeness and accuracy of technology assessments delivered, including pre-closure review of significant issues and findings stemming from these assessments · - Lead analysis on Qual ...

  • Cureskin

    Dermatologist

    1 week ago


    Cureskin Bengaluru, India

    CureSkin is an innovative tech-driven company solving dermatology (Skin and Hair) issues for users in India, using advanced AI technology through our mobile app. Through our advanced image recognition, we assist in the assessment of skin problems and provide treatments. We are fu ...


  • RSM US LLP Bengaluru, India

    We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture ...


  • Synergia Foundation Bengaluru, Karnataka, India

    **Intelligence. Intervention. Impact**: · The Synergia Foundation is a highly regarded independent thinktank based in Bangalore. Our mission is to deliver insight, impact and intervention on issues that affect each of our lives. · We engage leaders _from_ government, business and ...

  • Moody's

    Avp-talent Strategy

    6 days ago


    Moody's Bengaluru, India

    **The Role / Summary**: · The Senior Talent Strategy role will be a key member on the Talent Strategy & Employee Experience team who will partner closely with the Global Talent Strategy Leader, People Team leadership, and Moody's business leaders to drive best practice talent str ...


  • Capgemini Bengaluru, India

    Preparation of annual budget and monthly rolling forecast · - Variance Analysis · - Manage and track the Key Performance Indicators (KPI's) along with operations and business leaders · - Create and Build dashboards · - Assessment of risks and opportunities associated with the acc ...


  • Career flight consultancy Bengaluru, India

    **Title: SCIENCE SUBJECT MATTER EXPERT- Secondary** · **Job Summary**: A leader who is in charge of ensuring the quality delivery of curriculum prescribed by the board and focusing on approaches required to enhance the student's knowledge and competencies · **Reports to**: HM · * ...

  • Airbnb

    Talent Partner

    4 days ago


    Airbnb Bengaluru, India

    Airbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences ...

  • Julius Montz GmbH

    HRbp

    2 days ago


    Julius Montz GmbH Bengaluru, India

    **Description** · Koch Industries, Inc. has an HR Business Partner opportunity. This position will work to build strong rapport and relationships alongside employees and leaders in the location while empowering supervisors to grow and transform with the business. They will be cru ...

  • EY

    Ccass Sm

    1 week ago


    EY Bengaluru, India

    At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better, too. Join us and build ...