
AVP- Digital Finance & Artificial Intelligence (AI) Risk Management
- Heredia
- Permanente
- Tiempo completo
- At least five years of experience specific to technology governance, risk and control, self-assessment, identifying and evaluating control measures, and compliance with financial services, particularly in AI and digital finance.
- Technology and Industry Expertise: Broad experience in digital finance and AI technologies at substantial scale and complexity within global, highly regulated environments, with a focus on technology and data innovation.
- Strategic Leadership: Proven ability to evaluate and prioritize key initiatives, balance diverse stakeholder needs, and drive alignment across digital finance, AI, technology, and data domains.
- Collaboration and Communication: Exceptional verbal and written communication skills, with expertise in building relationships between business and technical stakeholders, influencing cross-functional teams, and leading large-scale projects.
- Analytical and Independent Problem-Solving: Clear thinker with strong analytical skills to assess complex processes, adapt to changing environments, work independently, and deliver results in dynamic, enterprise-wide initiatives.
- B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cyber Security or equivalent).
- Relevant certification is desirable, e.g., CISSP, CISM, CISA. Working knowledge of Risk Management life cycles based on established frameworks: NIST, COBIT, ORX, ISO 27001.
- Experience in Open Pages or other GRC tools and broader MS Office suite products.
- Review and Challenge: Independently review and challenge the Digitial Economy risk profile, ensuring compliance with the ORM framework and adherence to applicable policies, standards, and procedures.
- Governance and Reporting: actively engage in committees/forums, provide updates on the Technology risk profile, and ensure effective use of the Governance, Risk, and Compliance (GRC) tool for timely and accurate ORM-related activities.
- Risk and Control Self-Assessments (RCSA): Challenge the 1st LoD's RCSA processes, including risk identification and control assessment results; ensure timely escalation and reporting in line with ORM standards.
- Issue Management: initial challenge of the identification, documentation, response, and reporting of issues in-line with the Issue Management standard, including completeness and accuracy of documented issues, assigned impact ratings, escalation of past due issues, and challenging closure to ensure completed actions are evidenced and sufficient to mitigate the risk.
- Operational Risk Events (ORE's): initial challenge that the appropriate response, escalation, documentation, and reporting is in-line with the ORM framework, including post event root cause analysis to identify lessons learned and required actions to prevent recurrence.
- Key Risk Indicators (KRIs): initial challenge of the development and reporting of KRIs, including establishment of tolerance levels, 1LoD rationales where KRI's are out of tolerance or have changed significantly.
- Emerging & Evolving Risks: initial challenge and monitoring of emerging and evolving risks, identifying where new risks need to be reported, or current risks are significantly changing.
- Training and Stakeholder Engagement: Provide training, guidance, and support to the 1st LoD, assist in creating training materials, and act as a trusted advisor to stakeholders across business and technology functions.
- Risk Initiatives and Strategic Oversight: Challenge 1st LoD initiatives, from design to implementation, to mitigate transformation risks, and ensure forward-looking planning to address changes in the risk landscape.