Job Details

ID #17130513
State Texas
City Westlake
Job type Permanent
Salary USD TBD TBD
Source Charles Schwab & Co., Inc.
Showed 2021-07-22
Date 2021-07-21
Deadline 2021-09-19
Category Security
Create resume

Principal, Technology Risk Manager

Texas, Westlake, 76262 Westlake USA

Vacancy expired!

Your Opportunity

In Corporate Risk Management (CRM), we provide an integrated risk management strategy that supports the delivery of predictable financial and operational performance in order to produce successful client and shareholder outcomes. We are organized around six primary functions: Bank Risk, Enterprise Risk, Information Security Risk Management, Market and Investment Risk, Model Risk and Operational Risk. Within each of these areas, we develop a framework for how much risk we are willing to accept as a firm and establish processes for identifying, evaluating, measuring, monitoring, and reporting against that framework. In Information Security Risk Management, we support that framework across information and technology to protect client assets, client information and firm assets.

What you are good at

The Principal, Application Risk Management (ARM), as a second line of defense function, is responsible for a) proactively identifying, measuring, assessing and reporting application risk exposure, b) execute application risk management policy, oversee and assess adherence to policy, and report maturity progress to management, and c) assessing ongoing adherence to security standards and best practices by conducting recurring and ad-hoc risk assessments on platforms and applications.

Responsibilities include:

  • Help design and execute risk-centric policies for application risk management. Partner with development and business teams to assure policy compliance is communicated and path forward is understood.
  • Conducting policy oversight, collaborating with business and development teams to document risk management requirements, assess application design and architecture for compliance with published standards, and perform risk assessments where appropriate.
  • Maintain and evolve the measurement of KPI's/KRI's to monitor risk reduction.
  • Assess the application risk management space on a periodic basis to evolve the strategy to adapt to emerging threats and capabilities.

Principle Duties and Responsibilities:

  • Provide Effective Challenge & Policy Oversight
  • Develop and articulate secure application risk management strategies that continuously monitor and improve the security of customer-facing and internally facing applications. Effectively challenge 1st line of defense roadmaps to continuously improve responses to the changing risk landscape.
  • Collaborate with business and technology teams to create and maintain application risk management policies and standards reflecting the firm's risk appetite and industry best practices to assure robust controls.
  • Provide credible risk assessments and independent reporting
  • Liaison with product management and technology to assure risk management requirements are considered throughout the project lifecycle and across the portfolio.
  • Conduct oversight on identified vulnerabilities and remediation activities and provide reporting to business, technology, and risk management leaders. Provide support to keep mitigation plans on track for timely delivery.
  • Lead discussions with business units to review and approve mitigation strategies for vulnerabilities and areas of non-compliance with information security policy and standards.
  • Participate in defining, executing, and maturing the Secure Software Development Lifecycle (SSDLC).
  • Participate in continuous monitoring of adherence to Secure Application Development and other policies and standards.
  • Build and Maintain Relationships
  • Align with stakeholders from all three lines of defense regarding application and information security risks to the business units.
  • Work with internal auditors and regulators to articulate our application risk management framework, execution progress, and how application-level cybersecurity risks are managed at Schwab.
  • Work closely with technology and business teams to establish acceptable risk thresholds and perform assessments against the firm's established risk appetite and approved thresholds.

What you have

  • Bachelor's degree plus CISSP, CISM, or equivalent certification is preferred
  • 5+ years of experience in a risk, supervision/controls, compliance, or audit function
  • 5+ years' experience in the Information Security field
  • 2+ years of experience in financial services,
  • Direct experience working within Application Security, Development, Software Testing and Risk Management required
  • Experience with authoring, maintaining, and implementing IS Policies and Standards
  • Knowledge and experience in risk control frameworks such as NIST, ISO as well as regulatory and industry requirements such as GLBA, PCI, FFIEC
  • Experience with data analysis and reporting
  • Ability to effectively communicate with technical and executive audiences; both oral and written is required
  • Experience interfacing with auditors in support of audits and external regulatory exam processes is required
  • Experience with working with partners at all levels and across functional lines, bringing diverse points of view together to determine a clear direction forward
  • Thrive in a constantly evolving environment and meet critical commitments under pressure
  • Manage complicated issues and arbitrate across disparate partner groups
  • Conduct metrics and status reporting
  • Experience with GRC and Workflow tools such as IBM OpenPages or RSA Archer and Policy Tech or Policy Hub
  • Hands on experience with Agile/ Scrum methodology
  • Experience in gathering requirements, documenting, and assessing information for implementing information security policies and standards is required
  • Ability to work independently and proactively, with minimum guidance
  • Ability to work on multiple projects simultaneously while prioritizing based on risk/business needs
  • Effective organizational and time management skills
  • Excellent interpersonal, written, and verbal communication skills; demonstrated presentation skills
  • Ability to think strategically with sharp analytical skills and strong attention to detail and accuracy
  • Strong interpersonal, analytical, problem-solving, influencing, prioritization, decision-making and conflict resolution skills
  • Strong initiative; self-starter; self-directed; ability to multi-task
  • Experience writing, maintaining, testing, auditing, and revising policies and procedures
  • Understand the familiarity of laws and regulations within financial services for retail facing positions
  • Experience analyzing data and preparing solutions based on sound facts and findings
  • Self-starter with a can-do attitude who is capable of building relationships and influencing effectively within a matrixed organization
  • Experience in project planning, meeting facilitation for multiple groups and projects is preferred

Preferred Competencies:

Advanced degree such as MBA, professional designation such as CPA and/or prior Big 4 public accounting experience

CISA, CISM, CRISC, or equivalent certification

Why work for us?

Own Your Tomorrow embodies everything we do! We are committed to helping our employees ignite their potential and achieve their dreams. Our employees get to play a central role in reinventing a multi-trillion-dollar industry, creating a better, more modern way to build and manage wealth.

Benefits: A competitive and flexible package designed to empower you for today and tomorrow. We offer a competitive and flexible package designed to help you make the most of your life at work and at home-today and in the future. Explore further .

Schwab is committed to building a diverse and inclusive workplace where everyone feels valued. As an Equal Opportunity Employer, our policy is to provide equal employment opportunities to all employees and applicants without regard to any status that is protected by law. Please click here to see the policy.

Schwab is an affirmative action employer, focused on advancing women, racial and ethnic minorities, veterans, and individuals with disabilities in the workplace. If you have a disability and require reasonable accommodations in the application process, contact Human Resources at or call.

TD Ameritrade, a subsidiary of Charles Schwab, is an Equal Opportunity Employer. At TD Ameritrade we believe People Matter. We value diversity and believe that it goes beyond all protected classes, thoughts, ideas, and perspectives.

Vacancy expired!

Subscribe Report job