Technology Risk and Assurance Specialist
Job Overview
Job title: Technology Risk and Assurance Specialist
Job description: We are looking for a Technology Risk and Assurance Specialist to support the effective oversight and monitoring of IT Risk across Rio Tinto. This position is 2nd Line and critical to the embedment of risk and controls, and provides subject matter expertise covering a full spectrum of Technology risks (including but not limited to system continuity, information and cyber security, IT project, IT operations, and third party risk management).
Stakeholder Engagement
- Establish and maintain effective relationships with key stakeholders, leaders and team members within AMER/EMEA (specifically) and the broader organisation, including local and extended Cyber teams, IS&T teams (Operations, Delivery Hubs, Canadian Hub in particular), Risk AoE Business Partners, Group Internal Audit, Business Functions / Operations Leaders.
- Undertake a lead role within the region as the Single Point of Contact for technology risk and assurance domains.
Risk and Assurance – Reviews
- Lead the execution of risk and assurance reviews within the AMER/EMEA region, with the objective of measuring risk and control effectiveness against applicable frameworks and standards such as the IS&T Controls Framework (COBIT based), This includes:
- collaboration with function such as Ethics and Integrity, RT Legal, to take into consideration legal and regulatory requirements.
- collaboration with Cyber teams taking into consideration past security risk assessments and compliance assessments
- Proactively drive identification of potential solutions to remediate gaps identified from assurance reviews working closely with control owners.
- Support risk and assurance activities in other regions as necessary.
Risk and Assurance – Management
- Lead the maturity and improvement of risk culture and practice, supporting first line management in applying effective risk practices and generating appropriate risk behaviours, including maintenance of risk registers, controls and actions (maintained in Archer).
- Monitor key risks and control data and assist in the data collection, coordination and trend reporting of IS&T risk activities.
- Contribute to the continuous improvement of the IS&T Controls Framework and Risk Management Framework.
- Re-define risk registers and attend risk reviews as part of role development.
About you
Seeking an experienced technology risk professional to support the effective oversight and monitoring of IT Risk across Rio Tinto. The role forms a part of the 2nd Line Risk and Assurance team and provides subject matter expertise covering a full spectrum of Technology risks (including but not limited to system continuity, information and cyber security, IT project, IT operations, and third-party risk management).
To be successfully considered for this role, you will have:
- Post-secondary education or bachelor’s degree, in business, management, compliance or audit or IT Management or related degree
- Minimum 5 years’ experience as an IT Business Analyst or in an IT governance & compliance role for a large enterprise, or equivalent professional services experience
- Ability to work unsupervised with high personal standards and integrity, and in a highly deadline driven environment
- Bilingual is an asset
- Experience within a Technology Risk management/compliance function and technology controls programs and risk domains, Project Management,g. Change Management, SDLC, data protection practices, risk assessment frameworks, etc
- Knowledge in areas of Information Security, Operational Risk and IT governance
- Ability to manage multiple priorities/projects simultaneously, including the ability to manage relationships with internal stakeholders and resolve challenging issues
- Excellent problem-solving skills with the ability to proactively identify issues and solutions
- Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or Certified Governance of Enterprise IT (CGEIT) is desirable
Where you will be working
Rio Tinto Information Systems and Technology (IS&T) operates to enable better alignment with customer priorities, end-to-end accountability and flexibility to prioritize critical work. The function provides solutions that are aligned with current and future business requirements through the development and ongoing delivery of IT strategy and solution roadmaps. Through appropriate governance, consultative processes, and the use of industry best practices, IS&T also ensures that emerging technologies and innovative ideas are constantly evaluated, considered, and adopted, to provide easy-to-use, best-in-class solutions and services.
About us
Every idea, every innovation, every little thing the world calls ‘progress’ begins with a first step, and someone willing to take it: explorers, inventors, entrepreneurs. Pioneers.
For nearly 150 years, Rio Tinto has been a company of pioneers – generations of people spanning the globe, all with the grit and vision to produce materials essential to human progress.
Our iron ore has shaped skylines from Shanghai to Sydney. Our aluminium – the world’s first to be certified “responsible” – helps planes fly and makes cars lighter. Our copper helps wind turbines power cities and our boron helps feed the world and explore the universe. Our diamonds help us celebrate the best parts of life.
Every Voice Matters
At Rio Tinto, we particularly welcome and encourage applications from Indigenous Peoples, women, the LGBTQIA2 community, mature workers, people with disabilities and people from different cultural backgrounds.
We are committed to an inclusive environment where people feel comfortable to be themselves. We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome – they are essential to our success. We treat each other fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation, or anything else that makes us different.
Apply today if you want to work with the latest technology and innovation, in an environment where we challenge you to drive positive change.
Please note, in order to be successfully considered for this role you must complete all pre-screening questions.
Company: Rio Tinto
Expected salary:
Location: Montreal, QC
Job date: Sat, 12 Jun 2021 07:07:17 GMT