CrawlJobs Logo

Enterprise Technology Risk & Controls Associate

blackrock.com Logo

BlackRock Investments

Location Icon

Location:
India , Gurgaon

Category Icon
Category:

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

In this role, you will be a key member of the first line of defence ETRC Assessment & Reporting team, where you will be responsible for supporting internal risk identification programs akin to the RCSA supported by automated metrics, dashboards & reporting. The role will also assist in embedding a culture of risk identification and leveraging data and metrics to identify current and emerging risk themes across BLK.

Job Responsibility:

  • Support and identify enhancements for firm wide Risk Identification programs centred on the annual RCSA program
  • Support the BLK annual RCSA process across multiple first line technology entities & teams
  • Collaborating with the other 3 ETRC pillars and other risk partners to identify emerging risks
  • Support the development, maintenance & enhancement of executive-level and operational business reports using Power BI
  • Design, develop, and implement reporting solutions including automation to meet management and regulatory reporting requirements
  • Execute deliverables to deliver timely, accurate, and efficient service for scheduled reporting production processes
  • Prepare, deliver & enhance comprehensive PowerPoint presentations for business leads
  • Continuously enhance reporting processes and tools to improve efficiency, productivity and effectiveness
  • Support the production of existing Aladdin Platform Engineering & Aladdin Product Engineering and firmwide BLK expansion of Risk Estate reports
  • Ensure accurate and timely reporting of technology risk and control metrics
  • Identify and implement process improvements (including Artificial Intelligence – AI options) to enhance team performance

Requirements:

  • 3+ years of experience in asset management, financial services or technology in a technology operational risk-related role
  • Working knowledge of financial markets, asset classes & products
  • CISA or CRISC certification preferred
  • Skilled in identifying trends, measuring control effectiveness, and presenting actionable insights
  • Proven ability to partner with diverse teams
  • Structured critical thinker with superior problem-solving abilities
  • Strong grasp of content, business models, interest in technology, markets, and geopolitical trends
  • Demonstrates integrity and the highest standards, with a commitment to inclusion and diversity
What we offer:
  • Strong retirement plan
  • Tuition reimbursement
  • Comprehensive healthcare
  • Support for working parents
  • Flexible Time Off (FTO)

Additional Information:

Job Posted:
February 20, 2026

Expiration:
February 28, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Enterprise Technology Risk & Controls Associate

Technology Risk Governance Manager

Help us deliver a better tomorrow. Australia Post is delivering for all Australi...
Location
Location
Australia , Richmond
Salary
Salary:
Not provided
auspost.com.au Logo
Australia Post
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Strong background in Technology Risk and IT Governance within large, complex organisations
  • Proven experience in risk management supporting technology or digital functions
  • Expertise in technology, digital and information governance, security risk, and operational frameworks such as ISO27001/2, ITIL, E8, NIST, and COBIT
  • Familiarity with APRA CPS 230/234, ISO 31000, or similar standards
  • Ability to translate and present complex technical and operational information into simple business language to engage business stakeholders
  • Demonstrated ability to influence, challenge, and engage senior business and technology leaders
  • Maintaining strong objective relationships beyond span of control
  • Excellent analytical, problem-solving, and communication skills
Job Responsibility
Job Responsibility
  • Support the proactive identification, assessment, and facilitate mitigation of technology risks across operational environments and transformation programs
  • Plan and execute regular and ad-hoc reviews into areas of significant technology risks to the organisation, including deep dives, and facilitating commercial solutions for any issues that may arise
  • Partner with delivery teams, architects, and operational leaders to integrate risk management into business-as-usual processes and project lifecycles
  • Maintain a current risk register reflecting emerging threats, system dependencies, and control effectiveness
  • Facilitate regular risk and control assessments and timely remediation of identified gaps
  • Support the Technology & Cyber Controls Assurance function in undertaking reviews against the minimum policy, standard and control requirements
  • Undertake targeted reviews of the effectiveness of key Technology controls and provide reporting & insights
  • Develop and implement risk management processes, libraries and documentation that will help improve transparency and management of enterprise and business unit technology risks and associated compliance and operational requirements
  • Provide risk advisory support for technology operations and systems within transformation projects
  • Review and challenge technology designs, change management processes, and vendor engagements from a risk perspective
What we offer
What we offer
  • Career Development: opportunities for professional growth and development
  • Work-Life Balance: flexible working arrangements
  • Employee Wellbeing: resources and support to ensure a healthy and safe work environment
  • Fulltime
Read More
Arrow Right

Risk & Information Security Associate Analyst

We are looking for a highly organized, detail-oriented Risk & Information Securi...
Location
Location
Cyprus , Nicosia
Salary
Salary:
Not provided
www-ap.albourne.com Logo
Albourne
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 2–3 years of professional experience
  • Excellent organizational skills with the ability to manage multiple workstreams and meet deadlines in a dynamic environment
  • Strong written and verbal communication skills, including the ability to prepare concise, well-structured documents and interact professionally across all levels of the business
  • Meticulous attention to detail, particularly in preparing audit materials, compliance documentation, and reviewing access controls
  • Proactive and self-motivated, able to work independently and across time zones without direct daily supervision
  • Comfortable handling sensitive and confidential information with discretion
  • Interest in technology, cybersecurity, and enterprise risk
  • Basic understanding of information security principles and frameworks (e.g., ISO 27001, NIST)
  • Ability to interpret and work with structured information (e.g., policies, risk registers, audit plans)
  • Capable of coordinating inputs from multiple stakeholders and compiling them into coherent outputs (e.g., committee papers, training summaries, client DDQs)
Job Responsibility
Job Responsibility
  • Monitor and report on the effectiveness of information security controls
  • Support the identification, tracking, and resolution of security incidents or weaknesses
  • Assist in maintaining security metrics and dashboards for internal reporting
  • Contribute to the assessment of operational, technology, and third-party risks
  • Assist in evaluating controls and proposing mitigation strategies aligned with risk appetite
  • Participate in internal audits and control testing, ensuring timely remediation of findings
  • Help maintain and enforce security and risk management policies and procedures
  • Support compliance with relevant data protection, privacy, and information security regulations
  • Coordinate periodic user access reviews and assist with awareness initiatives
  • Work across departments to gather risk-related information and support secure business operations
What we offer
What we offer
  • Support for professional qualifications (such as CFA and CAIA)
  • Career growth and tools for ongoing learning and development
  • Medical insurance for you and your dependents
  • Provident fund
  • Yearly bonus dependent upon performance and company growth
  • Opportunity for international travel (i.e., short periods of secondment to other Albourne offices)
  • 5 additional service recognition holidays in surplus to standard annual leave
  • Albourne Training Days (minimum of 40 hours per year)
  • Free office parking
  • A supportive, diverse, and multi-cultural work environment
  • Fulltime
Read More
Arrow Right

LAPC Control Execution Lead

By joining Citi Belfast, you will work as a LAPC Control Execution Lead, respons...
Location
Location
United Kingdom , Belfast
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Significant relevant work experience
  • self-motivated and accountable
  • excellent communication skills – verbal & written
  • strategic mindset with the ability to think critically, solve complex problems, and drive innovative solutions through practical outcomes
  • ability to be responsible for a strategy, process, or control portfolio
  • experience with stakeholder management or cross functional teams
  • expertise in Compliance, Operational Risk Management or other control related function within Financial Services sector
  • expert-level understanding of MCA (Managers Control Assessment) frameworks and processes
  • experienced in Movement of Funds/ Payments Operational Risk
  • knowledge of other risk disciplines (market risk, credit risk) a plus
Job Responsibility
Job Responsibility
  • Oversees the development, implementation and application of operational risk policies, technology and tools, and governance processes to create lasting solutions for deliverables on movement of funds governance as a core enterprise capability
  • governance and oversight of movement of funds, large payment controls system or process and application integration initiatives, serving as an oversight function working with lines of businesses or in business risk and control teams
  • act as escalation point centrally to communicate and escalate reviews, concerns, and breaches
  • research, document and export best practices and common risk, controls, and corrective actions through framework papers
  • ensures that movement of funds related KORs and KRCIs are communicated and understood by businesses
  • develops and maintains relationships across the business users and lines of defense to better understand and deliver control and oversight requirements
  • oversees directly related control designs, with intention of ensuring efficiency of payment controls and/or lines of business executed and tested controls
  • analyze and build a comprehensive list of relevant controls associated with the LAPC (Large Anomalous Payment Control) rules engine, to ensure proper governance and oversight by its respective accountable owners
  • develop insights for all relevant controls within the organization.
What we offer
What we offer
  • Generous holiday allowance starting at 27 days plus bank holidays (increasing with tenure)
  • a discretional annual performance related bonus
  • private medical insurance packages to suit personal circumstances
  • employee Assistance Program
  • pension plan
  • paid parental leave
  • special discounts for employees, family, and friends
  • access to an array of learning and development resources.
  • Fulltime
Read More
Arrow Right

Transformation and Controls Senior Vice President, End User Computing

Global role responsible for supporting the development and implementation of the...
Location
Location
Ireland , Dublin
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experience in Risk and Control, 2nd line Testing or Audit roles
  • Understanding of evolving governance, controls and regulatory requirements relating to technology tools and capabilities
  • Excellent communication skills and the ability to motivate and persuade colleagues across disparate businesses, regions and cultures
  • Ability to understand and operate successfully in a complex, heavily matrixed corporate environment
  • Understanding of business and technology tools expertise related to enterprise controls and control automation oversight in financial or similar firms
  • Working knowledge of Citi's End User Computing Policy, EUC Governance Programmes and business operations
  • Demonstrates history of having worked as a Programme Manager, or working on large, strategic cross-functional projects
  • Specific subject matter expertise regarding control tooling and capabilities and a strong business understanding of the products and services Citi offers
  • Demonstrated ability to lead change management across large global organisations
Job Responsibility
Job Responsibility
  • Support the design and implementation of the EUC Governance Framework for Citi
  • Work with senior leaders and their teams across multiple businesses and functions as well as second and third lines of defense
  • Partner with stakeholders to draft and implement action plans in support of regulatory requirements/commitments and Consent Order initiatives
  • Provide oversight over the EUC governance programmes including principles, policy, practices and standards including industry best practices
  • Measure Policy adherence and remedial action associated with Policy adherence
  • Engage with business and Global Functions leaders to drive EUC agenda progress
  • Support management communications relative to EUC Transformation & Governance with senior management
  • Partner effectively across the firm with key teams to drive the tools and capabilities including EUC Inventory management and workflow system capabilities
  • Support the identification, design and implementation of an appropriate tools for EUC discovery capability
  • Partner with 2nd and 3rd Lines of Defense to ensure controls relating to EUCs are adequately designed and operating effectively
What we offer
What we offer
  • Competitive base salary (annually reviewed)
  • Business casual workplace
  • Hybrid working model (up to 2 days working at home per week)
  • Benefits that support well-being, living well and saving well
  • Fulltime
Read More
Arrow Right
New

Senior Associate - Technology Risk & Control

The Enterprise Technology Services (ETS) organization partners with the American...
Location
Location
India , Bengaluru Urban; Gurgaon
Salary
Salary:
Not provided
americanexpress.com Logo
Amex
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ Years experience in operational risk management
  • Understanding of critical operational risk management lifecycle activities
  • Excellent project management, communication, and interpersonal skills, with an ability to interact and obtain buy-in from senior BU/tech counterparts
  • Expertise in process governance, with a track record of establishing and overseeing robust decision-making processes that align with policies, regulatory frameworks, and/or operational standards
  • Experience within financial services industry
  • Strong analytical and problem-solving skills, with an ability to analyze data, identify trends, and evaluate risk scenarios effectively
  • Demonstrated history and ability to manage large teams, spread over geographies and with varying backgrounds
  • Have executive presence and be able to provide status updates to senior leadership.
Job Responsibility
Job Responsibility
  • Scope, triage (prioritize), and support remediation of Issues by influencing BU, who own and execute Issue/Operational Risk Event (ORE) Remediation
  • Investigate and conduct root cause analysis while also addressing repeated Issue types
  • Perform quality assurance on documentation of Issue/ORE type, urgency, severity/impact (e.g., impact analysis), and investigate as necessary to understand and address the root causes
  • Oversee the remediation process, including tracking progress, validate resolution efficacy, and communicate status updates to stakeholders to embed accountability along the process, collaborating with other Operational Risk Management (ORM) / Control Management teams as necessary
  • Document and maintain records of Issues/OREs and Remediations to ensure transparency and accountability in the issue management process
  • Analyze trends in Issues and events to identify potential systemic risks or control weaknesses within BU processes
  • Support and oversee the End-to-End (E2E) Issue resolution process, embedding accountability and ensuring lessons learned are integrated into future ORM practices
  • Perform sample testing of Issues to ensure resolution is complete and effective
  • Opine on specific control enhancements related to Issues
  • Engage with key stakeholders, including business unit leaders, compliance officers, and regulatory bodies, to facilitate effective issue management and resolution
What we offer
What we offer
  • Competitive base salaries
  • Bonus incentives
  • Support for financial-well-being and retirement
  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • Generous paid parental leave policies (depending on your location)
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities
Read More
Arrow Right

Internal Control Executive - Technology

At Vodafone, we’re not just shaping the future of connectivity for our customers...
Location
Location
Türkiye , İstanbul
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in Engineering, Computer Science, Information Systems, Business IT or a related discipline
  • Solid academic foundation in information systems, digital technologies, governance, risk or compliance domains
  • Professional certifications in IT audit, information security, risk management or governance (e.g., CISA, CRISC, CISSP, ISO Lead Auditor/Implementer, COBIT) are strong assets
  • Minimum five (5) years of experience in internal control, IT audit, technology risk, GRC, fintech compliance or digital governance roles
  • Hands-on experience in highly digitalized, regulated environments such as telecommunications, banking, fintech or large-scale enterprise operations
  • Demonstrated ownership of IT General Controls (ITGC), application controls and system-level control frameworks
  • Experience in embedding controls into ERP, CRM, billing, network OSS/BSS, payment and data platforms
  • Strong background in working with cross-functional IT, security, finance, legal and compliance teams
  • Advanced understanding of IT General Controls (access management, segregation of duties, change management, SDLC governance, logging & monitoring, backup and disaster recovery)
  • Advanced knowledge of application-level controls within ERP, CRM, billing, payment and customer lifecycle systems
Job Responsibility
Job Responsibility
  • Execute and maintain Vodafone Turkey’s technology internal control framework
  • Embed internal controls into system designs, workflows and operating procedures
  • Ensure alignment with COSO, COBIT and Vodafone Group governance standards
  • Access and privileged access management
  • Segregation of duties
  • Change management and SDLC governance
  • Logging, monitoring and audit trail integrity
  • Backup, disaster recovery and system availability
  • Data protection and privacy controls
  • Work with IT, security, network, digital and finance teams to ensure effective control operation
What we offer
What we offer
  • Vflexy: Flexible Benefits Program
  • Hybrid working kit
  • Ergonomic kit allowance
  • Digital meal voucher
  • Flexible transportation allowance
  • Employee assistance hotline & counselling
  • Comprehensive and flexible private health insurance
  • Discounted price deals for wide range of products & services
Read More
Arrow Right

Op Risk SME - Technology VP

Join us as an Op Risk SME - Technology VP. In this role, you will play a critica...
Location
Location
United States , Whippany; Wilmington
Salary
Salary:
150000.00 - 200000.00 USD / Year
barclays.co.uk Logo
Barclays
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Oversee operational risk related to technology infrastructure, including Windows Desktop environments, server platforms, and enterprise applications
  • Provide risk oversight for service management processes, including incident, problem, and change management, ensuring alignment with ITIL best practices
  • Evaluate and challenge technology change initiatives, including configuration management and release processes, to ensure risk is appropriately mitigated
  • Collaborate with technology teams to assess the resilience and security of infrastructure components, including network, storage, and cloud-based services
  • Analyze data and technical documentation to identify emerging risks and formulate actionable insights
Job Responsibility
Job Responsibility
  • Risk identification and proactive risk management, identifying interconnected, horizon and emerging risks to assist the business in understanding, managing and mitigating the right risks in line with their business strategy and objectives.
  • Analysis of operational risk data to identify trends, patterns, and emerging risks.
  • Risk-based analysis of business processes, systems, and controls to assess the likelihood and impact of identified risks.
  • Ongoing research and monitoring of internal and external sources to identify potential Operational Risks.
  • Oversight, review and challenge of 1st Line activities including - Risk Control Self Assessments (RCSAs), Risk Events, Issues and attendance at key Risk and Control meetings (with associated reporting) ensuring they accurately reflect the business risk position,.
  • Stakeholder management, engaging and working effectively with First and Second Line management.
  • Risk based 2nd Line input into 1st Line Projects, Initiatives and Strategic decision making.
What we offer
What we offer
  • medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances
  • incentive award
  • Fulltime
Read More
Arrow Right
New

Associate IS Security Engineer

The Cybersecurity Risk and Controls Analyst within Amgen’s Cybersecurity and Dig...
Location
Location
India , Hyderabad
Salary
Salary:
Not provided
amgen.com Logo
Amgen
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree and 3 years of directly related experience
  • Associate degree and 5 years of directly related experience
  • High school diploma / GED & 10 years of directly related experience
  • Bachelor’s degree in computer information systems or computer science
  • 2+ years of IT audit, Information Technology / Security control assurance or enterprise IT compliance experience
  • Advanced industry recognized security certification (i.e. CISA, CISM, CISSP, CRISC, Security+, etc.)
  • Working knowledge of Information Security principles: confidentiality, integrity, and availability
  • Knowledge of international standards for Information Technology and Information Security (i.e. ISO 2700x, NIST CSF, COBIT, ITIL, etc.)
  • Exceptional ability to apply critical thinking to complex risk scenarios
  • Proven ability to understand new technologies and paradigms such as cloud, emerging Big Data technologies, lean methodologies to propose appropriate controls and compliance mentorship
Job Responsibility
Job Responsibility
  • Advise project teams and application owners on information security risks and controls
  • Participate in projects or initiatives where a security risks and controls specialist is needed, with a focus on addressing risks by ensuring appropriate security controls are implemented
  • Evaluate compliance with security requirements
  • Evaluate IT controls’ design and implementation in various IT security processes
  • Test operating effectiveness of IT controls, including user access management, change management and computer operations for complex IT systems
  • Assess the risks of control deficiencies and identify mitigating controls
  • Clearly document and effectively communicate risks and risk mitigation actions
  • Understand and leverage ISO and NIST information security frameworks to establish accountability and responsibility for controls within the information systems organization
  • Ensure quality of work and timeliness across different functional deliverables
  • take ownership of issues and coordinate through to completion
What we offer
What we offer
  • Benefits for transgender employees
  • Industry-leading, family-friendly offerings for families of all compositions
Read More
Arrow Right