Job description
Job Reference #
City
Job Type
Your role
We are looking for a Cyber Risk Controller like you to:
- challenge our 1st line-of-defense’s risk-taking activities and risk assessments, working with CDIO Group Technology teams to review risks associated with cyber security and provide guidance on controls
- collaborate with our Cyber Assurance (Red) Team to maximize the impact of technical findings identified towards our residual risk posture around cyber security; take ownership of complex technical output and manage key stakeholders to ensure sustainable remediation will be orchestrated
- be a cyber risk taxonomy specialist to support and challenge CDIO Group Technology as part of the regular Risk Appetite Assessments (RAA) and Risk & Control Self-Assessment (RCSA) processes
- perform cyber security risk assessments, thematic reviews and deep dives as well as ad-hoc analysis, investigations, control testing and other risk control initiatives as required
- provide review and challenge to CDIO Group Technology as well as to our business divisions (via our Divisional Information Security Officers) on projects, new initiatives, processes, risk events, incidents, controls as well as regulatory compliance
- influence executives in CDIO Group Technology on key cyber risks and actions required to manage UBS’s risk appetite
- represent C&ORC Cyber Risk Control and escalate cyber risk issues/concerns in relevant forums including Technology Risk Forums and Management Committees
Your Career Comeback
Your team
Your expertise
- at least 7 - 8 years' experience in managing and/or overseeing remediation of complex technical cyber & information security findings, ideally within a financial services, regulatory agency or consultancy environment
- a Bachelor's degree in Computer Science, MIS, CIS, or similar discipline; an advanced degree is a plus
- professional certifications e.g. CISA, CRISC, CISM, CRISC or CISSP highly preferred
- experience in ISO 27001, the NIST Cyber Security Framework or other renowned international cyber risk management frameworks would be advantageous
- experience with financial services regulators (such as FED, FFIEC, PRA/FCA, MAS, HKMA, FINMA)
- strong understanding of core cyber controls, concepts and architectures. In-depth knowledge of cyber security threats and risks, cloud security concepts as well as new technologies such as artificial intelligence, DLT, quantum-safe cryptography etc.
- strong strategic, judgement and integrative thinking skills, deep cyber risk management & control knowledge, as well as good organizational, communication and influencing skills
#LI-Hybrid
About us
With more than 70,000 employees, we have a presence in all major financial centers in more than 50 countries. Do you want to be one of us?
Join us
From gaining new experiences in different roles to acquiring fresh knowledge and skills, we know that great work is never done alone. We know that it's our people, with their unique backgrounds, skills, experience levels and interests, who drive our ongoing success. Together we’re more than ourselves. Ready to be part of #teamUBS and make an impact?
Disclaimer / Policy Statements