- The overall purpose of this position, as part of the RISK ORM Payment Systems Risk and Testing team, is to ensure the continued development and implementation of group-wide Payment Systems Technical Testing program, through leading and executing ICT risk assessments of Payment Systems across the group in accordance with the Group Risk ORM standards and policies
- In addition, this role will also be responsible for delivering the Operational Risk Officer (ORO) oversight activities per the operational risk management framework (ORMF) in IT departments supporting critical payment processing systems
- Furthermore, this role entails representing the team in Risk Management governance committees (conducted in French/English); influencing the ICT risk culture by driving the agenda and reporting the risk status to the senior management through working in collaboration with other Stakeholders from the business and RISK ORM teams
Responsibilities
- Lead Payment Systems independent testing mission engagements with accountability and responsibility to ensure that the engagement team delivers the missions within agreed timelines adhering to RISK ORM framework and high-quality standards.
- Ensure that identification and assessment of operational risks are effective across the organization by correlating inputs from Independent Testing, Audit Findings, Internal Loss Data Collection Analysis, External Data Collection Analysis, Risk Control Self Assessments, Business Process Reviews, KPIs KRIs and Scenario Analysis.
- Accountable for providing excellence within Payment Systems Risk domain and serving as an advisor to business managers, identifying, analysing, categorizing, and prioritizing the risks affecting BNPP.
- Improve the effectiveness of the ICT Control Framework for Payment Systems by regularly assessing the control environment, risk assessment process, control activities, and monitoring activities in accordance with the Group Risk ORM standards and policies.
- Monitor operational risk profiles and material exposure to losses and provide appropriate reporting mechanism to senior management and business stakeholders, including through risk management governance committees.
- Contribute to the implementation and enhancement of BNPP operational permanent control framework.
- Provide a fair check and challenge to the LoD1 on Payments related Regulatory Attestation Exercises (e.g. CHAPS, TARGET2 and PSD2)
- Provide Payments Systems risk management consulting to the business, technical and operations groups.Contributing Responsibilities
- Collaborates at the India CoE level with Head of India CoE, including but not limited to the CoE level reporting requirements.
- Effectively contributes to the CoE, RISK India Hub and ISPL on Group mandates, objectives and priorities
- Lead by example, demonstrating effective Leadership in the CICEP team leading to CoE as a positive place to work in conjunction with the Head of India CoE.
Skills Required
- 10 to 12 years of experience in IT audit / ITGC controls testing / technical assessments, preferably in the areas of Payments Technology or Cyber domains within in a financial institution.
- Good working knowledge of best practices in risk management processes within the Banking sector.
- Excellent analytical skills with the ability to translate technical concepts and provide specialist guidance and advice to others.
- Demonstrated ability to communicate effectively and to present in a structured approach in English.
- Strong people management skills and an ability to work with individuals to set individual objectives and manage performance to ensure their delivery.
- Proven commercial and communication / relationship management skills.
- Ability to lead risk assessments.
Good working knowledge of concepts related to Payment and Information Security including emerging threats and attacks methodologies is highly desirable, at least in most of the below areas:
- Payment Flows/Chains
- SWIFT Systems
- Good technical understanding of security technologies, including intrusion detection/prevention, correlation of events, firewall, antivirus, anti-spam, policy tightening, patch management and configuration management, audit, security development technique, etc.
- Knowledge of cryptographic standards for encryption, electronic signature, key management infrastructure (PKI).
- Knowledge of IT Risk Management
Skills Preferred
- Has the proven ability to think outside of the box, challenge industry norms and adapt quickly to evolving requirements.
- Is self-aware, anticipates problems, adapts and meets them head on.
- Strong stakeholder management, relationship building, influencing, facilitating and presenting skills.
- Is solutions focused measures their output on whether issues, problems or challenges are resolved as a criteria for success.
Competencies:
- Professional qualification and expert knowledge in a specific Risk specialism and how that fits within the broader organization as well as more deeply within the Risk function.
- Degree level qualification in STEM subject will be advantageous.
Conduct:
- Consider the implications of your actions on colleagues, partners and clients before making decisions, and escalate issues to your manager when unsure.
Specific Qualifications (if required) Bachelors degree, and certification in Information Systems
Skills Referential
Behavioural Skills : (Please select up to 4 skills)
Attention to detail / rigor
Ability to deliver / Results driven
Ability to deliver / Results driven
Ability to collaborate / Teamwork
Transversal Skills:
Ability to develop others improve their skills
Ability to inspire others generate people's commitment
Ability to set up relevant performance indicators
Analytical Ability
Ability to develop and leverage networks
Education Level:
Bachelor Degree or equivalent