Associate - Technology & Cyber Risk Management RCSA Validation
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, IT Consultant, Information Security, IT Business Analyst
Associate – Technology & Cyber Risk Management RCSA Validation
Country:
United States of America
Santander is a global leader and innovator in the financial services industry and is evolving from a high‑impact brand into a technology‑driven organization. Our people are at the heart of this journey and together, we are driving a customer‑centric transformation that values bold thinking, innovation, and the courage to challenge what’s possible. This is more than a strategic shift. It’s a chance for driven professionals to grow, learn, and make a real difference.
If you are interested in exploring the possibilities We Want to Talk to You!
The Difference You MakeWe are seeking an Associate to join our Technology & Risk Management team (Second Line of defense) with a focus on Risk and Control Self‑Assessment (RCSA) validation. This role will be responsible for executing in‑depth validations of technology and cybersecurity risk/control assessments, ensuring consistency, accuracy, and compliance with internal and regulatory standards.
Essential Functions- Perform independent validation and challenge of Technology and Cyber RCSA assessments completed by the First Line of Defense (FLOD), ensuring completeness, accuracy, and adherence to Risk Management policies and procedures.
- Review and challenge the Risk and Control Matrix (RCM) for technology and cyber domains, confirming that key risks (e.g., cybersecurity, data integrity, system availability, change management) are adequately identified and mitigated.
- Provide second line oversight of FLOD control testing programs by evaluating the adequacy of control design, evidence of operating effectiveness, and accuracy of control test results conducted by the FLOD.
- Challenge and validate risk and control ratings.
- Partner with Risk Management team and other second line functions to ensure alignment between RCSA results, key metrics, and ICT risk appetite.
- Support development and continuous improvement of SLOD RCSA validation methodologies, templates, and tools tailored to technology risk and cyber controls.
- Provide periodic reporting to TRM leadership, governance committees on validation outcomes, control effectiveness.
- Contribute to awareness and training initiatives to strengthen the program.
- Ensure documentation of validation activities meets internal audit and regulatory expectations, supporting a robust control assurance framework.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education- Bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or related field.
- Master’s Degree in related disciplines. Preference given.
- Professional certifications are strongly desirable: CISA, CRISC, CISSP, CISM, CCAK, or PMP.
- Overall professional experience of 5+ years or more in Technology Risk Management, Cybersecurity Risk, IT Audit, or Operational Risk within financial services.
- Demonstrated hands‑on experience in testing and validating technology and cyber controls within the RCSA framework.
- Strong knowledge of ICT risk domains (e.g., cybersecurity, system availability, change management, data integrity, third‑party risk).
- Experience with in a highly regulated environment such as the financial services industry.
- Experience performing process assurance activities.
- Strong knowledge of IT and cybersecurity risks, including IT general controls, identity and access management, network security, cloud, and application security.
- Familiarity with industry frameworks and standards such as NIST, ISO 27001, COBIT, ITIL, CIS Controls.
- Understanding of regulatory expectations related to technology and cyber risk (e.g., OCC, FFIEC, PRA, EBA, DORA).
- Structured, detail‑oriented, and analytical, with the ability to balance execution and coordination.
- Strong communication and stakeholder engagement skills, capable of interfacing with both…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).