Responsibilities:
Manage the India Risk Management team consisting of Risk and Assurance activities to ensure
- Timely completion of all activities
- Adequate cross training and backup
- Completion of asks from India Leadership
Strategic planning for the Risk Management function
PSP - Governance (Policies, Standards & Procedures)
- Review and ensure compliance with the Enterprise Policy Program standard
- Report on creation of new documents, renewals/ expiry of existing documents and Standard Adherence Assessment conducted by CPO (Corporate Policy Office)
- Maintain repository of India wide documents
- Influence updates to policies, standards to enhance risk management activities
- Maintain Risk Management PSPs and SOPs and draft new documents as the team expands the scope of work
Corporate Insurance
- Renew and maintain following Insurance Policies
- Worker s Compensation (WC)
- Property Insurance
- Directors and Officers Liability (D&O)
- Commercial General Liability (CGL)
- Coordinate with Insurance Broker and facilitate claims
Physical Records
- Facilitate storage and transport of physical records via third party
- Maintain Inventory Index to track the data and retention requirements by Law
Internal Audit
- Finalize the vendor to conduct annual Internal Audit
- Draft the scope and IA calendar
- Coordinate with Internal teams and facilitate the IA
- Assist in timely closure of observations/ recommendations
- Report the status and details of observations to LT
- Prepare the Risk reports at India site level risk in the Enterprise Risk Management framework including key topics like
- Phishing drill report to Leadership Team (LT)
- Bi-annual Official Records (non-HR GDrive) certification and reporting to Risk Head
- Quarterly Sensitive Data Assessment and reporting to Risk Head
- Monthly Hard Disk Drive (HDD) remediation report to LT
- Monthly Iron Mountain document storage to File manages, respective LTs
- Constantly work with US Risk Office and Cyber teams to expand the scope of Risk Reporting
- Prepare Assurance Reports including
- Monthly Controls execution report to owners & relevant LT
- Coordinate with Capital One US teams and India support teams to report status on:
- IA TPM
- ABAC
- BCP testing
- Standard Adherence Assessment
- Statutory Audit
- Work closely with LT to maintain artefacts (like Vision, Roadmap, etc) in the internal portal for SLQ2CQ (Capital One internal Lean - Six Sigma based framework)
- Present the Risk and Assurance reports to LT in the following forums:
- Monthly Business Review (MBR) - chaired by India head, US Risk Office head and US Legal head
- Quarterly Risk, Legal & Tech Committee - chaired by India head, US Risk Office head, US Legal head and US Tech Head
- Ideate and implement Risk Management framework across Risk Taxonomy and refresh framework based on evolving business needs/ risks
- Partner with other Risk Management functions across the company and cross functional teams to conduct Process Level Assessments
- Maintain relationships with key stakeholders to ensure timely delivery of commitment
Basic Qualifications
- Bachelors degree in Engineering
- At least 7 years of experience in Banking/Risk Management
- At least 2 years of experience in Enterprise Risk Management
- Deep knowledge on:
- Enterprise Risk Management framework and implementation
- Three Lines of Defense framework
- Handling/ facilitating Internal Audits
Preferred Qualifications
- 7+ years of experience in risk management
- Enterprise Risk Management - Level 2 qualified (by IRM - Institute of Risk Management)
- COSO framework, ISO 31000 and ISO 27001