Head of Technology Risk Resilience Section
الوصف الوظيفي
Leadership Role: Head of Technology Risk Resilience Section
The Head of Technology Risk Resilience Section is a critical role within the Technology Risk & Data (TRD) function, responsible for overseeing and independently challenging the Bank’s technology resilience, stability, and operational control effectiveness. This role ensures that technology environments are resilient to disruptions through effective incident management oversight, control validation, disaster recovery readiness, and robust testing assurance across system changes and releases.
The Section Head is accountable for approving resilience risk assessments, validating control effectiveness, and proactively identifying and addressing weaknesses in testing, release processes, and operational readiness. This role provides forward-looking assurance on the Bank’s ability to prevent, withstand, and recover from technology disruptions, supporting executive decision-making through clear articulation of resilience risks and control gaps.
Key Responsibilities
- Technology Resilience Framework & Oversight: Define and maintain the technology resilience risk framework, covering incident management, control effectiveness, and operational stability. Approve methodologies for resilience risk assessment and control validation, ensuring alignment with regulatory expectations and industry standards. Establish clear definitions and standards for resilience, availability, and recovery.
- Incident & Problem Management Oversight: Oversee independent risk assessment of major incidents and systemic issues. Validate root cause analysis quality, challenge incident classification, prioritization, and resolution. Identify patterns, recurring issues, and systemic weaknesses, ensuring lessons learned are properly tracked and implemented.
- Control Effectiveness Validation: Oversee validation of key IT controls across change and release management, incident and problem management, batch processing, system monitoring, and alerting. Approve control assessment outcomes, identify control gaps, and ensure follow-up and closure of deficiencies.
- Testing Assurance: Establish and approve frameworks for independent assessment of testing adequacy across system changes and releases. Evaluate test coverage completeness, scenario design, regression testing effectiveness, and performance testing readiness. Challenge testing outcomes and ensure risks are identified prior to production deployment.
- Release & Operational Readiness Risk Assessment: Oversee risk assessment of release readiness for major deployments and system changes. Validate readiness across infrastructure, data migration, monitoring, support models, and escalation procedures. Challenge go-live decisions where resilience risks are not adequately mitigated, and ensure structured stabilization monitoring post go-live.
- Disaster Recovery (DR) & Business Continuity (BCP) Oversight: Oversee independent validation of DR and BCP readiness from a technology perspective. Validate DR architecture, failover mechanisms, and recovery capabilities. Assess DR drill effectiveness, identify gaps in recovery objectives, and ensure alignment with regulatory expectations and internal resilience targets.
- Integration with Risk Analysis & Governance: Provide resilience risk inputs to Risk Analysis for incorporation into the enterprise risk view. Ensure integration of incident, control, and testing insights into TRD reporting. Collaborate with the Governance function to ensure accurate representation of resilience risks in dashboards and reports.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.