Controls Manager
Thought Machine
Description
As the face of Controls, you will be responsible for controls management and controls testing and to build trust and credibility with various teams.
The role of the Controls Manager will be to understand control gaps (risks without controls); assess the designed effectiveness of controls (whether controls effectively mitigate risks); help the business create/update controls to target identified risks; and set the controls testing strategy to test the operating effectiveness of controls. This will involve working closely with risk and control owners in the first-line business areas, particularly our security team and support functions.
DUTIES
Develop periodic controls testing plans.
Engage with the wider business to ensure timely execution of the testing plans.
Develop and agree corrective actions for control gaps or failures identified in testing.
Report controls testing outcomes to Executive and Board.
Create new policies and procedures to mitigate Thought Machine’s risks.
Ensure Thought Machine controls meet any contractual agreements with clients.
Design initiatives to disseminate information security and compliance requirements to individuals who are not always familiar with working in the highly regulated environment of financial services.
Ensure that Thought Machine meets the audit standards of clients and oversee client / 3rd party audits.
Manage the lifecycle of the organisation’s policy suite and ensure documents are up to date and reviewed.
Manage Risk and Compliance processes including exceptions, corrective actions, code of conduct issues and user access reviews.
Support Risk and Compliance Managers with their duties.
Requirements
- 3+ years’ experience working in controls management & testing.
- In-depth Knowledge and implementation experience of Information Security controls
- Experience of drafting compliance and information security policies and procedures as well as compliance training.
- Experience of designing/providing compliance oversight of technology-related information security management system controls.
- Able to work within a cross-functional environment, particularly with engineering and delivery functions.
- Experience of establishing a controls testing framework and testing the design and operating effectiveness of controls.
- High energy and the desire to work in a fast moving environment.
- Proven experience with drafting documentation.
- Excellent communication and written English language skills.
- Experience working in controls at a FinTech company that provides a SaaS platform/ solution.
- Knowledge of SOC2, ISO 27001 and PCI standards and controls
- Knowledge of and experience working on regulations and compliance in financial services.
- Knowledge in Atlassian Enterprise tools and common Governance, Risk & Compliance tools.
Benefits
- Highly competitive salary
- Pension plan (match up to 7%)
- Life insurance - three times annual salary
- Competitive maternity (six months fully paid) and paternity leave (four weeks fully paid)
- Shared parental leave (matched to our maternity leave for the same point in time)
- 25 days holiday and bank holidays
- Flexible working hours
- Cycle-to-work scheme
- Electric car scheme
- Season ticket loan
- Access to outstanding learning materials and courses
- Sports and hobby clubs, subsidised by Thought Machine
- All the latest tech you need
- Start the day properly with fresh fruit and cereals
- Huge range of healthy (and not-so-healthy) snacks, smoothies and drinks
- A talented and experienced team as your colleagues
- An environment where we encourage learning and progress
- Two charity days a year
- Weekly food pop-up
We actively hire candidates who demonstrate technical excellence in their field and welcome people of all ages and backgrounds, providing everyone with equal access to professional development. You are encouraged to apply even if your experience doesn't accurately match the job description. We also encourage applications from those with different abilities, including candidates with ADHD, autism, dyslexia or dyspraxia.