Manager, BRCO Control Testing - Enterprise Security and Technology
Listed on 2026-03-03
-
Finance & Banking
Risk Manager/Analyst, Financial Compliance
Job Description
The Business Risk and Control Officers (BRCOs) play a pivotal role in guiding the business to identify and understand risk exposures and the controls needed which are integral to reducing risk and safeguarding our customers and colleagues. BCROs are critical to the success of the Risk Management Lifecyle and play a role in Planning, Identifying, Assessing, Mitigating, Monitoring, and Reporting. BRCOs are members of the First Line of Defense (1
LOD) who:
- Provide leadership and coaching to the 1
LOD to proactively identify and effectively manage risks. - Translate and educate 1
LOD to enable and drive business relevant implementation of Second Line of Defense (2
LOD) risk management frameworks, policies, taxonomies, and inventories. - Review, validate, and test 1
LOD activities to ensure adequate control design and effective control operation. - Provide credible challenge to 1
LOD colleagues, ensuring safeguard and risk mitigation measures are upheld in decision making and adherence to 2
LOD frameworks and policies prior to 2
LOD review. - Drive two-way collaboration across 1
LOD and 2
LOD; liaise between 1
LOD and 2
LOD to drive engagement throughout the risk management lifecycle. - Collaborate and coordinate across the organization to help navigate and mitigate horizontal risk promoting resilience and ensuring safety and soundness.
- Document, aggregate and report risk in accordance with the risk management lifecycle.
The Manager, Business Risk and Control Office (BRCO) Control Testing I is responsible for leading a small to medium size team of testers to execute a structured review to validate that processes and controls function as intended to mitigate risk, including SOX controls. The Manager, BRCO Control Testing I does not own the design nor execution of controls.
Position Responsibilities Translates and interprets corporate testing policies and manages/drives implementation of overall independent testing program for the Line of Business (LOB)- Created and adheres to a defined testing schedule and provides periodic updates on progress.
- Provides guidance to other team members supporting the engagement.
- Establishes strong relationships with business partners and other key stakeholders ( SOX Office).
- Understands LOB end to end business processes, products, services, financial statement risks, controls and risk profile.
- Adheres to testing procedures, standards, and methodologies established by Second Line of Defense (2
LOD). Tests are performed periodically based on inherent risk level and frequency of controls operation; scope and sample size vary based on the type of test, inherent risk level, and dataset population size. - Addresses any review and challenge comments as received to ensure alignment with 2
LOD testing requirements. Designs and executes testing plans and scripts to evaluate the effectiveness of the overall control environment, including for SOX compliance. - Performs walkthrough prep and walkthrough execution.
- Assesses both Design (is the control is designed to accomplish the goal or detect/prevent a misstatement - test sample of
1) and Effectiveness (was the control executed correctly). - Performs the role of Tester/Preparer (does the testing, picks the samples, executes testing based on test plan, documents, manages follow-up, reviews comments) or Reviewer (reviews the testing, documents issues).
- Ensures 1
LOD quality assurance procedures are aligned with frameworks and policies.
- Documents narratives, flowcharts, and controls.
- Identifies and escalates issues for remediation.
- Validates remediation of control deficiencies and issues, including sustainability.
- Supports audits, exams and assessments conducted internally and externally.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).