Description:
Under the supervision of the Director, Business and Technology Governance, you will provide oversight and advisory support in evaluating technology solution permission models, analyzing access requests, and implementing controls to mitigate risks of inappropriate access and segregation of duties issue. You will also provide guidance on information retention principles and give advice on retention requirements for document classification
About Your Role
As an Advisor, Access and Information Governance , you’ll:
- Advise and provide oversight on the access and information governance framework, aligned with risk levels, system and data classification, document/data retention requirements and enterprise strategy
- Guide and review the design, implementation, and maintenance of access permission models across business applications and cloud platforms
- Oversee access governance processes, segregation of duties matrices, and related controls, retaining hands-on involvement and execution some key access governance controls where required
- Guide and contribute to the implementation of practices regarding the management of external identities, privileged accounts, and access in cloud environments, participating in long-term strategic requirements gathering
- Provide analysis and executive summary of key access governance metrics and controls
- Identify access-related risks and collaborate with stakeholders to design and implement mitigating controls
- Act as a key liaison with internal and external auditors and provide guidance to teams on IAM practices and improvements
- Guide and contribute to the implementation of practices regarding the information retention governance. Work with Legal to define and implement best practices and guidelines related to PSP’s information retention
- Guide content owner and users to classify the information under the adequate document series as per the PSP Retention Schedule
What You’ll Need
- A minimum of three (3) to five (5) years of professional experience in access governance, IT internal controls, internal control frameworks and/or IT audit
- Bachelor of Business Administration in Information Technology or a combination of education and experience deemed equivalent
- Strong knowledge of cloud services concepts and solutions and Microsoft Entra ID, Azure DevOps, SharePoint, Analytics tools, Power BI, Power Apps, etc
- Experience in developing and implementing processes, procedures and controls
- Ability to understand business issues and integrate them into the development of technology solutions, access models and relevant controls identification
- Good knowledge of technological challenges and risks, and ability to formulate functional and value-added requirements and recommendations
- Good knowledge of investment business processes or financial services
- Strong analytical, problem identification and problem-solving skills, with the ability to influence and guide stakeholders
- CISA, CPA, or other relevant certification, an asset
- Bilingualism: English and French (frequent interactions in English with PSP employees based in our offices in Hong Kong, London and New York, and interactions in French with employees in our local offices in Montreal and Ottawa)