リスク・コンプラ・監査、2000万以上の転職求人
4件
検索条件を再設定

並び順:
全4件
1-4件目を表示中
リスク・コンプラ・監査、2000万以上の転職求人一覧
外資投資銀行でのGroup Audit - Senior Principal Auditor - VP
おすすめ年齢
20代
30代
40代
50代以上
年収レンジ
年収イメージ:1800万円〜2000万円以上(経験・能力を考慮の上当社規定により決定)
ポジション
VP
仕事内容
・Executes day-to-day operational audit work and contributes to the delivery of audits. Opportunity to participate in all Corporate and Investment banking and infrastructure related audits relating to businesses in Japan and South Korea.
・Depending on experience, may have the opportunity to lead a team on individual audit assignments.
Implements dynamic planning through Continuous Audits and Risk Assessment of the business.
・Plans audits e.g. documenting activity flows of the processes to be reviewed, identifies risks and the key actual controls in place to mitigate the identified risks and attends meetings with internal stakeholders as and when required.
・Executes audit fieldwork in line with the agreed audit approach e.g. testing of key controls to determine whether they are properly designed and are operating effectively and documenting work in accordance with divisional standards.
・Completes all assigned work in line with agreed budgets, including ad hoc projects and special investigations.
・Proactively develops and maintains professional working relationships with colleagues, the business and respective support areas.
・Partners with other divisional/teams during audit engagement to guarantee an integrated approach.
・Presents complex and sensitive messages (such as audit issues) comprehensively and professionally and reduces complex topics to simple statements.
・Participates in exit meetings, drafts high quality audit Findings for review by audit management, facilitates issue tracking and validates the closure of issues.
・Is a competent partner and challenger to clients in the closure process of findings.
・Communicates openly with divisional management and the internal stakeholders; keeps them informed of potential issues and escalates problems/delays accordingly.
・Responsible for interfacing with regulators during inspections and adhoc requests on topics relating to Group Audit and validating regulatory findings.
・Keeps abreast of pertinent industry, regulatory and business practices.
・Takes ownership for own development and career management, seeking opportunities to develop personal capability and improve performance contribution.
・Depending on experience, may have the opportunity to lead a team on individual audit assignments.
Implements dynamic planning through Continuous Audits and Risk Assessment of the business.
・Plans audits e.g. documenting activity flows of the processes to be reviewed, identifies risks and the key actual controls in place to mitigate the identified risks and attends meetings with internal stakeholders as and when required.
・Executes audit fieldwork in line with the agreed audit approach e.g. testing of key controls to determine whether they are properly designed and are operating effectively and documenting work in accordance with divisional standards.
・Completes all assigned work in line with agreed budgets, including ad hoc projects and special investigations.
・Proactively develops and maintains professional working relationships with colleagues, the business and respective support areas.
・Partners with other divisional/teams during audit engagement to guarantee an integrated approach.
・Presents complex and sensitive messages (such as audit issues) comprehensively and professionally and reduces complex topics to simple statements.
・Participates in exit meetings, drafts high quality audit Findings for review by audit management, facilitates issue tracking and validates the closure of issues.
・Is a competent partner and challenger to clients in the closure process of findings.
・Communicates openly with divisional management and the internal stakeholders; keeps them informed of potential issues and escalates problems/delays accordingly.
・Responsible for interfacing with regulators during inspections and adhoc requests on topics relating to Group Audit and validating regulatory findings.
・Keeps abreast of pertinent industry, regulatory and business practices.
・Takes ownership for own development and career management, seeking opportunities to develop personal capability and improve performance contribution.
大手銀行系コンサルティング会社でのボードガバナンスコンサル
おすすめ年齢
20代
30代
40代
50代以上
年収レンジ
〜2450万円 ※ポジションにより異なる
ポジション
コンサルタント〜パートナー
仕事内容
社長/CEO にとっての「コーポレートガバナンスのかかりつけ医」として、上場企業の持続的な成長・企業価値向上に向けて、取締役会だけでなく指名・報酬までを含めた、コーポレート・ガバナンスのあるべき姿の設計・実装・運用を並走支援します。
具体的には、
コーポレートガバナンス全般
コーポレートガバナンスのグランドデザイン、具体的には社長 CEO が描く将来像の実現のためのコーポレートガバナンスのグランドデザインを策定し、それに基づき取締役会の役割責任、社内/外取締役の役割責任、取締役会構成、取締役会アジェンダ設定、取締役会評価など取締役会の実質化と持続的な実効性の向上、指名・報酬委員会の位置づけの明確化、諮問プロセスの設計など各委員会の実質化と持続的な実効性の向上、および機関設計の変更支援などコーポレートガバナンス体制の構築および監督機能の向上に貢献します。
グランドデザイン策定、グランドデザインに基づく取締役会の役割責任の言語化、社内/外取締役の役割責任の言語化、取締役会構成、取締役会アジェンダ設定 グランドデザインに基づく指名委員会、報酬委員会、サステナビリティ委員会、人材開発委員会の位置づけの明確化、ポリシーの設定、答申内容の具体化、答申に基づくプロセス設計など
機関設計変更支援
取締役会評価による取締役会および各委員会の持続的な実効性向上支援
2.取締役会運営
社長 CEO が描く未来の実現に向けてグランドデザインに基づき、取締役会議長の役割責任および構成員である社内/外取締役の役割責任の言語化、取締役会アジェンダの設定、取締役会審議の視点の提起・運用方法の構築、業務執行に対する報告事項の視点の提起・運用方法の構築、また中長期に企業価値を向上させるために必要な中長期戦略の審議、モニタリングの視点など中長期戦略ガバナンスの支援、サステナビリティガバナンス視点、人的(知的)資本ガバナンス視点、ポートフォーリオガバナンス視点の明確化など取締役会の監督機能の実効性を向上し、持続的な成長、中長期的な企業価値向上に資する取締役会運営に貢献します。
アジェンダ設定
議長、社内/外取締役および取締役会の役割責任の言語化
中長期戦略モニタリングの視点の提起・運用方法の構築
取締役会によるサステナビリティ課題、人的(知的)資本経営などの審議やモニタリング視点の提起・運用方法の構築
取締役会評価による取締役会の持続的な実効性向上支援
3.コーポレートセクレタリー支援
企業が持続的な成長を実現するためには、将来財務の向上を見据えた戦略の構築、およびそれらに係るコミュニケーションが必要です。パーパスの策定、マテリアリティの特定、それらに基づく長期ビジョン、非財務を含む中期経営計画策定のための指針作り等支援を通じて、クライアントの企業価値向上をサポートします。また、サステナビリティ経営に係るガバナンス体制の構築、および効果的なコミュニケーションの実現を後押しすることにより、クライアントのサステナビリティガバナンスの強化に貢献します
〈PJT 例〉
【某システムインテグレーター】
コーポレートガバナンス高度化におけるグランドデザイン(執行と監督の在り方における大方針)の策定・合意形成・実装支援
【某 BtoC プラットフォーマー】
指名委員会等設置会社への機関設計変更、および指名委員会・報酬委員会の詳細設計を含めたコーポレートガバナンスの統合的支援
【某広告代理店】
指名委員会等設置会社移行支援と並行した取締役会の実効性評価の高度化支援
具体的には、
コーポレートガバナンス全般
コーポレートガバナンスのグランドデザイン、具体的には社長 CEO が描く将来像の実現のためのコーポレートガバナンスのグランドデザインを策定し、それに基づき取締役会の役割責任、社内/外取締役の役割責任、取締役会構成、取締役会アジェンダ設定、取締役会評価など取締役会の実質化と持続的な実効性の向上、指名・報酬委員会の位置づけの明確化、諮問プロセスの設計など各委員会の実質化と持続的な実効性の向上、および機関設計の変更支援などコーポレートガバナンス体制の構築および監督機能の向上に貢献します。
グランドデザイン策定、グランドデザインに基づく取締役会の役割責任の言語化、社内/外取締役の役割責任の言語化、取締役会構成、取締役会アジェンダ設定 グランドデザインに基づく指名委員会、報酬委員会、サステナビリティ委員会、人材開発委員会の位置づけの明確化、ポリシーの設定、答申内容の具体化、答申に基づくプロセス設計など
機関設計変更支援
取締役会評価による取締役会および各委員会の持続的な実効性向上支援
2.取締役会運営
社長 CEO が描く未来の実現に向けてグランドデザインに基づき、取締役会議長の役割責任および構成員である社内/外取締役の役割責任の言語化、取締役会アジェンダの設定、取締役会審議の視点の提起・運用方法の構築、業務執行に対する報告事項の視点の提起・運用方法の構築、また中長期に企業価値を向上させるために必要な中長期戦略の審議、モニタリングの視点など中長期戦略ガバナンスの支援、サステナビリティガバナンス視点、人的(知的)資本ガバナンス視点、ポートフォーリオガバナンス視点の明確化など取締役会の監督機能の実効性を向上し、持続的な成長、中長期的な企業価値向上に資する取締役会運営に貢献します。
アジェンダ設定
議長、社内/外取締役および取締役会の役割責任の言語化
中長期戦略モニタリングの視点の提起・運用方法の構築
取締役会によるサステナビリティ課題、人的(知的)資本経営などの審議やモニタリング視点の提起・運用方法の構築
取締役会評価による取締役会の持続的な実効性向上支援
3.コーポレートセクレタリー支援
企業が持続的な成長を実現するためには、将来財務の向上を見据えた戦略の構築、およびそれらに係るコミュニケーションが必要です。パーパスの策定、マテリアリティの特定、それらに基づく長期ビジョン、非財務を含む中期経営計画策定のための指針作り等支援を通じて、クライアントの企業価値向上をサポートします。また、サステナビリティ経営に係るガバナンス体制の構築、および効果的なコミュニケーションの実現を後押しすることにより、クライアントのサステナビリティガバナンスの強化に貢献します
〈PJT 例〉
【某システムインテグレーター】
コーポレートガバナンス高度化におけるグランドデザイン(執行と監督の在り方における大方針)の策定・合意形成・実装支援
【某 BtoC プラットフォーマー】
指名委員会等設置会社への機関設計変更、および指名委員会・報酬委員会の詳細設計を含めたコーポレートガバナンスの統合的支援
【某広告代理店】
指名委員会等設置会社移行支援と並行した取締役会の実効性評価の高度化支援
大手証券会社でのGlobal Head of Cyber Threat Defense (Fusion Center)
おすすめ年齢
20代
30代
40代
50代以上
年収レンジ
年収イメージ:1400万円〜2000万円以上(経験・能力を考慮の上当社規定により決定)
ポジション
Managing Director
仕事内容
Responsibilities:
・Develop and implement a comprehensive CTD strategy and roadmap (including the deployment the MITRE ATTACK framework, defense in depth, and other best practices) to safeguard the organization’s infrastructure, systems, and data from security threats.
・Lead the Cyber Fusion Center, which includes the Security Operations Center (SOC), Cyber Threal Intel, and Incident Response teams.
・Note that eventually the Cyber Fusion Center will include other activities such anti-fraud and physical access.
・Oversee the detection of cybersecurity events in real time through centralized monitoring.
・Analyze cybersecurity events from multiple sources such as SIEM, IDS/IPS, EDR, AV, Firewalls, etc.
・Respond to and contain cybersecurity incidents, and identify eradication strategies.
・Facilitate the transformation of the current SOC and Incident Response capabilities.
・Manage adversary indicators of compromise, tracking, and monitoring of adversary tactics, techniques, and procedures, motivations, goals and strategic objectives.
・Manage incident response activities, including incident triage, containment, eradication, and recovery to minimize the impact of security incidents on the organisation.
・Lead cyber threat intelligence collaboration internally and externally.
・Create industry standard group level ‘Follow the Sun’ fusion center of CTI and SOC professionals to provide a center for the monitoring, analysis and reporting of cyber events and activities to identify trends and potential risks and leading proactive measures to mitigate.
・Ensures all CTD activities are compliance with all relevant regulations and standards.
・Collaborate with cross-functional teams to assess security posture and recommend improvements to enhance threat detection and response capabilities.
・Provides regular cyber threat briefings about adversarial threat modelling, advanced analytics, and other leading-edge technologies to proactively inform multiple audiences of potential threats.
・Understand how to convert highly technical language to business-centric language including being able to clearly explain the impact of threats on the business value chains.
・Stay informed about industry trends and best practices in CTD, and recommend improvements to enhance the division’s performance.
・Provide clear guidance to key stakeholders (e.g., IT, business, legal, compliance) on how to meet specific security requirements that will enhance all CTD activities.
・Establish relationships with law enforcement and other cyber threat defense agencies in Japan but also in other countries where Our company has large operations centers.
・Develop and maintain security policies, procedures, and guidelines to ensure compliance with regulatory requirements and industry standards.
・Develop and implement a comprehensive CTD strategy and roadmap (including the deployment the MITRE ATTACK framework, defense in depth, and other best practices) to safeguard the organization’s infrastructure, systems, and data from security threats.
・Lead the Cyber Fusion Center, which includes the Security Operations Center (SOC), Cyber Threal Intel, and Incident Response teams.
・Note that eventually the Cyber Fusion Center will include other activities such anti-fraud and physical access.
・Oversee the detection of cybersecurity events in real time through centralized monitoring.
・Analyze cybersecurity events from multiple sources such as SIEM, IDS/IPS, EDR, AV, Firewalls, etc.
・Respond to and contain cybersecurity incidents, and identify eradication strategies.
・Facilitate the transformation of the current SOC and Incident Response capabilities.
・Manage adversary indicators of compromise, tracking, and monitoring of adversary tactics, techniques, and procedures, motivations, goals and strategic objectives.
・Manage incident response activities, including incident triage, containment, eradication, and recovery to minimize the impact of security incidents on the organisation.
・Lead cyber threat intelligence collaboration internally and externally.
・Create industry standard group level ‘Follow the Sun’ fusion center of CTI and SOC professionals to provide a center for the monitoring, analysis and reporting of cyber events and activities to identify trends and potential risks and leading proactive measures to mitigate.
・Ensures all CTD activities are compliance with all relevant regulations and standards.
・Collaborate with cross-functional teams to assess security posture and recommend improvements to enhance threat detection and response capabilities.
・Provides regular cyber threat briefings about adversarial threat modelling, advanced analytics, and other leading-edge technologies to proactively inform multiple audiences of potential threats.
・Understand how to convert highly technical language to business-centric language including being able to clearly explain the impact of threats on the business value chains.
・Stay informed about industry trends and best practices in CTD, and recommend improvements to enhance the division’s performance.
・Provide clear guidance to key stakeholders (e.g., IT, business, legal, compliance) on how to meet specific security requirements that will enhance all CTD activities.
・Establish relationships with law enforcement and other cyber threat defense agencies in Japan but also in other countries where Our company has large operations centers.
・Develop and maintain security policies, procedures, and guidelines to ensure compliance with regulatory requirements and industry standards.
大手証券会社でのGlobal Head of Information Security Risk & Controls
おすすめ年齢
20代
30代
40代
50代以上
年収レンジ
年収イメージ:1400万円〜2000万円以上(経験・能力を考慮の上当社規定により決定)
ポジション
Executive Director
仕事内容
Responsibilities:
・Develop security reporting/metrics for multiple audiences including executive management and board reporting. Ensure that the relevant metrics are fed into various committees and the Chief Control Office framework and the 2nd Line of Defense.
・Responsible for the implementation of the BISTRA (Business-centric Security Threat & Risk Assessment) Methodology across the most critical value chains of the firm.
・Select, deploy, and manage the Security GRC Portal management to manage the risk and control framework as well as the BISTRA methodology.
・Track and manage all audit, regulatory examinations, client requests, law enforcement requests, and external certifications.
・Manage the risk treatments of security issues and risks identified such as risk acceptances, risk deferments, etc. on behalf of the program and project teams and other stakeholders. Track and monitor the risk treatments to closure.
・Develop and manage all security documentation for the Global CISO team including a library of threats, risks, controls, mitigating practices, capabilities, functions, tools, and processes.
・Monitor and report on compliance with information security and cybersecurity regulations and standards.
・Collaborate with internal stakeholders to ensure alignment of information security risk and controls governance with business objectives.
・Stay current on security risk and controls trends, threats, and regulatory requirements to proactively address emerging issues.
・Responsible for formalising the response to information security incidents, such as data breaches or cyber compromises internally and to regional regulators in accordance with notification rules
・Develop and manage the third-party security risk management team including security assessments and onsite security audits for third parties.
・Develop security reporting/metrics for multiple audiences including executive management and board reporting. Ensure that the relevant metrics are fed into various committees and the Chief Control Office framework and the 2nd Line of Defense.
・Responsible for the implementation of the BISTRA (Business-centric Security Threat & Risk Assessment) Methodology across the most critical value chains of the firm.
・Select, deploy, and manage the Security GRC Portal management to manage the risk and control framework as well as the BISTRA methodology.
・Track and manage all audit, regulatory examinations, client requests, law enforcement requests, and external certifications.
・Manage the risk treatments of security issues and risks identified such as risk acceptances, risk deferments, etc. on behalf of the program and project teams and other stakeholders. Track and monitor the risk treatments to closure.
・Develop and manage all security documentation for the Global CISO team including a library of threats, risks, controls, mitigating practices, capabilities, functions, tools, and processes.
・Monitor and report on compliance with information security and cybersecurity regulations and standards.
・Collaborate with internal stakeholders to ensure alignment of information security risk and controls governance with business objectives.
・Stay current on security risk and controls trends, threats, and regulatory requirements to proactively address emerging issues.
・Responsible for formalising the response to information security incidents, such as data breaches or cyber compromises internally and to regional regulators in accordance with notification rules
・Develop and manage the third-party security risk management team including security assessments and onsite security audits for third parties.
全4件
1-4件目を表示中