ITAO, AVP

Posted 8 Days Ago
Be an Early Applicant
Park, MI, USA
In-Office
Expert/Leader
Financial Services
The Role
Own onboarding, governance, security and lifecycle of business-aligned SaaS and internal applications. Ensure IAM, SDLC controls, audits, patching, DR tests, capacity planning, incident reduction, and compliance with policies and standards.
Summary Generated by Built In
Job Description:

Job Title: ITAO, AVP

Location: Pune, India

Corporate Title: Assistant Vice President

Role Description

We are seeking an ITAO to join DWS's Private Markets Technology team to onboard and own business aligned strategic SaaS (Software as a Service) and internal applications. You will work closely with the wider technology team and business stakeholders to ensure applications are onboarded and operated in a compliant manner to achieve the business outcomes.

  • The successful candidate is expected to have at least 12-15 years’ experience in IT, preferably with Asset Management Business Applications and Processes.
  • The IT Application Owner (ITAO) has sound IT risk management skills. They follow one of several possible service delivery approaches, acknowledge interference with the IT application’s life cycle and assist with incorporating the adopted approach into best practice.
  • Make sure that all steps in Identity & Access Management cycle (on-boarding, recertification, off-boarding) are compliant with DB Policies and application is on-boarded to central tools.
  • The ITAO is aware of the gap in the current infrastructure solutions and where industry innovations are along the maturity lifecycle. They work with application stakeholders to improve the infrastructure, ensuring compliance with the technical roadmap.
  • The ITAO has a sound knowledge of development methodologies and the IT policies necessary to perform effectively in the organisation, aligned to the bank’s appetite for risk.
  • The ITAO acts to improve safety and security of the application, compliance with regulations, policies and standards, enhance operational readiness, and ease maintenance of the environment for delivering change into production.
  • The ITAO supports the bank’s audit function in the remediation of audit points and self-identified issues in order to reduce risk.
  • The ITAO is responsible for producing and maintaining accurate documentation on compliance with methodologies, IT policies and IT security requirements.
  • ITAOs will also be responsible for Application Decommissioning
  • ITAOs will be driving activity that helps incidents reduction against an application
  • Support compliance on all steps of SDLC process and make sure that all SDLC controls are green.
  • Consult with the ITAO community, information security specialists in our CSO organization, and other infrastructure teams like the ORR/SDLC teams.

What we’ll offer you

As part of our flexible scheme, here are just some of the benefits that you’ll enjoy

  • Best in class leave policy
  • Gender neutral parental leaves
  • 100% reimbursement under childcare assistance benefit (gender neutral)
  • Sponsorship for Industry relevant certifications and education
  • Employee Assistance Program for you and your family members
  • Comprehensive Hospitalization Insurance for you and your dependents
  • Accident and Term life Insurance
  • Complementary Health screening for 35 yrs. and above

Your key responsibilities

  • Enterprise IT Governance: Responsible for review of current and proposed information systems for compliance with the organisation's obligations (including legislation, regulatory, contractual and agreed standards/policies) and adherence to overall strategy
  • Information security:  Communicates information security risks and issues to business managers and others. Performs basic risk assessments for small information systems. Contributes to vulnerability assessments. Applies and maintains specific security controls as required by organisational policy and local risk assessments. Investigates suspected attacks. Responds to security breaches in line with security policy and records the incidents and action taken.
  • Information content publishing: Understands technical publication concepts, tools and methods and the way in which these are used. Uses agreed procedures to publish content. Obtains and analyses usage data and presents it effectively. Understands, and applies principles of usability and accessibility to published information.
  • Business risk management: Investigates and reports on hazards and potential risk events within a specific function or business area.
  • Continuity management: Implements and contributes to the development of a continuity management plan. Coordinates the assessment of risks to the availability, integrity and confidentiality of systems that support critical business processes. Coordinates the planning, designing, and testing of maintenance procedures and contingency plans.
  • Data management: Assists in providing accessibility, retrievability, security and protection of data in an ethical manner.
  • Methods and tools: Provide support on the use of existing method and tools. Configures methods and tools within a known context. Creates and updates the documentation of methods and tools

Overall Responsibilities Summary:

  • Work closely with business application users and SaaS vendors on application onboarding and governance.
  • Ensure appropriate controls onboarded and implemented where appropriate.
  • Make sure that all steps in Identity & Access Management cycle (on-boarding, recertification, off-boarding) are compliant against DB Policies and application is on-boarded to central tools.
  • Manage Internal and external application audits and Audit issue remediation activities.
  • Completion of regular/recurring assessments
  • Timely response to audit & regulatory requirements with evidence, were compliant.
  • Make sure that infrastructure is compliant and has up-to-date patches.
  • Plan for Application Hardware / Software / License upgrades or migration activities to align to the compliant platforms.
  • Keep up-to-date DR Test Plan and manage regular DR Tests
  • Manage application capacity forecasting and monitoring.
  • Manage any IT Security incidents that may occur in the application.
  • Support compliance on all steps of SDLC process and make sure that all SDLC controls are green.
  • Application Decommissioning
  • Drive incidents reduction against an application

Your skills and experience

Must have

  • Hands on understanding of risk frameworks, control environments and application governance.
  • Experience in Software Development Lifecycle (SDLC) - from idea to production to understand our customer journey, these mostly application owners, business ISOs and development teams
  • Experience on File transfer ,Filenet , SFTP, dbExchange, Datagateway, APIs.
  • Basic Technical capabilities and infrastructure knowledge (e.g.: MS SQL Server or Oracle database, PL/SQL, Linux, Network (firewalls, VPN) etc)
  • Enterprise technology knowledge and experience (e.g. application architecture, infrastructure, data transfer methods (SFTP), application and database technologies.)
  • Experience with business tools including Jira, Confluence, Share point, and Microsoft 365. Expertise in Jira Dashboards, Confluence documentation.
  • Planning/Organizing: Able to manage work but also to make the estimate, scheme in detail, work on deployment plans and manage deadlines.
  • Manage the technical roadmap of the application (technology roadmap compliance), estimate/budget capacity needed.
  • Expertise in Planning and execution of Releases, Changes, Patches.
  • Exposure of handling L3 role, incident analysis, patch preparation and implementation.
  • Skilled individual to interact with L2 teams for incident and problem management cases.

Education / Certification / Experience

  • Degree-level IT and/or information security qualification, or equivalent experience in information Security and IT Security
  • General understanding of current security industry standards, best practices, and/or frameworks i.e.: NIST, ENISA, ISO27001, OWASP
  • Problem-solving and analytical skills with the ability to oversee complex processes
  • Ability to educate a technical and non-technical audience about various security measure

Preferable

  • Knowledge of information security tools e.g., security scan and testing tools
  • Understanding of cloud engineering and native security features
  • Firm understanding of DevSecOps and the banks shift left agenda to integrate security in the software development lifecycle as earliest as possible.
  • ISO or ITAO certification (for internals only)
  • GCP-Cloud foundation knowledge
  • Scripting experience in Python, PowerShell and similar scripting tools.

How we’ll support you

  • Training and development to help you excel in your career
  • Coaching and support from experts in your team
  • A culture of continuous learning to aid progression
  • A range of flexible benefits that you can tailor to suit your needs

About us and our teams

Please visit our company website for further information:

https://www.db.com/company/company.html

We at DWS are committed to creating a diverse and inclusive workplace, one that embraces dialogue and diverse views, and treats everyone fairly to drive a high-performance culture. The value we create for our clients and investors is based on our ability to bring together various perspectives from all over the world and from different backgrounds. It is our experience that teams perform better and deliver improved outcomes when they are able to incorporate a wide range of perspectives. We call this #ConnectingTheDots.

Skills Required

  • 12-15 years' experience in IT, preferably with Asset Management business applications and processes.
  • Hands-on understanding of risk frameworks, control environments and application governance.
  • Experience across Software Development Lifecycle (SDLC) from idea to production.
  • Experience with file transfer technologies and tools: FileNet, SFTP, dbExchange, Datagateway and APIs.
  • Technical infrastructure knowledge: MS SQL Server or Oracle databases, PL/SQL, Linux, network components (firewalls, VPN).
  • Enterprise application architecture and data transfer method knowledge.
  • Experience with Jira, Confluence, SharePoint and Microsoft 365; expertise in Jira dashboards and Confluence documentation.
  • Planning and organizing skills for deployment plans, releases, changes, patches and roadmap management.
  • Experience in L3 incident analysis, patch preparation/implementation and interacting with L2 teams for incident/problem management.
  • Degree-level IT and/or information security qualification or equivalent experience.
  • General understanding of security industry standards and frameworks (NIST, ENISA, ISO27001, OWASP).
  • Problem-solving and analytical skills; ability to educate technical and non-technical audiences.
  • Manage application audits, remediation activities, DR tests, capacity forecasting and decommissioning.
  • Ensure Identity & Access Management processes (onboarding, recertification, offboarding) comply with policies and central tools.
  • Ensure infrastructure compliance and timely patching; plan hardware/software/license upgrades or migrations.
  • Drive incidents reduction and maintain SDLC controls in green.
  • Knowledge of information security tools (security scanning and testing)
  • Understanding of cloud engineering and native cloud security features (GCP knowledge preferred).
  • Firm understanding of DevSecOps and integrating security early in SDLC.
  • ISO or ITAO certification (internal candidates)
  • Scripting experience in Python, PowerShell or similar scripting tools.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Frankfurt am Main
3,893 Employees
Year Founded: 1956

What We Do

DWS Group (DWS) with EUR 933bn of assets under management (as of 30 June 2024) aspires to be one of the world's leading asset managers. Building on more than 60 years of experience, it has a reputation for excellence in Germany, Europe, the Americas and Asia. DWS is recognized by clients globally as a trusted source for integrated investment solutions, stability and innovation across a full spectrum of investment disciplines. We offer individuals and institutions access to our strong investment capabilities across all major liquid and illiquid asset classes as well as solutions aligned to growth trends. Our diverse expertise in Active, Passive and Alternatives asset management – as well as our deep environmental, social and governance focus – complement each other when creating targeted solutions for our clients. Our expertise and on-the-ground knowledge of our economists, research analysts and investment professionals are brought together in one consistent global CIO View, giving strategic guidance to our investment approach. DWS wants to innovate and shape the future of investing. We understand that, both as a corporate as well as a trusted advisor to our clients, we have a crucial role in helping to navigate the transition to a more sustainable future. With approximately 4,500 employees in offices all over the world, we are local while being one global team. We are committed to acting on behalf of our clients and investing with their best interests at heart so that they can reach their financial goals, no matter what the future holds. With our entrepreneurial, collaborative spirit, we work every day to deliver outstanding investment results, in both good and challenging times to build the best foundation for our clients’ financial future.

Similar Jobs

Deutsche Bank Logo Deutsche Bank

ITAO, AVP

Fintech • Financial Services
In-Office
Park, MI, USA
68787 Employees

IDeaS Logo IDeaS

Project Manager

Software • Analytics • Hospitality
Remote or Hybrid
United States
702 Employees

DFIN Logo DFIN

Manager - Sales Operations

Fintech • Software
Remote or Hybrid
United States
1750 Employees

Enverus Logo Enverus

Manager, Power Markets - 26232

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
5 Locations
1800 Employees
115K-130K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account