- Develops, implements, maintains, and continuously enhances the Controls Testing Program.
- Establishes and maintains methodologies, standards, procedures, and support documentation for independent assessments and testing activities.
- Executes independent assessments to evaluate the design and effectiveness of IT and Cybersecurity controls.
- Evaluates controls against internal policies, regulatory requirements, and industry-recognized frameworks.
- Provides credible challenge to First Line of Defense control owners regarding control effectiveness and remediation activities.
- Analyzes and documents assessment results, identify control gaps, root causes, and risk themes, and determine remediation priorities.
- Validates corrective actions and prepares clear, concise, and actionable reports that communicate findings and recommendations to management and stakeholders.
- Supports internal audits, external audits, regulatory examinations, and inquiries by providing documentation and supporting evidence.
- Monitors emerging threats, technology risks, regulatory developments, audit observations, and industry practices and incorporate relevant changes into methodologies and program coverage.
- Identifies opportunities to enhance assessment methodologies through automation, analytics, and approved AI-enabled capabilities.
- Coordinates internal and external penetration testing engagements, including scope, objectives, and testing requirements.
- Reviews penetration testing results, assess the adequacy of remediation plans and corrective actions, and maintain supporting documentation and historical records.
- Supports other Second Line of Defense Cyber and Technology Risk activities as assigned.
- Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti-money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.).
- Adheres to Bank policies and procedures and completes required training.
- Identifies and reports suspicious activity.
- Minimum 4-6 years of experience in controls testing, IT audit, cybersecurity, technology risk, compliance, or related disciplines.
- Experience performing control design assessments, control effectiveness evaluations, and remediation validation activities.
- Experience evaluating IT and Cybersecurity controls and documenting observations, findings, and recommendations.
- Experience developing, implementing, executing, and maintaining controls testing, validation, or oversight program preferred.
- Experience coordinating penetration testing engagements preferred.
- Experience working within banking, financial services, or other highly regulated industries preferred.
- Experience interacting with auditors, regulators, and senior management preferred.
- Strong understanding of risk management principles, controls frameworks, and regulatory requirements.
- Knowledge of controls testing methodologies, program development, evidence evaluation techniques, and remediation validation processes.
- Strong understanding of the Three Lines Model and the respective responsibilities of 1LoD, 2LoD, and Internal Audit.
- Familiarity with NIST Cybersecurity Framework (CSF), NIST SP 800-53, CIS Controls, FFIEC guidance, and related industry standards.
- Familiarity with penetration testing processes and remediation validation practices.
- Strong analytical, organizational, and problem-solving skills.
- Excellent written, verbal, and presentation skills with the ability to communicate complex technical and risk concepts to diverse audiences.
- Ability to present findings and recommendations clearly, objectively, and independently.
- Ability to manage multiple priorities and deadlines while maintaining attention to detail.
- Ability to work independently as the subject matter expert for the Controls Testing Program and drive continuous improvement initiatives.
Skills Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Risk Management, or a related field
- 4-6 years of experience in controls testing, IT audit, cybersecurity, technology risk, compliance, or related disciplines
- Experience performing control design assessments, control effectiveness evaluations, and remediation validation
- Experience evaluating IT and cybersecurity controls and documenting observations, findings, and recommendations
- Experience developing, implementing, executing, and maintaining controls testing, validation, or oversight programs
- Experience coordinating penetration testing engagements
- Experience in banking, financial services, or other highly regulated industries
- Experience interacting with auditors, regulators, and senior management
- Professional certification such as CISA, CRISC, CISSP, CISM, CCSP, or equivalent
- Knowledge of risk management principles, controls frameworks, regulatory requirements, controls testing methodologies, evidence evaluation, and remediation validation
- Knowledge of the Three Lines Model and responsibilities of the First Line, Second Line, and Internal Audit
- Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, FFIEC guidance, and related industry standards
- Familiarity with penetration testing processes and remediation validation practices
- Strong analytical, organizational, problem-solving, written, verbal, and presentation skills
BankUnited Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about BankUnited and has not been reviewed or approved by BankUnited.
-
Healthcare Strength — Healthcare coverage is positioned as comprehensive, with medical, dental, and vision options plus disability and life insurance. Wellness programming is described as robust, including incentives, screenings, and on-site fitness facilities at the corporate center.
-
Retirement Support — Retirement support includes a 401(k) plan with a company match and relatively quick eligibility after one month. Auto-enrollment and auto-increase features are described, which can help employees build savings consistently.
-
Leave & Time Off Breadth — Time-off offerings are described as broad, including a sizable PTO range by level and paid holidays. Additional time-off programs such as volunteer time and flexible/hybrid/remote arrangements are also described for eligible positions.
BankUnited Insights
What We Do
BankUnited, Inc., with total consolidated assets of $35.2 billion at March 31, 2021, is a bank holding company with one wholly owned subsidiary, BankUnited. BankUnited, a national banking association headquartered in Miami Lakes, Florida, provides a full range of banking services to individual and corporate customers through banking centers in Florida and New York. The Bank also provides certain commercial lending and deposit products on a national platform. Here at BankUnited, we endeavor to provide, through experienced lending and relationship banking teams, personalized customer service and offer a full range of traditional banking products and services to both commercial and retail customers.









