Commonwealth of Pennsylvania

POSITION DESCRIPTION FOR JOB POSTING

Position Number:  00069887

Description Activated On:  9/3/2026 1:53:02 PM


Position Purpose:
Describe the primary purpose of this position and how it contributes to the organization’s objectives. Example: Provides clerical and office support within the Division to ensure its operations are conducted efficiently and effectively. 

This position is responsible for implementation, oversight, and management of the department’s risk management, internal control, and vendor management programs in the Bureau of PRISM.

Description of Duties:
Describe in detail the duties and responsibilities assigned to this position. Descriptions should include the major end result of the task. Example: Types correspondence, reports, and other various documents from handwritten drafts for review and signature of the supervisor.

Risk Mgmt and Internal Controls:
Manages the enterprise risk management strategy for the department, which includes risk identification, determination of risk appetite, risk response, and ongoing monitoring of risk management activities for the department.

Evaluates new and existing departmental initiatives for risk, based upon department’s risk management policy, identified risk tolerance.

Facilitates meetings and workshops to identify risks and to determine the inherent and residual risk scores for each risk identified.

Determines areas of risk and makes recommendations to the Executive Office regarding the risk and reported ROI of new and existing initiatives to determine implementation or continuation of the initiative.

Creates, maintains and submits the department annual risk register and risk management report to the Office of the Budget.

Assists the bureaus in the development, monitoring and reporting of corrective action plans and progress for identified risks and internal control gaps.

Holds regular meetings with the bureaus to monitor the progress of identified corrective action plans.

Establishes, maintains and reports on testing of key internal controls and oversees bureau-level testing of process controls.

Provides updates to the Office of the Budget on the status of the department's risk management and internal controls program, as needed.

Reviews newly created or updated business process maps of the key processes within the departmental in order to determine controls and potential control gaps at the process level.

Runs quarterly Internal Control Oversight Committee (ICOC) meetings to provide updates to the committee on internal control and risk management activities.

Provides training and consultation to staff responsible for managing and responding to risk at the bureau-level.

Vendor Management:
Works in collaboration with the Bureau of Fiscal Management to assess risk in the department's vendor management strategy.
Manages the receipt of Service Organization Control (SOC) reports from designated vendors in contract with the department.

Reviews SOC reports from designated vendors in contract with the department and works with Office of Chief Counsel, Bureau of Fiscal Management, and the bureau overseeing the contract to address any findings through the implementation of corrective action plans with the service organization.

Documents and tests the Complementary User Entity Controls outlined in the SOC reports from designated vendors to ensure our compliance with complementing controls.


Coordinates and monitors, in coordination with the department’s Audit Liaison in Fiscal Management, the department’s official response or follow up to performance audits conducted by the Auditor General.

Coordinates the submission of a project requests with the Bureau of PRISM for corrective action plans or management responses that involve a technology solution or modification due to risk evaluation.

Demonstrates a commitment to the service-oriented culture of the Department.

Applies Lean thinking in day-to-day tasks.

Is mindful of internal controls and risk management when changes are made to a process.

Treats others equitably and adheres to diversity and inclusion requirements in the workplace.

Performs other related work as required.

Decision Making:
Describe the types of decisions made by the incumbent of this position and the types of decisions referred to others. Identify the problems or issues that can be resolved at the level of this position, versus those that must be referred to the supervisor. Example: In response to a customer inquiry, this work involves researching the status of an activity and preparing a formal response for the supervisor’s signature.

1. Researches best practices and approaches for operational strategies, policies and plans.
2. Makes recommendations for operational strategies, policies and plans.
3. Implements the department’s enterprise risk management and internal controls program.
4. Makes recommendations on policy or process improvements.

Requirements Profile: Identify any specific experience or requirements, such as a licensure, registration, or certification, which may be necessary to perform the functions of the position. Position-specific requirements should be consistent with a Special Requirement or other criteria identified in the classification specification covering this position. Example: Experience using Java; Professional Engineer License

Experience:



Licenses, registrations, or certifications:

1. 
  N/A
 
2.  
N/A
 
3.  
N/A
 
4.  

 
5.  

 
6.  


Essential Functions
: Provide a list of essential functions for this position. Example: Transports boxes weighing up to 60 pounds.
 
 1. Communicates effectively both verbally and in writing
 2. Establishes and maintains effective working relationships
 3. Conducts research, analysis and provides recommendations
 4. Analyzes and interprets information and data
 5. Proficiently navigates a PC, software applications and computer systems
 6. Creates, interprets and implements regulations, policies and procedures
 7. Facilitates workshops and meetings
 8. Speaks publically to large groups of people
 9. Travels, as required
 10.