
Director, Technology Risk Management
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in United States.
• Lead the implementation of the Technology Risk Management framework in accordance with NIST CSF, FFIEC, and SOX ITGC.
• Convert regulatory requirements into practical controls and practices for Technology and Product teams.
• Define, operationalize, and oversee technology risk appetite, tolerances, and Key Risk Indicators (KRIs).
• Supervise the enterprise-wide identification and evaluation of risks related to cloud, infrastructure, cybersecurity, data protection, AI, emerging technologies, and third-party/vendor interactions.
• Provide data-driven insights and reports on risk posture, trends, and emerging risks to senior leadership.
• Facilitate the ongoing enhancement of control maturity and maintain the effectiveness of SOX ITGC.
• Collaborate with Technology teams to design and deploy scalable, automated controls.
• Ensure the execution of regulatory examinations, internal audits, and commitments to remediation.
• Manage issues effectively, including identification, prioritization, root cause analysis, and sustainable remediation.
• Promote the prompt remediation of high-risk issues and the reduction of aged items.
• Lead the adoption of automation and tools for risk identification, monitoring, and reporting.
• Assess and enhance technology processes to mitigate risk, boost resilience, and improve operational efficiency.
• Embed risk management within the Software Development Life Cycle (SDLC), product development, and change management processes.
• Establish governance and oversight for AI and emerging technologies.
• Evaluate risks associated with new technology initiatives and advise on safe adoption practices.
• Collaborate with Technology and Business leaders to proactively manage risk.
• Lead interactions with Internal Audit, External Audit, and second-line defense functions.
• Build and nurture a high-performing team.
• Execute other duties as assigned.
• A minimum of 10 years of experience in Technology Risk, Cybersecurity, IT Audit, or related fields within financial services or regulated environments.
• Proven experience working within or alongside first-line technology functions, demonstrating a strong orientation towards business partnership.
• Demonstrated success in evolving risk programs into strategic, insight-driven functions.
• In-depth understanding of cloud and infrastructure risks, cybersecurity, data protection, third-party/vendor risks, and risks related to AI/emerging technologies.
• Strong knowledge of FFIEC, NIST CSF, and SOX ITGC standards.
• Ability to translate complex technical risks into clear, concise reports suitable for executive-level audiences.
• Excellent judgement, capable of balancing risk management with business enablement.
• Proven ability to lead and cultivate high-performing teams.
• Strong stakeholder management skills, with experience engaging senior leadership and regulatory bodies.
• Ability to drive accountability, encourage collaboration, and foster a culture of continuous improvement.
• Bachelor's Degree.
• Relevant certifications such as CISA, CRISC, or CISSP.
• Health insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Paid time-off benefits.
• Flexible spending account.
• 401(k) with employer match.
• Employee Stock Purchase Plan (ESPP).
CenterWell Senior Primary Care
Ledgebrook
WNS
Exceptional HR Solutions, LLC
Get handpicked remote jobs straight to your inbox weekly.