Overview
In this role, you will lead technology risk assessment and control oversight to identify emerging firmwide risk themes and craft communications for senior decision-makers. You will provide SME guidance to process owners to ensure controls operate effectively and comply with regulatory standards. By partnering with Product, Risk & Control, Technology, and business stakeholders, you’ll deliver a comprehensive view of technology risk posture and its business impact. You’ll leverage AI-assisted approaches to accelerate risk synthesis while ensuring auditability and security. This role suits a proactive expert shaping risk management in a dynamic environment.
Responsibilities
- Identify, quantify, and communicate technology risk with root-cause analysis and remediation recommendations
- Analyze cybersecurity and technology data to derive risk intelligence and patterns
- Leverage enterprise-authorized AI to accelerate synthesis of risk evidence and draft executive reporting with strong data handling controls
- Build and maintain relationships with technologists, assessment teams, and data officers to enable cross-functional risk work
- Govern controls, policies, issue management, and measurements; provide senior-management insights on control effectiveness
- Monitor and evaluate control effectiveness; propose enhancements to strengthen risk posture and regulatory compliance
- Promote AI-assisted, reuse-first approaches for recurring control testing and action-plan management with human oversight and auditability
Key requirements
- 5+ years in technology risk management, cybersecurity, or related field
- CISSP, CRISC or equivalent qualification or formal training in tech risk/information security
- Experience with information management practices and insight production
- Experience using enterprise-authorized AI capabilities with strong validation habits
- Ability to review and validate AI-assisted risk outputs for security, auditability, and regulatory alignment
- Familiarity with risk management frameworks and regulatory requirements
- Proven ability to influence executive decision-making and translate tech insights into business strategy
- Strategic influence
- Cross-functional collaboration
- Strong communication with executive stakeholders
- Data security
- Risk assessment & reporting
- Control evaluation, design, and governance
…
