Governance Strategist for ITGC and Identity & Access Management at Truist. Coordinating governance structures and driving risk management initiatives across technology teams.
Responsibilities
Provide coordination, effective challenge and robust independent oversight of policies, limits, and committees to drive effective governance structures and requirements to effectively manage and mitigate risks within assigned business units and support alignment with the overall corporate strategy.
Provide consultative leadership and develop working relationships across assigned business units and committees to drive the implementation and execution of a multi-level governance document structure and comprehensive inventory for all defined governance materials.
Support and contribute to the design, implementation, and execution of comprehensive, forward-looking and risk-based frameworks, processes, and systems for prioritizing, structuring, reviewing and approving governance materials throughout the company.
Support the monitoring and execution of risk governance policies and procedures to establish defined processes, clear roles and responsibilities, and effective challenge routines.
Identify and monitor risk governance exceptions, issues, and emerging trends across assigned business units and committees to drive their remediation, acceptance, or escalation to governing bodies.
Document the governance and reporting program including methodologies, processes and procedures, report writing, conventions for consistently vetting and documenting findings and working papers.
Lead the development and maintenance of processes and procedures to ensure the accuracy of the reports produced by the team.
Evaluate control weakness or key indicators exceeding risk limits and perform root cause analysis.
Build a working knowledge of the business units strategic plan, key objectives, risk appetite statement, and RSCA process to understand the risks identified and controls applied to mitigate them in order to execute ad hoc risk management initiatives and controls testing.
Assist in the detection of emerging and/or under recognized risks.
Conduct data aggregation to support risk appetite framework and quarterly profile, including KRI's and ongoing risk identification.
Assist business leaders in development of RAF metrics and thresholds.
Generate content for regular management and risk program governance committees.
Facilitate Risk Committee and other risk committee/working groups.
Demonstrate Truist’s risk culture.
Requirements
Bachelor’s degree in Business, Finance, Communications or equivalent education and related training
Eight to twelve years of financial services or risk management experience, and/or equivalent education, training and experience
Strong interpersonal and relationship management skills with ability to interact and communicate within all levels of organization, across functions, and within public sector/governmental agencies
Strong analytical, cognitive, conceptual, critical thinking and organizational skills
Demonstrated leadership, communication (verbal and written), presentation and facilitation skills
Demonstrated planning ability with demonstrated judgment, problem-solving and decision-making skills
Demonstrated proficiency in basic computer applications, such as Microsoft Office software products
Experience auditing SOX 404 / 302 ITGC controls, particularly within logical security and Identity & Access Management (IAM)
Working knowledge of IAM concepts such as provisioning, de-provisioning, role-based access, privileged access management (PAM), authentication/authorization mechanisms, and access review processes
Hands-on or oversight experience with IAM platforms (e.g., SailPoint, Active Directory / Azure AD, CyberArk, etc.)
Experience supporting or executing ITGC walkthroughs, control testing, or evaluating IT control deficiencies
Benefits
medical, dental, vision, life insurance
disability, accidental death and dismemberment
tax-preferred savings accounts
401k plan
at least 10 days of vacation
10 sick days
paid holidays
defined benefit pension plan
restricted stock units
deferred compensation plan
Job title
SOX Governance Strategist – Identity and Access Management
Associate in Model Risk Management role within Financial Services Group analyzing financial risks. Support senior members with model validation, risk assessments, and deliver reports.
Senior Supervisory Control Specialist overseeing compliance and supervisory practices within Wealth and Investment Management. Collaborating with business partners to mitigate risks while ensuring adherence to regulations.
Risk Management & Insurance Intern role at Orchid Insurance in Tampa, FL. Participating in a 6 - week summer internship program focused on risk management and insurance fundamentals.
Intern supporting climate risk and exposure analytics at USAA with modeling and data analysis for catastrophe management. Collaborating across teams to address climate impacts and improve resilience strategies.
Senior Operational Risk Officer providing oversight and risk management expertise for KeyCorp's Consumer Bank. Engaging with business units to ensure effective operational risk management practices.
Customer Complaint Resolution Specialist in the Customer Advocacy team addressing escalated complaints. Conducting investigations, preparing executive - level responses, and advocating for better customer experiences at M&T Bank.
Manager of Information Governance and Privacy overseeing compliance and incident investigations at CVS Health. Fostering privacy culture and risk remediation for Health Services Segment.
Clinical Nurse Risk Strategist translating complex medical and pharmacy data into actionable insights for employers. Collaborating with teams to support cost management and health outcomes.
Technology Risk and Control Associate managing technology risk and analytics at AIG. Involved in risk assessments, reporting, and working with technology teams for compliance.
Market Risk Manager providing oversight of capital markets products at State Street. Ensuring risk analysis and compliance with regulations while analyzing balance sheet risk management frameworks.