IT Risk Principal providing risk governance and oversight across technology and operational risks at Huntington Bank. Managing cybersecurity programs and compliance in a financial institution.
Responsibilities
Management of processes to ensure credible challenge, oversight, and validation of IT risk findings/action plans/risk acceptances and 1st line risk and control assessments across the Bank
Management and Oversight of assigned L2 risk(s) from our Risk Registry in alignment with our risk appetite
Participation and Challenge within the IT Policies and Standards framework and processes to ensure output is aligned with risk appetite. This includes metrics, controls, process maps and other wholesale material for a healthy standard.
Deliver periodic IT risk updates at governance meetings and active participation in the IT Risk Committee and associated sub-forums
Deliver quarterly independent IT Risk Assessments and targeted assessments to form and support the Bank’s IT risk profile
Providing Risk Management leadership across the Bank’s Information Technology, and Operational risks
Assisting with determining the IT Risk Program's strategy and areas of focus
Participation in our mentorship programs in alignment with our focus on colleague growth
Provide Risk Management and thought leadership across the Bank’s Cyber and Cloud domains
Active participation and challenge of proposed and existing Cyber processes and procedures focused on key topics including Threat and Vulnerability Management, Network Governance and Domain Management, Cybersecurity Operations, Zero Trust, Posture Compliance and Drift Management, Data Governance, Security Education and Outreach Management, Post Quantum Computing, Cyber Risk Quantification, and Red\Blue\Purple Teaming
Engage with subject/domain owners to provide effective challenge of strategy, decisions, roadmaps, tools/solutions, policies/standards, findings/action plans/risk acceptances, etc.
Provide deep analysis of Cyber and Cloud vendors, products and services
Active analysis and oversight of Cyber governance technology controls
Requirements
Bachelor's degree or equivalent level of work experience
Five or more years relevant experience in a technology role, directly supporting technology processes or assets (applications/systems/etc.) within a financial institution.
Previous experience serving in a Governance/Risk/Compliance/Audit function, ideally in a leadership role and with a large firm
Effective advisory and collaboration skills, and ability to drive consensus
Advanced understanding of the IT process (developing, delivering, supporting technology) and associated grasp of Technology Risks and Controls
Logical and organized problem solver
Effective written and verbal communication skills.
Critical/strategic thinker (able to look at something strategically and think risk, efficiency, cost, etc. – big picture ‘so what’ analysis and can execute what’s needed to help support the effort)
Process-oriented mindset and able to tell a story leveraging data
Time management/organized/ability to prioritize
Managerial courage and ability to effectively interact with various levels of leadership
In-depth knowledge of risk management processes and principles, including experience assessing risks, analyzing testing results and developing remediation plans
Strong preference for recognized industry certification such as ISACA CRISC/CISA/CISM, ISC2 CISSP/SSCP, or similar. Where these certifications are not possessed at the time of hire, the candidate will be expected to obtain certification within a 12-month period
Experience working in the Financial Services industry
Investigation Analyst in Provider Risk at Manulife focusing on fraud prevention, detection, and investigation in the healthcare sector, working with internal teams and stakeholders.
Operational Risk & Resilience Manager overseeing governance and risk management activities in the financial services sector. Collaborating with multiple businesses to enhance operational risk awareness.
Consultant providing ecotoxicology and environmental risk assessment services for clients in the chemical sector. Role involves working collaboratively to meet regulatory needs and deliver high - quality consultancy services.
Operational Risk Analytics Intern assisting in operational risk management tasks at State Street across various departments. Engaging in projects, learning events, and supporting deliverables with a focus on data and analytics.
Merchant Risk Monitoring Associate assessing fraud, credit, and brand risks for global fintech company. Collaborating with merchants to manage risk effectively in hybrid setting.
Data Analyst intern at Česká spořitelna focusing on Data Governance and AI initiatives in banking. Involves collaborating on data management and quality projects with modern data tools.
Senior Data Governance professional designing and implementing data governance frameworks. Working closely with clients to align governance with data architectures and business needs at SunnyData.
IT Risk Analyst conducting threat analysis and managing Technology risk at Davy Group. Collaborating with teams to enhance IT security and ensuring compliance with regulatory standards.
CCO Governance Analyst assessing the integrity and effectiveness of the banks internal control framework. Collaborating with stakeholders to maintain control effectiveness and mitigate risk.
Head of Risk & Controls in corporate banking technology managing internal controls and mitigating risks within a Tier - 1 bank ecosystem. Leading strategic initiatives and engaging stakeholders while ensuring control effectiveness.