CybersecurityJobs.io
← Back to all jobs

Job Description

Own second line compliance and operational risk oversight for application and technology security within high-risk technology environments.

Responsibilities

  • Assess risks and the effectiveness of Front Line Unit (FLU) processes and controls to support compliance with applicable laws, rules, and regulations
  • Support regulatory inquiries and participate in audits and examinations with independent oversight
  • Provide independent compliance and operational risk coverage of FLU and/or Control Function (CF) performance and related third-party or vendor relationships in alignment with the Global Compliance - Enterprise Policy and the Operational Risk Management - Enterprise Policy, plus the Compliance and Operational Risk Management Program and Standard Operating Procedures
  • Identify and escalate problems or issues, drive actions to address root causes that lead to compliance risk issues and/or operational risk losses
  • Monitor inventories of processes, risks, controls, and associated metrics for risk appetite and limits, including reporting violations of compliance and regulatory activities
  • Contribute to independent risk management reporting for covered areas to support country or regional governance and management routines
  • Analyze and interpret applicable laws, rules, and regulations to provide clear, practical guidance and identify or manage risks
  • Review and challenge FLU/CF processes, risk, Single Process Inventory, and FLU/CF Risk and Control Self-Assessment outputs for themes or trends, while tracking regulatory change relevant to the coverage area(s)
  • Monitor and assess adherence to Global Technology policies and standards
  • Perform inline review of ITGPST issue management activities, including remediation of regulatory issues
  • Provide independent second line oversight of the Application and Technology Security Assessment program, including control effectiveness review, risk identification, issue management, and regulatory compliance
  • Assess technology and cyber risks across critical applications, business processes, and technology environments
  • Review and challenge risk acceptance decisions, remediation strategies, and control design for application security risks
  • Monitor emerging technology and AI-related risks, evaluate evolving cyber threats, governance frameworks, and control environments to confirm appropriate risk management practices
  • Support executive reporting, governance routines, and strategic communications for senior leadership audiences
  • Evaluate adherence to enterprise risk management standards, technology policies, and regulatory expectations
  • Partner across technology, cybersecurity, risk, audit, and business teams to strengthen operational resilience and risk management

Requirements

  • 7+ years of experience in operational risk, technology risk, information security, cybersecurity, compliance, audit, or related risk management disciplines, preferably within a large financial institution
  • Expertise in cybersecurity, application security, technology governance, third-party technology risk management, or operational resilience
  • Ability to influence and challenge senior leaders and executive stakeholders while maintaining effective partnerships
  • Experience supporting regulatory examinations, audit engagements, issue remediation programs, and risk governance activities
  • Background in risk-related disciplines with strong experience in the Global Compliance & Operational Risk program from a 1st or 2nd line perspective
  • Comfort communicating with clarity and impact at the executive level and shaping outcomes
  • Understanding of AI-related risks, governance considerations, cybersecurity implications, and how technology-enabled solutions support risk management activities
  • Familiarity with GCOR programs, Global Technology policies, and ITGPST processes and risks
  • Skill in identifying, assessing, and remediating operational risks and issues
  • Proficiency generating actionable insights using data analysis and reporting tools
  • Ability to build trust, challenge constructively, and partner effectively across the enterprise
  • Proficient with industry security frameworks (e.g., NIST CSF) and applicable Laws, Rules, and Regulations

Technologies

  • NIST CSF
  • AI-related risks
  • ITGPST
  • Global Technology policies
  • Application and Technology Security Assessment
  • Technology Third Party Risk Management
  • Single Process Inventory
  • FLU/CF Risk and Control Self-Assessment

Desired Qualifications

  • Familiarity with Application Technology Security Assessments, vulnerability management, software development lifecycle controls, or application security testing programs
  • Understanding of emerging technology risks, including AI governance, model risk considerations, and cybersecurity implications of AI-enabled technologies
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent risk and technology certifications
  • Second or third line of defense experience, or experience in a business risk and controls role
  • Strong familiarity with the Global Compliance & Operational Risk (GCOR) program and related tools or applications
  • Familiarity with the Issues Management program and tools
  • Demonstrated success leading targeted assessments, audits, or regulatory exam engagements, including authoring responses, report outs, and observations
  • Constructively challenges; supports opinions and recommendations with facts and data
  • Demonstrates productive partnering with stakeholders across the enterprise at all levels

Skills

  • Advisory
  • Monitoring, Surveillance, and Testing
  • Regulatory Compliance
  • Reporting
  • Risk Management
  • Critical Thinking
  • Influence
  • Interpret Relevant Laws, Rules, and Regulations
  • Issue Management
  • Policies, Procedures, and Guidelines Management
  • Business Process Analysis
  • Decision Making
  • Negotiation
  • Process Management
  • Written Communications

Location and Schedule

  • Charlotte, NC (onsite)
  • Shift: 1st shift (United States of America)
  • Hours per week: 40

Similar Jobs