Compliance and Operational Risk Manager β Application Security and Technology Risk Oversight
Job Description
Own second line compliance and operational risk oversight for application and technology security within high-risk technology environments.
Responsibilities
- Assess risks and the effectiveness of Front Line Unit (FLU) processes and controls to support compliance with applicable laws, rules, and regulations
- Support regulatory inquiries and participate in audits and examinations with independent oversight
- Provide independent compliance and operational risk coverage of FLU and/or Control Function (CF) performance and related third-party or vendor relationships in alignment with the Global Compliance - Enterprise Policy and the Operational Risk Management - Enterprise Policy, plus the Compliance and Operational Risk Management Program and Standard Operating Procedures
- Identify and escalate problems or issues, drive actions to address root causes that lead to compliance risk issues and/or operational risk losses
- Monitor inventories of processes, risks, controls, and associated metrics for risk appetite and limits, including reporting violations of compliance and regulatory activities
- Contribute to independent risk management reporting for covered areas to support country or regional governance and management routines
- Analyze and interpret applicable laws, rules, and regulations to provide clear, practical guidance and identify or manage risks
- Review and challenge FLU/CF processes, risk, Single Process Inventory, and FLU/CF Risk and Control Self-Assessment outputs for themes or trends, while tracking regulatory change relevant to the coverage area(s)
- Monitor and assess adherence to Global Technology policies and standards
- Perform inline review of ITGPST issue management activities, including remediation of regulatory issues
- Provide independent second line oversight of the Application and Technology Security Assessment program, including control effectiveness review, risk identification, issue management, and regulatory compliance
- Assess technology and cyber risks across critical applications, business processes, and technology environments
- Review and challenge risk acceptance decisions, remediation strategies, and control design for application security risks
- Monitor emerging technology and AI-related risks, evaluate evolving cyber threats, governance frameworks, and control environments to confirm appropriate risk management practices
- Support executive reporting, governance routines, and strategic communications for senior leadership audiences
- Evaluate adherence to enterprise risk management standards, technology policies, and regulatory expectations
- Partner across technology, cybersecurity, risk, audit, and business teams to strengthen operational resilience and risk management
Requirements
- 7+ years of experience in operational risk, technology risk, information security, cybersecurity, compliance, audit, or related risk management disciplines, preferably within a large financial institution
- Expertise in cybersecurity, application security, technology governance, third-party technology risk management, or operational resilience
- Ability to influence and challenge senior leaders and executive stakeholders while maintaining effective partnerships
- Experience supporting regulatory examinations, audit engagements, issue remediation programs, and risk governance activities
- Background in risk-related disciplines with strong experience in the Global Compliance & Operational Risk program from a 1st or 2nd line perspective
- Comfort communicating with clarity and impact at the executive level and shaping outcomes
- Understanding of AI-related risks, governance considerations, cybersecurity implications, and how technology-enabled solutions support risk management activities
- Familiarity with GCOR programs, Global Technology policies, and ITGPST processes and risks
- Skill in identifying, assessing, and remediating operational risks and issues
- Proficiency generating actionable insights using data analysis and reporting tools
- Ability to build trust, challenge constructively, and partner effectively across the enterprise
- Proficient with industry security frameworks (e.g., NIST CSF) and applicable Laws, Rules, and Regulations
Technologies
- NIST CSF
- AI-related risks
- ITGPST
- Global Technology policies
- Application and Technology Security Assessment
- Technology Third Party Risk Management
- Single Process Inventory
- FLU/CF Risk and Control Self-Assessment
Desired Qualifications
- Familiarity with Application Technology Security Assessments, vulnerability management, software development lifecycle controls, or application security testing programs
- Understanding of emerging technology risks, including AI governance, model risk considerations, and cybersecurity implications of AI-enabled technologies
- Professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent risk and technology certifications
- Second or third line of defense experience, or experience in a business risk and controls role
- Strong familiarity with the Global Compliance & Operational Risk (GCOR) program and related tools or applications
- Familiarity with the Issues Management program and tools
- Demonstrated success leading targeted assessments, audits, or regulatory exam engagements, including authoring responses, report outs, and observations
- Constructively challenges; supports opinions and recommendations with facts and data
- Demonstrates productive partnering with stakeholders across the enterprise at all levels
Skills
- Advisory
- Monitoring, Surveillance, and Testing
- Regulatory Compliance
- Reporting
- Risk Management
- Critical Thinking
- Influence
- Interpret Relevant Laws, Rules, and Regulations
- Issue Management
- Policies, Procedures, and Guidelines Management
- Business Process Analysis
- Decision Making
- Negotiation
- Process Management
- Written Communications
Location and Schedule
- Charlotte, NC (onsite)
- Shift: 1st shift (United States of America)
- Hours per week: 40
Similar Jobs
T
P
A