Information Technology Enterprise Risk Manager

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office
Senior level
Financial Services
The Role
Lead IT risk management activities across information technology, security, and data domains. Oversee RCSA processes, validate and test controls, challenge first-line assessments, support compliance (GLBA, PCI, HIPAA), monitor remediation, quantify technology risk metrics, analyze IT-related losses, and partner with IT/IS/Data teams to mature second-line defenses and governance.
Summary Generated by Built In
OH0713 NW Bancshares HQ, PA0728 Pittsburgh Business Office

Job Description

The Information Technology Enterprise Risk Manager within the Risk Management organization is responsible for supporting the execution and oversight of Northwest's Operational Risk framework as it relates to information technology, information security and data risks. This role will adapt previous experience and industry leading practices to identify, assess, monitor, and report key technology risks, helping to embed risk awareness into strategic and operational decision-making. This role will help to support activities including, but not limited to, Risk and Control Self-Assessments (RCSA), risk management training, issues management, risk management and policy and procedure governance.
 
Essential Functions
•    Provide oversight of the Risk and Control Self-Assessment (RCSA) activities within technology-related processes, performing credible challenge of the conclusions derived from the RCSA, and monitoring routines
•    Independently assess risks and drive actions to address the root causes that persistently lead to significant residual operational risk by challenging both historical and proposed practices
•    Validate the first line’s control testing and independently test the first line’s information technology, information security and data controls to verify the design and operational effectiveness
•    Leverage the current Enterprise Risk Management framework and partner with IT, IS and Data teams to further mature the second line of defense technology and information security risk assessments, document controls, identify gaps, and create action plans for critical IT processes, including validation and testing to ensure IT risk programs are implemented and executed appropriately
•    Provide support to key risk assessments and perform credible challenge of methodologies and results, including the annual Gramm-Leach-Bliley Act (GLBA) Assessment, Authentication and Access Assessments, Payment Card Industry Data Security Standard assessment and HIPAA compliance
•    Consult with the first line on the creation of issues to address control gaps/failures and monitor the progress of remediation, ensuring timely and accurate mitigation, and providing credible challenge to support the timely closure of issues
•    Support the establishment of metrics to quantify and measure technology risks and provide review and challenge to the action plans of deficient metrics
•    Perform oversight of the front-line’s management of IT/IS/Data activities and exception handling, including the documentation of IT changes, end-of-life technology, resiliency enhancements and testing, business impact analysis, vulnerability management, completion of action items related to addressing technology failures and disruptions, CDEs and data rules
•    Provide credible challenge of the first line’s IT/IS/Data policies and standards ensuring compliance under Northwest’s corporate governance requirements
•    Analyze losses in the Business associated with IT failures, disruptions and errors to understand how losses were incurred, determined lessons learned, identify root causes and developing recommendations for future risk avoidance
 
Additional Essential Functions
•    Ensure compliance with Northwest’s policies and procedures, and Federal/State regulations
•    Navigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiency
•    Work as part of a team
•    Work with on-site equipment
 
What You Bring to the Team
•    Additional job duties as assigned by management
 
QUALIFICATIONS
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
 
Education 
Bachelor's Degree    Degree in Management Information Systems, Cybersecurity, or Business Administration             
 
Work Experience     
8 - 12 years    Cybersecurity/information technology experience And
6 - 8 years    Prior financial institution experience             
 
Additional Knowledge, Skills and Abilities
•    Deep understanding of information technology, information security and data principles and best practices
•    Proficient in risk management methodologies, frameworks, and execution of the Risk and Control Self-Assessment (RCSA)  
•    Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)  
•    Experience with vulnerability scanning and penetration testing tools  
•    Strong analytical and problem-solving skills    
•    Excellent communication and reporting abilities    
•    Deep understanding of information technology and information security principles and best practices    
•    Proficient in risk management methodologies and frameworks    
•    Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)  
•    Experience with vulnerability scanning and penetration testing tools    
•    Strong analytical and problem-solving skills    
•    Excellent communication and reporting abilities  
 
Licenses and Certifications
    Infrastructure Library (ITIL)                
    Certified Information System Auditor               
    Certified Information Security Manager (CISM)                
    Certified Risk and Information Systems Control                 
    Certified Information Systems Security Professional (CISSP)                 
 
 


Northwest is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

Skills Required

  • Bachelor's Degree in Management Information Systems, Cybersecurity, or Business Administration
  • 8-12 years cybersecurity/information technology experience
  • 6-8 years prior financial institution experience
  • Deep understanding of information technology, information security and data principles and best practices
  • Proficient in risk management methodologies, frameworks, and execution of RCSA
  • Knowledge of compliance regulations and standards (NIST CSF, GLBA, PCI DSS, HIPAA)
  • Experience with vulnerability scanning and penetration testing tools
  • Strong analytical and problem-solving skills
  • Excellent communication and reporting abilities
  • Familiarity with Microsoft Office and department-specific applications
  • Certifications: ITIL, CISA, CISM, CRISC, CISSP
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Columbus, OH
136 Employees
Year Founded: 2008

What We Do

Northwest Bank is a privately held community bank focused on serving the specific needs of businesses in Washington, Oregon, Idaho and Utah. Our experienced bankers deliver customized financial solutions and exceptional customer service. We do that by getting to know you, your business and your aspirations, first. Then we create a plan that will work, and stay with you every step of the way. We see our relationship with you as a partnership, the way banking should be. Trust matters when picking your financial partner. Northwest Bank is rated as one of the best capitalized banks in the nation. We have earned 5-Star “Superior” ratings from both BauerFinancial® and Bankrate.com’s Safe and Sound® ratings service. Founded in 2008, we have offices in Boise, Idaho; Portland, Oregon; Coeur d'Alene, Idaho; Seattle, Washington; and Salt Lake City, Utah metropolitan markets. Northwest Bank: Experienced Bankers. Exceptional Service. Creative Solutions. Member FDIC Equal Housing Lender

Similar Jobs

Navan Logo Navan

Consultant

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Remote or Hybrid
USA
3300 Employees

DraftKings Logo DraftKings

Senior Associate Delivery Manager

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
82K-102K Annually

DraftKings Logo DraftKings

Data Coordinator Associate

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
14-17 Hourly
Hybrid
3 Locations
289097 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account