Talent.com
Old National Bancorp
IT Risk Officer, SrOld National Bancorp • Lake Elmo, MN, United States
IT Risk Officer, Sr

IT Risk Officer, Sr

Old National Bancorp • Lake Elmo, MN, United States
9 days ago
Salary
$98,400.00 yearly
Job type
  • Full-time
Job description

IT Risk Officer, Sr Cybersecurity

Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving.

We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance. 401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization. We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.

Position Summary

The IT Risk Officer, Sr Cybersecurity serves as the primary first-line risk professional for Old National Bank's cybersecurity and information security operational domains. This senior-level role is the IT Risk Office's subject matter expert and 1LOD owner for five (5) Tier 1 Assessable Units encompassing Security Operations, Identity and Access Management, Data Protection, Vulnerability Management, and Threat Intelligence. The role is a direct response to the bank's recent organizational change moving the Information Security and Cyber Security Operations function into the IT organization, creating an immediate requirement for dedicated first-line risk coverage across these domains.

This role operates at the intersection of technical security operations and enterprise risk governance. The IT Risk Officer, Sr Cybersecurity must be equally fluent in the language of security practitioners and the language of risk committees, translating technical control performance into risk-rated assessments that drive leadership decisions. The position works daily with the CISO organization, Security Operations Center, Identity and Access Management team, and Data Protection engineering functions while simultaneously managing relationships with Internal Audit, Enterprise Risk Management, and regulatory examiners. In addition to leading day-to-day risk oversight, this role serves as a strategic partner to the CISO, collaborating to define, evolve, and execute the enterprise cybersecurity risk strategy ensuring the bank's security posture is proactively aligned to its risk appetite, business objectives, and evolving threat landscape.

The urgency of this hire reflects the current risk landscape. The IT Risk Officer, Sr Cybersecurity will serve as the linchpin of the bank's ability to demonstrate credible first-line oversight to its regulators, auditors, and board.

Salary Range: $98,400/yr - $199,000/yr plus bonus. The base salary indicated for this position reflects the compensation range applicable to all levels of the role across the United States. Actual salary offers within this range may vary based on a number of factors, including the specific responsibilities of the position, the candidate's relevant skills and professional experience, educational qualifications, and geographic location.

Key Accountabilities:

  • Cybersecurity Risk Strategy & CISO Partnership: Partner directly with the CISO to shape and refine the enterprise cybersecurity risk strategy, ensuring alignment between first-line risk oversight priorities and the security program roadmap. Translate risk assessment findings, threat intelligence, and regulatory expectations into strategic recommendations that inform investment decisions, capability prioritization, and program maturity targets. Provide the CISO with a risk-informed perspective on emerging initiatives (e.g., cloud migration, AI adoption, M&A integration) to enable proactive risk positioning rather than reactive remediation. Co-develop the multi-year cybersecurity risk appetite framework, including thresholds, escalation triggers, and board-reportable risk narratives. Represent the IT Risk Office in cybersecurity strategy forums and steering committees, ensuring risk considerations are embedded in strategic decision-making at the earliest stages.
  • Cybersecurity Risk Assessment & RCSA Execution: Lead comprehensive Risk and Control Self-Assessments (RCSAs) for all five assigned cybersecurity AUs. Conduct targeted risk assessments of security operations, identity governance, data protection, and vulnerability management programs as needed. Evaluate control design and operating effectiveness across the cybersecurity control environment, with particular focus on PCI DSS compliance requirements, IAM access governance, and NIST CSF alignment. Identify control gaps and risk exposures, document findings, and develop risk-rated remediation recommendations in collaboration with domain owners.
  • Issue Management & Remediation Oversight: Take oversight ownership of the open cybersecurity-related issues in the eGRC system. Establish structured remediation tracking, prioritization criteria, and escalation pathways for High and Moderate risk items. Partner with Security Operations, IAM, and Vulnerability Management teams to drive remediation velocity against SLA expectations. Manage OCC regulatory recommendations in cybersecurity domains through completion, ensuring documentation of evidence sufficient for examiner validation. Support PCI remediation program oversight, coordinating across network segmentation, access control, encryption, and monitoring workstreams.
  • Regulatory & Audit Engagement: Serve as the IT Risk Office's primary point of contact for all cybersecurity-related regulatory examinations, audit engagements, and second-line assessments. Support OCC and FFIEC examinations by providing control evidence, facilitating documentation requests, and preparing IT leadership for examiner discussions. Maintain awareness of emerging regulatory guidance on cybersecurity, AI risk, and third-party technology risk from OCC, FFIEC, and NIST. Translate examination findings into structured remediation plans with clear ownership and milestone tracking.
  • Risk Governance, Monitoring & Reporting: Develop, maintain, and report on cybersecurity-domain Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) that provide meaningful visibility into the health of the cybersecurity control environment. Contribute domain-specific content to executive and board-level risk reporting, the quarterly ISTRM Risk Profile report, and risk appetite monitoring. Monitor the bank's NIST CSF 2.0 maturity profile across Identify, Protect, Detect, Respond, and Recover domains, tracking progress toward target maturity. Provide credible challenge to cybersecurity program metrics and escalate emerging risk themes.
  • Emerging Technology Risk & Threat Intelligence Integration: Monitor the evolving cybersecurity threat landscape, with particular focus on AI-accelerated attack vectors, adversarial use of generative AI, and the quantum computing cryptographic migration timeline. Partner with Threat Management team to ensure threat intelligence findings are translated into actionable risk management activities. Assess the cyber risk implications of the bank's AWS cloud migration, including cloud-native security controls, identity federation, and cloud configuration governance.
  • Team Leadership & Talent Development: Provide day-to-day direction, coaching, and development for two direct reports: a Cybersecurity Risk Analyst and a Vulnerability Management Risk Lead. Define workload allocation, analytical standards, and quality expectations for the sub-team. Mentor team members in risk assessment methodology, regulatory awareness, and professional development. Model the IT Risk Office's culture of rigor, proactivity, and collaborative partnership with business and technology stakeholders.

Key Competencies for Position:

  • Technical Credibility & Risk Judgment Brings genuine cybersecurity depth; can assess control design and effectiveness, not just document process narratives
  • Regulatory Fluency Understands what examiners look for and can prepare the organization accordingly; has sat in exam rooms and knows how to navigate them
  • Influence Without Authority Drives remediation velocity through partnership with security teams who do not report to this role
  • Precision & Thoroughness Produces documentation, evidence packages, and risk assessments that withstand examiner scrutiny
  • Strategic Awareness Understands how the cybersecurity risk profile connects to the bank's strategic objectives and communicates accordingly
  • Team Leadership Develops analysts and junior professionals; models the professional standards expected of the IT Risk Office

Qualifications and Education Requirements:

  • Experience: Minimum 68 years in cybersecurity, IT risk management, or information security governance, with at least 3 years in a financial services environment. Demonstrated experience managing cybersecurity risk assessments, audit engagements, and regulatory examinations. Prior exposure to IAM program governance, PCI DSS compliance, and vulnerability management oversight strongly preferred.
  • Frameworks & Regulations: Deep understanding of NIST CSF 2.0; FFIEC Cybersecurity Assessment Tool; PCI DSS v4.0; CIS Critical Security Controls; and OCC Heightened Standards as they apply to information security. Familiarity with GLBA Safeguards Rule and emerging AI risk frameworks.
  • Technical Proficiency: Fluency with GRC platforms (Archer, ServiceNow IRM, or equivalent); SIEM tooling (Splunk, Microsoft Sentinel); IAM platforms (SailPoint ISC, Entra/Active Directory); cloud security frameworks (AWS Security Hub, AWS Config, CIS AWS Benchmark); and vulnerability management tools (Tenable, Qualys, or equivalent). Understanding of DLP, encryption standards, and network segmentation principles.
  • Analytical & Problem-Solving Skills: Ability to assess complex cybersecurity environments, quantify risk exposure, and prioritize remediation efforts based on business impact, regulatory urgency, and exploitability. Experience developing KRI frameworks and dashboard reporting from operational security data. Comfort working with large issue datasets and translating findings into executive-ready
Create a job alert for this search

IT Risk Officer, Sr • Lake Elmo, MN, United States

Similar jobs

IT Risk Officer, Sr

Old National BancorpLake Elmo, MN, United States
Full-time

IT Risk Officer, Sr Cybersecurity.Old National Bank has been serving clients and communities since 1834.With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the com... Show more

 • Promoted

Chief Operating Officer

Minnwest BankSaint Paul, MN, United States
Full-time

Minnwest Leadership Opportunity.Minnwest is a family owned, community bank based in Minnesota and South Dakota.We believe our success is measured by the extent in which we have a positive impact on... Show more

 • Promoted

Third Party Risk Management Director (Hybrid)

Securian FinancialSaint Paul, MN, United States
Full-time

Risk Management Consulting Director.The Third Party Risk Management (TPRM) Director is accountable for leading and transforming the enterprise TPRM program to effectively manage risk across the ful... Show more

 • Promoted

Senior IT Auditor

Ent Credit Union | WingsSaint Paul, MN, United States
Full-time

This role supports execution of the audit plan.Supports the execution of all phases of IT audits including planning, risk assessment, walkthroughs, process documentation, operating effectiveness te... Show more

 • Promoted

Account Manager - State Farm Agent Team Member

Jesse Johnson - State Farm AgentForest Lake, MN, United States
Full-time

Do You Want A Career And Not Just A Job?.This busy insurance and financial services office has a passion to make a difference in the lives of others and better the community.We are an established, ... Show more

 • Promoted

Corporate Safety Director

The Contingent PlanSaint Paul, MN, United States
Full-time

The Contingent Plan is actively recruiting a corporate EHS director for its client headquartered in the Twin Cities.This is a hybrid role with the expectation that the person will be onsite at the ... Show more

 • Promoted

Lead Internal Auditor - TPRM

Choice BankSaint Paul, MN, United States
Full-time

Lead Internal Auditor - Third Party Risk Management (TPRM) Focus.This role will primarily support audits related to Third Party Risk Management - including Fintech focus, oversight, ongoing monitor... Show more

 • Promoted

Store Manager

O'Reilly Auto PartsCannon Falls, MN, United States
Full-time

Compensation Pay Range: $60,000.The actual hourly rate will equal or exceed the required minimum wage applicable to the job location.Additional compensation includes annual, quarterly performance,... Show more

 • Promoted

Senior GRC Risk Analyst

MISOSaint Paul, MN, United States
Full-time

Are you passionate about cybersecurity and protecting critical infrastructure? Join MISO as a Senior GRC Risk Analyst, where you will play a key role in safeguarding the power grid by identifying, ... Show more

 • Promoted

VP, Enterprise Risk

SynchronySaint Paul, MN, United States
Full-time

Vice President, Enterprise Risk.This Vice President, Enterprise Risk role is a key member of the Enterprise Risk Management (ERM) team.Primary responsibilities include managing execution of the ent... Show more

 • Promoted

Client Experience Associate SAFE ACT, Assistant Vice President

Citigroup Inc.Washington, MN, United States
Full-time

This is a seasoned professional role responsible for applying in-depth disciplinary knowledge to improve processes and workflows within the Banking, Credit and Investments platform.They ensure a se... Show more

 • Promoted

Shift Supervisor

CVS HealthHastings, MN, United States
Full-time +1

We're building a world of health around every individual shaping a more connected, convenient and compassionate health experience.At CVS Health, you'll be surrounded by passionate colleagues who c... Show more

 • Promoted

System Director SOC (Staffing and Scheduling)

FairviewSaint Paul, MN, United States
Full-time

System Director, Soc Staffing & Scheduling.The System Director, SOC Staffing & Scheduling provides system-level leadership for the design, optimization, and execution of staffing and scheduling ope... Show more

 • Promoted

Risk Analyst (Subcontractor Prequalification)

Bituminous Roadways IncSaint Paul, MN, United States
Full-time

Risk Analyst (Subcontractor Prequalification).McGough is a respected partner that brings six generations of experience to high profile, unique and complex construction projects.We take great pride ... Show more

 • Promoted

Senior Manager, IT Risk & Compliance

Patterson CompaniesSaint Paul, MN, United States
Full-time

Senior Manager, It Risk & Compliance.Patterson isn't just a place to work, it's a partner that cares about your success.One of the distinguishing marks of our company is the talented people who emb... Show more

 • Promoted

Information Technology Professional

US NavyLindstrom, MN, US
Full-time

Information Technology Professional (IT/CTN/IS).Information Systems Technicians, Cryptologic Technician Networks, and Intelligence Specialists keep the Fleet connected, informed, and secure by oper... Show more

 • Promoted

Sr. Director, Sales - Risk & Fraud

Thomson ReutersSaint Paul, MN, United States
Full-time

Director, Sales - Government Risk & Fraud.Director, Sales- Government Risk & Fraud you will be responsible for leading the Thomson Reuters, Government Risk & Fraud overall sales and retention strat... Show more

 • Promoted

Shift Manager

Arby'sLindstrom, MN, US
Part-time

You may know us as the brand with Roast Beef and Curly Fries but we are also crafting incredible career opportunities.Youre in the right place if youre here for.Shift Meal Discount and Family Dini... Show more

 • Promoted

Infrastructure IT Relationship Manager

OsaicSaint Paul, MN, United States
Full-time

Information Technology Opportunity in Financial Services.Infrastructure IT Relationship Manager.Atlanta: 2300 Windy Ridge Pkwy SE, Suite 750, Atlanta, GA 30339.La Vista: 12325 Port Grace Blvd, La V... Show more

 • Promoted

Lead Internal Auditor - BSA/AML Focus

Choice BankSaint Paul, MN, United States
Full-time

Lead Internal Auditor BSA/AML Focus.This role will primarily support audits related to Bank Secrecy Act (BSA), Anti-Money Laundering (AML), financial crimes compliance, and associated risk managem... Show more