Talent.com
Information Technology (IT) Risk Management, Dir.
Information Technology (IT) Risk Management, Dir.Federal Home Loan Bank of San Francisco • San Francisco, CA, United States
No longer accepting applications
Information Technology (IT) Risk Management, Dir.

Information Technology (IT) Risk Management, Dir.

Federal Home Loan Bank of San Francisco • San Francisco, CA, United States
1 day ago
Job type
  • Full-time
Job description

Job Description : Background :

The Federal Home Loan Bank of San Francisco ("Bank") is a cooperative, wholesale bank that provides liquidity to its members and helps meet community credit needs through credit products and services to member financial institutions over all phases of the economic cycle. The Bank's members include commercial banks, credit unions, industrial loan companies, savings institutions, insurance companies, and community development financial institutions headquartered in Arizona, California, and Nevada. The Bank is member focused; embraces accountability to meet commitments and uphold our governance, risk and control standards as a government sponsored enterprise; and values differences to foster an inclusive culture.

The role of the Director, IT Risk Management (ITRM) within the Enterprise Risk Management (ERM) is to support the Bank in continuing to mature and execute the Bank's IT Risk Management practices. Our goal is to provide an enterprise-wide risk framework and centralized oversight and governance for IT and Information Security (IS) activities, and to drive greater transparency and inform risk-based decision-making across the Bank. Additionally, the role will be responsible for executing the risk-based IT and IS assessment activities for the in-scope Business Units (BU), processes, and technologies / tools.

Success in this role entails working closely with the Risk, IT, and IS teams to socialize risk concepts and frameworks, and promote the organizations' risk culture. Additionally, this role must have the ability to adapt previous experience and industry leading practices to fit the Bank. The position also partners with functional and operational leadership in the development of risk mitigation plans, consistent with the Bank's ERM framework. The role will be an integral part of a risk management team that encourages creativity, leadership, and influence.

Primary Responsibilities :

Under the direction of the Senior Director, IT and EUC Risk Management, the essential responsibilities for this role will be the following :

  • Help mature and execute an IT and IS risk management framework using industry leading practices (e.g., NIST CSF, COBIT, and Cloud Security Alliance) and take into consideration regulatory expectations.
  • Review processes and controls against leading practices, industry frameworks, and regulations, identify gaps in design and execution, communicate issues and recommendations, and monitor remediation efforts.
  • Drive common Process, Risk, and Control taxonomies for the Bank, including IT and IS, to improve operational efficiency.
  • Leverage the Bank's ERM, ORM / ITRM frameworks and partner with IT and IS teams to execute IT and IS risk assessments - including Inherent Risk Assessments (IRA), Operational Risk Assessments (ORA), FedLine Advantage Assessment, AWS assessment, and other in-depth technology and process assessments - identify gaps, document action plans, and perform validation as appropriate.
  • Assist in Operational integrated risk assessments by leading the technology aspects of the IRAs and ORAs for the in-scope BUs.
  • Partner with the ERM / ORM teams and lead the effort to review and refresh ORM / ITRM Policy and Procedures, at a minimum, on an annual basis.
  • Assist ERM leadership to update Risk Appetite Framework annually or as needed. Help define and enhance Key Risk Indicators (KRI) and their tolerances, generate or review metrics and Key Takeaways in the Enterprise Risk Report (ERR).
  • Lead the investigation and documentation of IT and IS related Operational Events. Validate remediation actions when completed.
  • Prepare and present IT Risk Management updates to Committees as appropriate
  • Assist with communication and escalation of significant IT / IS risks and issues to the appropriate management, and monitor corrective actions to address issues, where needed.

In addition, this role may be asked to complete the following tasks :

  • Assist the Enterprise Risk Officer and the Senior Director, IT and EUC Risk Management, in ERM strategy-implementation and improvement opportunities.
  • Assist in regulatory and internal audit engagements, including collection of relevant documentation requested in internal and external exams.
  • Work with the Risk Analytics team to help embed data-driven metrics and decisions within ERM.
  • Work with the IT and IS teams on technology initiatives as appropriate, e.g., Artificial Intelligence tools adoption and Cloud transformation.
  • Help assess enterprise and emerging risk issues, including assignment of risk ratings consistent with established policy standards.
  • Other tasks under the direction of ERM / ORM / ITRM leadership.
  • Critical Competencies :

  • Knowledge and working experience with ORM and ITRM Frameworks based on industry best practices and the three lines of defense model.
  • A minimum of 7 years of experience in performing IT / IS / ORM risk assessments and control testing leveraging IT / IS Frameworks and Standards (e.g., FFIEC, NIST CSF, ISO, COBIT, ITIL).
  • Knowledge of IT and IS risks associated with the System Development Lifecycle, Development. Operations, Agile Development Processes, Infrastructure, Security Operations / Engineering, etc.
  • Knowledge of and experience with IT and IS tools, e.g., SailPoint, Splunk, Tenable, and CyberArk
  • A team player who can comfortably work in a dynamic and fast-paced environment, ability to respond to changing circumstances, and ability to meet the hybrid working model requirements.
  • Ability to interact with senior management while balancing multiple projects and other responsibilities.
  • Regulatory experience with the Federal Housing Finance Agency is a plus.
  • Strong attention to detail with a proactive approach to solving and preventing problems.
  • Excellent organization, project management, and prioritization skills.
  • Excellent interpersonal skills to work in a team environment and to influence and interface with a broad range of stakeholders at all levels, internal and external.
  • Certified Information Systems Auditor (CISA), Certification in Control Self-Assessment (CCSA), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or other risk management discipline certification.
  • Ability to take ownership of projects and deliver high-quality results.
  • SALARY RANGE : $175K - $210K

    The Federal Home Loan Bank of San Francisco is committed to the principles of equal opportunity in employment (e.g., employees, applicants) and in contracting (e.g., suppliers, vendors) regardless of race, color, religion, sex, national origin, disability status, genetic information, age, sexual orientation, gender identity, status as a parent, or any other characteristic protected by law. We are committed to cultivating a workplace free of unlawful discrimination, harassment, and retaliation, and are dedicated to fostering vibrant communities by serving as a reliable source of liquidity and resources for affordable housing and economic development.

    Salary ranges reflect the base salary that the Bank reasonably expects to pay for a given role and is not inclusive of annual incentive award opportunities, retirement benefits or the value of other health and welfare or other ancillary benefits. We consider many factors when determining base salaries such as individual background and experience, the competitive environment, education, particular skill set(s), and industry and institutional knowledge.

    The Bank is committed to offering all team members challenging and engaging work with market competitive pay, retirement, and benefit offerings. In support of this commitment, the Bank routinely engages in market competitive benchmarking surveys and analysis to ensure our team members continue to be paid fairly and competitively.

    Create a job alert for this search

    Technology Management • San Francisco, CA, United States

    Related jobs
    Information Technology (IT) Risk Management, Dir.

    Information Technology (IT) Risk Management, Dir.

    Federal Home Loan Bank of San Francisco • San Francisco, CA, United States
    Full-time
    Information Technology (IT) Risk Management, Dir.Join to apply for the Information Technology (IT) Risk Management, Dir.Federal Home Loan Bank of San Francisco. The Federal Home Loan Bank of San Fra...Show more
    Last updated: 30+ days ago • Promoted
    Data Integrity Analyst

    Data Integrity Analyst

    Russell Tobin • Cupertino, CA, US
    Full-time
    Months with Possibility Extension.Quality Assurance Analyst – Data Integrity General Description : .The client is dedicated to creating the best product on the market, striving not only to exceed the...Show more
    Last updated: 19 days ago • Promoted
    Senior / Staff System Reliability and Risk Engineer

    Senior / Staff System Reliability and Risk Engineer

    Gatik AI • Mountain View, CA, United States
    Full-time
    Gatik, the leader in autonomous middle-mile logistics, is revolutionizing the B2B supply chain with its autonomous transportation-as-a-service (ATaaS) solution and prioritizing safe, consistent del...Show more
    Last updated: 1 day ago • Promoted
    Senior Application Security Engineer (Hybrid - US)

    Senior Application Security Engineer (Hybrid - US)

    Energy Solutions • Oakland, CA, United States
    Full-time
    Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Kubelt • San Francisco, CA, United States
    Full-time
    World is a network of real humans, built on privacy-preserving proof-of-human technology, and powered by a globally inclusive financial network that enables the free flow of digital assets for all....Show more
    Last updated: 30+ days ago • Promoted
    Network Security Architect

    Network Security Architect

    VirtualVocations • Concord, California, United States
    Full-time
    A company is looking for a Network Senior Lead Security Architect.Key Responsibilities Lead assessments of potential risks targeting network infrastructures and provide security requirements and ...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Compliance Lead

    Information Security Compliance Lead

    Ivo AI, Inc. • San Francisco, CA, United States
    Full-time
    Contract negotiation is the most time-consuming, costly, and difficult component of the contract lifecycle—and it hasn’t gotten much easier since the days of fax machines.Large language models have...Show more
    Last updated: 5 days ago • Promoted
    Software Engineer, Security Observability

    Software Engineer, Security Observability

    OpenAI • San Francisco, CA, United States
    Full-time
    Software Engineer, Security Observability.Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Imprint • San Francisco, CA, United States
    Full-time
    Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Rakuten, Booking.H-E-B, Fetch, and Brooks Bro...Show more
    Last updated: 6 days ago • Promoted
    InfoSec - Principal Product Security Engineer

    InfoSec - Principal Product Security Engineer

    Elastic • Mountain View, CA, United States
    Full-time
    Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale - unleashing the potential of businesses and people.The Elastic Search AI...Show more
    Last updated: 7 days ago • Promoted
    Product Security Engineer

    Product Security Engineer

    Databricks Inc. • San Francisco, CA, United States
    Full-time
    RDQ326R24 - This role can be based remotely anywhere in the United States.The Product Security Team's mission is to Left-shift SDLC (Security Development Lifecycle) processes for ALL code written i...Show more
    Last updated: 30+ days ago • Promoted
    I-9 Compliance Administrator

    I-9 Compliance Administrator

    VirtualVocations • Fremont, California, United States
    Full-time
    A company is looking for an I-9 Administrator (Remote).Key Responsibilities Work with client employees through web conferencing to ensure accurate completion of Form I-9 Verify employment eligib...Show more
    Last updated: 5 hours ago • Promoted • New!
    System Software Engineer, Integrity

    System Software Engineer, Integrity

    OpenAI • San Francisco, CA, United States
    Full-time
    System Software Engineer, Integrity.Applied AI Engineering - San Francisco.The Integrity team at OpenAI is dedicated to ensuring that our cutting‑edge technology is not only revolutionary but also ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Airwallex • San Francisco, CA, United States
    Full-time
    Airwallex is the only unified payments and financial platform for global businesses.Powered by our unique combination of proprietary infrastructure and software, we empower over 150,000 businesses ...Show more
    Last updated: 6 days ago • Promoted
    Cyber Warfare Technician

    Cyber Warfare Technician

    U.S. Navy • Sausalito, CA, US
    Full-time +1
    To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.As a Cryptologic Technician, you are one of the worlds greatest problem-solvers. Were looking for people with sha...Show more
    Last updated: 1 day ago • Promoted
    Application Security Architect

    Application Security Architect

    VirtualVocations • Concord, California, United States
    Full-time
    A company is looking for an Application Security Architect.Key Responsibilities Collaborate with development teams to implement secure coding practices and conduct application vulnerability asses...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Principal Engineer

    Application Security Principal Engineer

    VirtualVocations • Santa Clara, California, United States
    Full-time
    A company is looking for a Principal Engineer to lead the development of innovative Application Security products.Key Responsibilities : Develop and integrate code scanning and application securit...Show more
    Last updated: 23 hours ago • Promoted
    Application Security Engineer

    Application Security Engineer

    VirtualVocations • Santa Clara, California, United States
    Full-time
    A company is looking for an Application Security Engineer to join their Infrastructure & Security team.Key Responsibilities Identify and fix vulnerabilities in software through code audits and se...Show more
    Last updated: 30+ days ago • Promoted