Senior Technology Risk Officer Resiliency
Leader within the Truist second-line-of-defense (LOD2) Technology Risk team responsible for independent risk oversight of technology resiliency. As a valuable teammate you will develop a trusted advisor relationship with technology leaders in assigned oversight areas, provide credible challenge focused on technology resiliency, perform risk identification and mitigation strategy development, partner with other internal teams to assess and mitigate technology risk and manage teammates to execute on technology risk oversight activities and grow their professional skillsets.
The Senior Technology Risk Officer Resiliency position is a senior risk leader role responsible for independently assessing and challenging the effectiveness of the firm's technology and cyber resilience programs. The successful candidate will leverage deep technical expertise and strong analytical skills to ensure critical business operations can withstand, adapt to, and recover from severe disruptions, such as cyberattacks, system failures, or natural disasters. This position focuses on all aspects of technology resiliency including, business continuity, disaster recovery and effective testing and measurement to appropriately manage the risk of resiliency at Truist. This role provides guidance and expert challenge to technology teams and executive leadership to ensure alignment with the firm's risk appetite and regulatory requirements.
Following is a summary of the essential functions for this job :
- Technology Risk Leadership - Provide independent risk oversight (i.e. second line of defense / LOD2) enterprise-wide for Enterprise Control Functions through the effective identification, mitigation, monitoring and reporting of operational, technology, compliance and strategic risks within the ECFs;
- Strategic Alignment- Provide strategic risk advisory to ECF leads, i.e. the Chief Information Security Officer, the Chief Data Officer, the Chief Technology Officer, etc that supports the Truist organization's strategies and objectives while operating within established risk appetites. Provide effective challenge of the ECF Strategy for Truist;
- Industry engagement- lead engagement of peer institution second line functions to influence the industry build of the tech risk functions;
- Targeted control testing- lead execution of independent second line testing / evaluations (e.g. Red Team / Penetration Testing); work is typically commissioned by the Board, the CEO and / or the CRO;
- Value Delivery Ensure that resources, activities and initiatives are aligned to enable and sustain achievement of business objectives within forecasted spend rates while reducing risks;
- Provide independent assessment and oversight of the maturity of technology risk domains (e.g. Cyber, Service Delivery and Operations, Data Management, etc) and adequacy of controls pertaining to domains in meeting agreed to business outcomes for performance, stability, security and service availability. Assessments should leverage agreed upon metrics produced by Business Unit Risk Management (BURM) / first line of defense LOD1) but challenged and validated as appropriate;
- Independent Challenge of LOD1 assessments - Review and attest to / challenge adequacy of risk assessments (i.e. Risk & Control Self-Assessments, Application Assessments, Change Risk Assessments) produced by BURM;
- Committee Engagement Serve as member of the Technology Risk Committee and participate in the Enterprise and Board Risk Committees and the Board Technology Committee, when applicable for Technology Risk related topics;
- Regulatory Engagement Oversight - Ensure effectiveness and structure in regulatory engagement practices, including responses out of the impacted ECF group;
- Training and Communication - Encourage and monitor risk education, skills training and adoption of goals to drive improved risk culture and awareness across the enterprise;
- Policy & Standard Leadership Engage on ECF Risk policy governance, as well as, policies, standards, procedures owned by areas of