Sr. Operational Risk Officer - Technology/Cybersecurity
KeyBankAbout the role
Location:
4910 Tiedeman Road - Brooklyn, Ohio 44144Job Summary
Reporting to the Director, Technology Risk Oversight, this 2nd Line of Defense role will be part of the team supporting various support functions within Key Technology and Operations (KTOS) including Intelligent Automation, Contact Center and Investment Operations, Enterprise Technology Services and Enterprise Application Delivery and Support.
This role will be responsible for performing appropriate oversight to drive assurance that Key remains compliant with all applicable Technology Risk practices. As part of this oversight role, experience with technology delivery, application development, technology operations, enterprise architecture, technology governance, information security, and the ability to leverage that experience to identify material risks, provide credible challenge and assist in developing effective mitigation strategies.
Responsibilities
- Collaborate with leaders to gain insights on operational performance, emerging risks and strategic initiatives while identifying opportunities for improvement.
- Evaluate and monitor projects, strategic initiatives, and new technologies to ensure alignment with risk tolerance and business goals.
- Review risks, controls and, conduct assessments to support effective oversight and compliance with risk management requirements.
- Oversee the technology portfolio, assessing projects and initiatives to ensure alignment with risk appetite and adequate mitigation strategies.
- Support and enhance the overall risk oversight framework by developing and updating oversight practices.
- Partner with various teams to influence the implementation of operational practices to mitigate risk within appetite.
- Provide expert advice on risk management practices, offering practical solutions to mitigate identified risks.
- Analyze and assess risks associated with new products or services including third parties.
- Assist with audits and regulatory examinations, ensuring through and timely responses to inquiries and findings.
- Foster positive relationships with business partners and senior management ensuring open communication on risk matters.
- Escalate and report any significant risk issues and facilitate appropriate corrective actions.
- Perform ongoing monitoring of emerging risks, industry and regulatory trends.
Education Qualifications
- Bachelor's Degree (Or equivalent experience may be considered) (required)
- Minimum of 8-10 years industry experience, within Operational Risk, Enterprise Risk, Technology Risk, Information Security Risk, External/Internal Audit or in the technology or information security lines of business.
- Obtained at a minimum one of the following certifications:
- ISACA: CISA, CRISC, CET, CGEIT, CISM
- ISC2: CISSP, CCSP, SSCP
- Cloud Security Alliance Certs: CCAK
- Cloud Provider-Specific Certifications
- Outstanding active listening skills
- Demonstrated ability to work with internal and external auditors and regulators.
- Ability to think strategically coupled with the ability to drive to execution
- Ability to view risk holistically within a dynamic, fast paced team environment
- In-depth practical knowledge of internal controls, risk assessments and operational and compliance processes, and applicable techniques for implementation of compliance and legal requirements and operational processes.
- Familiarity with Microsoft Office tools such as Excel, Teams, and the proven ability to learn how to use other unique technologies.
- Capable of conducting in depth testing of systems, processes and controls
- Manage workflows and task assignment to ensure timely completion of work
- Have an execution oriented, process efficiency and continuous improvement mindset
- Possessing intellectual curiosity and a passion for seeking to understand
- Proven ability to have, maintain, and establish strong contacts within the industry so as to be aware of current industry issues and practices
Preferred Qualifications
- MBA, or other relevant advanced education in business, finance, technology, or economics
- Experience working in the financial services industry and or a second line oversight function for a financial institution
- Current and practical knowledge of Technology and/or Information Security activities, challenges, and workflows
- Additional industry certifications such as those listed above
- Foundational knowledge of Archer GRC preferred
- Project management, Agile experience preferred
Experience Qualifications
- 8+ years Experience in technology and information security (required)
- 5+ years Operati
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s