Jobs and Careers
TI

Sr. Associate, 2LoD Technology Risk

TIAA
United Statesfull_timeVerifiedPosted 10 Feb 2025
💰 $120,000/yr($95,000/yr$120,000/yr)

About the role

Sr. Associate, Technology Risk (2LoD)

The Sr. Associate Technology Risk is responsible for the 2LoD challenge & oversight for the implementation and support of enterprise risk management programs for the Retirement, Marketing, and Digital Client Technology (RMDCT) organization, as well as the monitoring, escalation, reporting, and influencing prioritization of significant risks and control weaknesses. The RMDCT organization works closely with business teams to build and execute a comprehensive technology roadmap for their businesses, bolstering the core functions, platforms, products and digital capabilities while delivering efficiencies.


Key Responsibilities and Duties

The specialist in technology risk is the primary 2LoD interaction point with the RMDCT organization, and the key responsibilities and duties of this role include:

  • Strategic Initiatives – partner with 2LoD business-aligned risk & compliance partners to provide engagement, counsel, advice, and challenge on key strategic initiatives to ensure risks and regulatory aspects are appropriately considered and addressed.
  • 2LoD Targeted Risk Assessments – support the execution of 2LoD independent targeted risk assessments to confirm control effectiveness and identify opportunities to strengthen controls to enhance confidentiality, integrity, and availability.
  • Issue & Incident Management – responsible for supporting these enterprise programs and providing appropriate governance and challenge to ensure the execution of program requirements and mitigation of risk; provide 2LoD challenge for (1) risk-accepted issues, issue rating criticality, and linkage to the RCSA program; (2) ensure action plans adequately address the identified control gaps; (3) review and track the root causes for major technology incidents to identify and highlight potential thematic concerns.
  • Relationship Management – build and maintain effective relationships with key 1LoD leaders (L5/L6) via recurring, periodic 1:1s, and ad-hoc touchpoints to share information and position oneself as a trusted advisor.
  • Policy & Standards – provide 2LoD support and challenge for IT’s documented Information Technology Policy and IT Standards, including ensuring associated controls and implementation timelines meet regulatory requirements, and gathering feedback and evaluation of proposed changes and timelines that will directly impact technology teams.
  • Risk and Control Self-Assessment (RCSA) – support and challenge the implementation and maturation of the RCSA program and related processes; (1) effectively coordinate with 1LoD risk & control partners to ensure that the implementation of the RCSA program includes the appropriate identification of technology risks and control weaknesses; (2) work in collaboration with business-aligned control teams to ensure RCSAs provide a full view of the technology control environment that the businesses are reliant upon to support their critical business functions.
  • Risk Management Committees – provide support to management in delivering periodic risk and compliance reporting.
  • Risk Appetite & Thresholds – support the maintenance, performance monitoring, and periodic updates to Enterprise & LoB risk appetite statements and breach thresholds based on direction and feedback from the CRO Teams and business leaders.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 3+ Years Required; 5+ Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work


Career Level
7IC

Required Skills

  • 3 years of experience in IT/Technology Risk Management, IT/Technology Compliance, IT/Technology Audit, or Information Technology.

Preferred Skills

  • Bachelor’s Degree.
  • 5+ years of working experience in IT/Technology Risk Management, IT/Technology Compliance, IT/Technology Audit, or Information Technology.
  • Experience independently evaluating/performing risk and control assessments and/or audits across various technology areas/domains.
  • Knowledge of software development lifecycles and methodologies (e.g., SAFe Agile, DevOps, domain-driven design), as well as change management processes.
  • Familiarity with financial services technology-related laws/regulations/control frameworks, and experience with evaluating impacts on technology risks, controls, policies, and standards.
  • Professional Certifications: CISA, CISSP, CRISC, and/or CISM.

Related Skills

Adaptability, Business Acumen, Compliance, Consultative Communication, Critical Thinking, General Risk Management, Organizational Savviness, Problem Solvi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

TIAA

View company profile →