Sr. IT Risk Specialist, Large Institution Supervision
Federal Reserve SystemAbout the role
Company
Federal Reserve Bank of San FranciscoWe are the Federal Reserve Bank of San Francisco—public servants with a mission to advance the nation’s monetary, financial, and payment systems to build a stronger economy for all Americans. We are a community-engaged bank, and are committed to understanding and serving the vibrant, expansive communities of the Twelfth District. That means we seek and appreciate new perspectives. We respect people for what they do and for who they are. We build opportunities to learn and grow. When you join the SF Fed, you become part of a diverse team united in its purpose to promote an economy that works for everyone. We empower our people to balance their life and work responsibilities. That’s why we offer a flexible hybrid work model that allows you to collaborate with office colleagues on some days, and work from home on others.Are you passionate about large bank supervision and being a part of a dynamic team? The Information Technology (IT) Team within the Risk, Policy and Analysis Group’s Risk Specialist Team is looking for individuals with a passion for technology risk to join our team in the role of Sr. IT Risk Specialist, Large Institution Supervision. In this role, you will provide subject matter expertise in IT-related areas to the San Francisco Reserve Bank’s Large Institution Supervision Group (LISG). LISG is responsible for monitoring and assessing the safety and soundness of large banking institutions, U.S. operations of foreign banking organizations, and significant bank service providers in the District. You will closely interact with numerous individuals throughout the supervisory community and executive management of supervised firms.
Your focus includes leading assessments and examinations over a spectrum of IT and broader aspects of risks from the use, ownership, operation, connectivity, and impact of technology (e.g., cybersecurity, business resiliency, vendor risk management, financial technology and innovation) to determine the effectiveness of a firm’s business technology risk management program and validate remediation efforts of identified issues.
Essential Responsibilities:
- Lead or participate in horizontal and firm-specific examinations, providing written conclusions and findings for inclusion in supervisory reports.
- Work across portfolios (LIS, RBO, high risk CBO and Service Providers).
- Develop and maintain expertise in cybersecurity/information security, cloud computing, IT operations, IT risk management, and IT internal audit, as well as supervisory expectations and industry practices in those areas.
- Synthesize information from multiple sources to identify industry trends and emerging issues. Identify the implications of these trends, both at the micro and systematic levels and propose approaches to identified issues.
- Develop an understanding of supervisory rating systems applied to large banks (LFI ratings) and service providers (URSIT ratings). Understand the FFIEC framework for supervising service providers and related supervisory expectations contained in the FFIEC IT handbook.
- Assist in the development of firm risk assessments and supervisory strategies, and the vetting of exam scopes and findings. Provide briefings to senior FRS staff and others in the supervisory community.
- Develop comprehensive, creative, and agile approaches to evaluating risks and operational resiliency. Analyze information security and risk management programs to determine an estimated risk and potential impact to the financial institutions and financial services industry.
- Prepare informative, well-supported supervisory products and work papers, effectively communicating complex and problematic supervisory findings, including required actions to senior management and boards of directors. Prepare and deliver written analyses and presentations on firm-specific as well as broader industry trends or emerging risks.
- Provide coaching, training, and mentoring of less experienced colleagues.
Requirements:
- Bachelor’s degree in business, technology, or related fields of study. Advanced degrees or professional certifications with an emphasis on internal audit or information security (e.g., CRISC, CISM, CISA, CISSP, CIA) or examiner commission are desired.
- Typically requires seven or more years of direct or comparable banking, financial industry or banking supervision experience with bank examinations, internal audit, or in conducting control assessments at a banking organization or consulting firm is desired.
- Advanced knowledge of common frameworks such as FFIEC, NIST, FSSCC and ISO desired.
- Knowledge of, ability to evaluate, and/or willingness to learn, cybersecurity/information security and technology risks facing complex financial institutions and prudent practices for managin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s