Senior IT Risk Manager, Operational Risk Management
Voya FinancialAbout the role
Together we fight for everyone’s opportunity for a better financial future.
We will do this together — with customers, partners and colleagues. We will fight for others, not against: We will stand up for and champion everyone’s access to opportunities. The status quo is not good enough … we believe every individual and every community deserves access to financial opportunities. We are determined to support both individuals and communities in reaching a better financial future. We know that reaching this future depends on our actions today.
Like our Purpose Statement, Voya believes in being bold and committed to action. We are committed to a work environment where the differences that we are born with — and those we acquire throughout our lives — are understood, valued and intentionally pursued. We believe that our employees own our culture and have a responsibility to foster an environment where we all feel comfortable bringing our whole selves to work. Purposefully bringing our differences together to positively influence our culture, serve our clients and enrich our communities is essential to our vision.
Are you ready to join a company with a strong purpose and a winning culture? Start your Voyage – Apply Now
Profile Summary:
The Senior IT Risk Manager reports to the Head of IT Risk Management (ITRM) within Voya's enterprise Operational Risk Management function. This ITRM function provides risk oversight for Voya’s enterprise Information Technology (IT) function and technologies supporting Voya's Investment Management, Retirement Benefits, and Employee Benefits businesses by facilitating processes to identify, monitor, and mitigate IT related operational risks, and by providing senior leadership with timely and accurate information to assist in risk-based decision making.
Profile Description:
The mission of the Operational Risk Management (ORM) function is to support Voya leadership in risk-based decision making and to assist with the management of operational risks of the enterprise, through the application of a comprehensive framework, processes, and tools for identifying, measuring, and monitoring operational risks.
We are seeking a motivated and self-driven individual that will focus on the communication, implementation, and execution of operational risk policies and procedures, in support of risk management within Voya’s enterprise IT function and Investment Management, Retirement Benefits, and Employee Benefits business technologies. The individual will employ business, IT, and operational process knowledge to perform independent review and challenge, and to advise stakeholders on solving complex and time-sensitive risk related matters. Responsibilities include, but are not limited to the following:
Regularly interact with and build partnerships with stakeholders across business and IT functions at varying levels to promote and instill a strong risk culture.
Provide subject matter expertise and advise on IT related risks and remediation/mitigation of risk exposures. Real-time risk advisory and risk measurement are key elements of this role.
Assist in defining IT risk and control standards and maintaining the standards framework.
Lead IT risk identification and assessment activities that include IT process reviews, top-down risk assessments, targeted risk and control assessments, development of key risk indicators (KRI), risk event management, trend analysis, and controls compliance.
Monitor the IT risk and control environment including root cause analysis of issues and incidents to identify process improvement, control optimization, and risk reduction opportunities.
Develop Board and senior leadership risk reporting and risk committee materials.
Assist with assessments concerning compliance with applicable laws and regulations impacting IT.
Work closely with line of business ORM teams to characterize potential IT risks and trends, assessing business impact and articulating criticality and implications to business stakeholders.
Assist with ongoing development and maintenance of IT Risk Management strategy and framework, and education of stakeholders.
Knowledge & Experience:
Bachelor’s degree in Computer Science, MIS or related field; or equivalent work experience. Master’s degree desirable.
Minimum 8-15 years of relevant experience with a strong background in IT, IT audit, and/or IT risk management and including minimum 4 years of f
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s