Jobs and Careers
US

IT/IS Risk Management Principal

USAA
United Statesfull_timeVerifiedPosted 6 Oct 2025
💰 $314,960/yr($164,780/yr$314,960/yr)

About the role

Why USAA?

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.

Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.

The Opportunity

We are seeking an IT/IS Risk Management Principal to provide second line of defense oversight for USAA's Information Technology/Information Security functions. This individual contributor role involves developing and performing a comprehensive risk management plan, emphasizing a strong background in solutions using AI. The ideal candidate includes over 10 years of information security experience, with expertise in Identity and Access Management. Validated presentation skills for engaging diverse partners, including executive audiences. Experience as an IT/IS risk consultant within the financial industry

We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: Charlotte, NC, San Antonio, TX, Plano, TX, Tampa, FL.

Relocation assistance is not available for this position.

What you'll do:

  • Establishes and maintains an Enterprise IT/IS risk governance framework that supports enterprise-wide standard operating policies and procedures that are aligned with the USAA Board’s risk appetite, the company’s business and strategic objectives, and regulatory expectations.
  • Reviews and evaluates the Third-Party Risk Management Program and incorporates the applicable requirements into the Enterprise IT Risk Governance Program.
  • Accountable for assessing business unit level IT/IS policies, standards and procedures developed and implemented by the business divisions to ensure they are in alignment with and support the Enterprise IT/IS policies, standards and procedures.
  • Evaluates and challenges the completeness and accuracy of the 1st LOD’s enterprise-wide IT/IS process risk and control inventory; conducts validation testing and reviews to ensure the recommended corrective actions to 1st and 2nd LOD identified IT/IS issues are complete, balanced and effective.
  • Continually evaluates information technology, information security and data risk developments, strategic and operating plans, stress points and changes in operating processes to identify potential risks which may impact the IT/IS operating and control environment.
  • Reviews and monitors identified material IT/IS internal and external risks and emerging potential threats and ensures risk mitigation action is taken
  • Assesses the enterprise information technology systems and information security protocols to ensure they are secure to support the businesses’ processing environment and are adequately controlled to appropriately mitigate IT/IS risks.

What you have:

  • Bachelor’s degree OR 4 additional years of related experience beyond the minimum required may be substituted in lieu of a degree.
  • 10 years of Information Technology / Information Security (IT/IS) experience, in a relevant industry or operational area, to include banking, insurance, financial services, project management, auditing / public accounting / consulting, and/or military service to include 6 years of specific risk management experience.
  • Experience in applying IT/IS risk frameworks such as risk governance, control efficiency measurement, process, risk and control analysis, and risk management coverage plan (monitoring, assessment and testing).
  • In-depth knowledge of cyber security, information security, fraud risk management, data risk management, customer authentication and identification access processes and controls.
  • Communicate and influence across all Lines of Defense.
  • Knowledge of federal regulation 12 CFR Part 30, including Appendices A, B and D and with federal supervisory guidance, to include:
    • OCC Documents: Large Bank Supervision Handbook; OCC Safety and Soundness Handbooks - Internal Control, and Retail Lending; and with key OCC bulletins to include: Third Party Risk Management; Technology Risk Management; and Operational Risk
    • Federal Reserve Documents: Consolidated Supervision Framework for Large Financial Institutions; Federal Reserve Board Bank Holding Company Supervision Manual
    • FFIEC Manuals and Handbooks to include: Banking; Information Technology Examination
  • General understanding of federal laws, rules, and regulations, to include:
    • CRA; ECOA; FCRA; MLA; SCRA; Regulation DD; Regulation E; Regulation Z; BSA/AML and UDAP/UDAAP
    • <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

USAA

View company profile →