Jobs and Careers
CA

VP, IT Risk Management Governance & Policy

CardWorks, Inc.
Pittsburgh, United Statesfull_timeVerifiedPosted 21 Jan 2026

About the role

Join our team - and take the next step in achieving a fulfilling career!

What We Do

At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most.

Who We Are

CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC.

CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans.  We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.

Merrick Bank is an FDIC-insured Utah Industrial Loan BankMerrick operates three main business lines:  credit cards, recreational lending, and merchant services.

Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.

Position Summary:

The Vice President, IT Risk – Governance & Policy is responsible for developing, implementing, and maturing the Technology Risk Management Framework in alignment with enterprise risk strategy, regulatory expectations, and industry best practices. This role leads governance, policy, and reporting efforts across technology risk domains, providing clear, actionable, and risk-based insights to leadership and the Board. The VP serves as a key partner to Enterprise Risk Management, Audit, and Technology leaders to ensure effective oversight of technology risk.

Essential Functions:

 

Technology Risk Framework & Governance

  • Develop, implement, and maintain the Technology Risk Management Framework aligned with enterprise risk strategy, regulatory expectations, and industry frameworks (e.g., NIST, ISO, COBIT)

  • Establish governance structures, processes, and routines to ensure consistent identification, assessment, monitoring, and escalation of technology risks

  • Ensure alignment between technology risk governance and enterprise risk management programs

Board & Executive Reporting

  • Support Board and executive reporting by delivering clear, concise, and risk-based insights and recommendations

  • Prepare quarterly, monthly and as needed technology risk reports for senior management and Board committees

  • Translate complex technical and regulatory risk topics into business-relevant narratives for appropriate audiences

Policy & Standards Ownership

  • Contribute to IT risk-related policies and standards, including but not limited to Security Policy and supporting standards

  • Ensure policies align with internal control frameworks and applicable regulatory requirements (e.g., FDIC, SOC, SOX)

  • Manage policy review cycles, updates, and approvals according to a defined governance schedule

  • Drive consistent interpretation of technology policies across technology teams

Risk Metrics, KRIs & Dashboards

  • Develop and maintain key risk indicators (KRIs), metrics, and dashboards across technology risk domains

  • Leverage metrics, incident data, and control performance to identify risk trends and emerging threats

  • Continuously enhance risk metrics to improve transparency and decision-making

Regulatory & Risk Awareness

  • Stay current on applicable regulations, supervisory guidance, and industry standards (e.g., FDIC, SOX, NIST)

  • Assess regulatory changes for impact to technology risk governance, policies, and reporting

  • Partner with Technology, Audit, and Risk teams to ensure readiness for exams, audits, and reviews

 

 

Education and Experience:

  • Bachelor’s degree required; advanced degree or certifications (CISA, CISSP, CRISC, etc.) preferred

 

Summary of Qualifications:

Required

  • 12+ years of experience in Technology, Technology Risk, IT Risk Management, Audit, or Regulatory

  • Proven experience

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CardWorks, Inc.

View company profile →