Jobs and Careers
NA
Assistant Vice President, Risk Governance and Reporting (Patch Vulnerability & Technology Risk)
Navy Federal Credit UnionUnited Statesfull_timeVerifiedPosted 1 May 2024
About the role
The Assistant Vice President for ETS Risk Governance and Reporting is a direct report to the Vice President of Risk for Navy Federal’s Information Technology Department. The position supports the broader Enterprise Technology Services (ETS) Risk mission to effectively manage risks, compliance and facilitate informed decision making by building an agile capability responsible for risk reporting, strategy and planning, and risk culture development.
Risk Reporting and Intelligence
- Coordinate through ETS Enterprise Technology Business Services and Enterprise Risk Management (ERM) to define and develop risk reporting and metrics to include Key Risk Indicators (KRIs) for Information Technology department.
- Coordinate through ETS Enterprise Technology Business Services and to define and develop division-level performance metrics such as Objectives and Key Results (OKRs) and Key Performance Indicators (KPIs).
- Manage scheduled and ad-hoc risk reporting and presentations for executive and technology leaders to include Board, Committees, Sub-Committees, and monthly risk forums.
- Maintain a catalog of technology risk data, reports and dashboards that can be tailored for varying audiences (board, executives, technology leaders) to support scheduled and ad-hoc requests.
- Define and execute risk data aggregation methodology to support reporting requirements and identify top technology risks to the organization and analyze risk data to identify trends and insights.
- Drive the risk analytics and reporting program to higher levels of maturity with a focus on automation of data collection and dashboard creation.
- Define risk data management (in include data quality) and reporting requirements as well as develop risk reporting procedures.
Planning and Strategy
- Collaborate to establish goals, standards, and strategies for ETS Risk in alignment with enterprise and departmental objectives to include annual goals and a multi-year roadmap.
- Management of the division backlog of work projects and initiatives to include prioritization.
- Management of the division mission, vision, and value statements.
- Oversee the preparation and execution of Annual Financial Planning for the division.
- Development and management of Department-level calendar of audit, risk assessment and controls testing activity.
- Coordinate through ETS's Talent Development & Communications group to develop, manage, and execute on a talent development strategy.
Risk Culture
- Coordinate through ETS’s Talent Development & Communications group to develop, manage, and orchestrate risk management-related training and communication campaigns.
Administrative
- Monitoring and tracking of second line-of-defense obligations to include Risk & Control Self-Assessments (RCSAs), Business Impact Assessments (BIAs), controls testing, issues reporting and reporting of compliance issues and risks.
- Management of the ETS Risk Service Catalog and Operating Model to include tracking and management of interaction models for the various ETS functional areas.
- Management of ETS updates to the ERM Technology PRC (Process, Risk, Control) Taxonomy.
- Oversee knowledge management for the division.
- Perform supervisory/managerial responsibilities.
- Perform other duties as assigned.
- Bachelor's degree in a relevant field, or the equivalent combination of education, training and/or experience.
- Significant, proven experience defining key measurements that will drive visibility, accountability, quality and overall IT/Security effectiveness.
- Significant, proven experience with developing Key Risk Indicators (KRIs), Key Performance Indictors (KPIs), and Objectives & Key Results (OKRs)
- Experience in risk management, reporting and analytics, strategic planning, and management of personnel.
- Ability to own, maintain interactions with diverse sources of data to include databases, connectors, feeds, APIs and other systems that can provide data towards reporting and metrics.
- Working knowledge of at least one industry-leading risk management framework(e.g. OCTAVE, COBIT etc.)
- Advanced knowledge of information technology and information security concepts, principles, capabilities, and methods, and translating best practices to operations in a risk management framework.
- Advanced knowledge of information technology process, risks, and controls
- Strong proficiency in Microsoft Office applications.
- Proficiency with Splunk, ServiceNow and Azure DevOps.
- Strong presentation skills and the ability to adjust message and filter details based on audience(e.g. technical, business, management).
- Ability to work individually, and as part of a team.
- Strong written and oral com
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s