Sr. Director – Technology Risk Management
Early WarningAbout the role
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Summary
The Sr. Director of IT Risk serves as a senior leader within the Second Line of Defense (2LOD), responsible for supporting independent oversight, challenge, and governance of Technology Risk across a heavily regulated FinTech environment and reporting directly to the Vice President of Technology Risk
Essential Functions
Oversee independent oversight and challenges to the design, implementation, and effectiveness of technology risk management practices across the enterprise.
The role partners closely with the 1LOD Technology, Security, and Product teams to ensure that business goals and risks are adequately identified, while maintaining objective independence to oversee, assess, and challenge risk management decisions.
Provide expertise for assessing control gaps and remediation plans; evaluating adequacy, sustainability, and timeliness of corrective actions.
Collaborate with other risk and business leaders, to drive an end-to-end, holistic view of technology risks, controls and issues that may include non-technology processes and functions necessary to achieve a specific business outcome.
Work with second line of defense risk functions to understand and monitor applicable requirements and assess business impact to support a consistent approach across Technology for appropriate projects and processes to address needed changes.
Work closely with technology business leaders and our second line of defense teams 2nd line ORM team to maintain a comprehensive universe of risks, controls and RCSAs that reflect a complete and accurate view of technology risk and is aligned with relevant IT frameworks and internal policies.
Demonstrated understanding of risk management frameworks (COSO, NIST, ISO 27001), regulatory expectations (FFIEC, OCC, Fed, CFPB), and cloud security principles (AWS/GCP/Azure).
Manage and Mentor risk specialist to build and operate a high-performing IT Risk team.
Aggregate risk data across Technology to support reporting and analytics for risk management use by the business (RCSA, issues, vendor, control testing, etc.); ensure comprehensive universe of KRIs to support effective Technology-wide reporting.
Promote a strong risk culture and effective communication between 1LOD and 2LOD.
Manages a team that guides the Technology organization in the execution of risk management disciplines.
Supports materials for risk reporting and updates to senior management, risk committees, and external oversight bodies.
Provide effective leadership in developing and leading a high-performing team in support of technology risk objectives.
Support periodic oversight and challenge of risk assessments, including IT general controls, cloud risks, cyber risks, AI/ML risks, data management risks, and operational resilience assessments, and govern the tracking, challenge, and closure of technology and cyber findings and issues.
Supports the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
Minimum Qualifications
Education and/or experience typically obtained through completion of a bachelor's degree.
Typically, a minimum of 15 years of progressive risk management experience, preferably within financial services, or other complex, highly regulated environment, using the three lines of defense model.
Demonstrated success developing and retaining highly engaged, high performing teams and aligning technology business risk organization to meet business objectives.
Experience operating within a formal three-lines-of-defense (3LOD) model with in-depth understanding of 2LoD accountabilities.
Strong Information Technology subject matter knowledge.
Strong understanding of risk assessment techniques, practices. and control framew
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s