Jobs and Careers
TR

Senior Cybersecurity Risk Officer

Truist
United Statesfull_timeVerifiedPosted 3 Jul 2025

About the role

The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency:  English (Required)

Work Shift:

1st shift (United States of America)

Please review the following job description:

Truist is looking for a Senior Cybersecurity Risk Officer to serve as the independent oversight and effective challenge function to the Chief Information Security Officer covering the Cyber Security and Identity and Access Management domains. Provide guidance to senior leaders across the company on critical cyber control failures and issues; use judgment to escalate significant issues and emerging risks; evaluate, determine and communicate cyber and access management domain maturity to Executive Leadership and the Board of Directors; consistently and appropriately apply second line of defense corporate authority for managing Truist’s technology risk, including driving our overall risk appetite for the company for Cyber related functions.

Following is a summary of the essential functions for this job.  Other duties may be performed, both major and minor, which are not mentioned below.  Specific activities may change from time to time.

1. Technology Risk Leadership - Provide independent risk oversight (i.e. second line of defense/LOD2) for Truist Technology through the effective identification, mitigation, monitoring and reporting of operational, technology, and compliance related risks within Enterprise Technology with a specifics focus on the Cyber and Identity and Access Management domains.

2. Strategic Alignment – Provide Cyber and Information Security Risk governance that supports the Truist organization’s strategies and objectives while operating within established risk appetites;  Provide effective challenge of the Corporate Cybersecurity Strategy for Truist

3. Industry engagement- lead engagement of peer institution second line functions to influence the industry build of the tech risk / cyber second line functions

4. Penetration / Red Team testing- lead execution of independent second line Red Team / Penetration Testing; work is typically commissioned by the Board, the CEO and / or the CRO.

5. Value Delivery – Ensure that cyber / information security risk resources, activities and initiatives are aligned to enable and sustain achievement of business objectives within forecasted spend rates while reducing risks;

6. Cyber / Information Security Risk Assessment– Provide independent assessment and oversight of the maturity of information security and adequacy of cyber controls pertaining to information security in meeting agreed to business outcomes for performance, stability, security and service availability. Assessments should leverage agreed upon metrics produced by Business Unit Risk Management (BURM) /first line of defense – LOD1) but challenged and validated as appropriate;

7. Independent Challenge of LOD1 assessments - Review and attest to/challenge adequacy of risk assessments (i.e. Risk & Control Self-Assessments, Application Assessments, Change Risk Assessments) produced by BURM; 

8. Committee Engagement – Serve as member of the Technology Risk Committee and participate in the Enterprise and Board Risk Committees and the Board Technology Committee, when applicable for Cybersecurity topics;

9. Regulatory Engagement Oversight - Ensure effectiveness and structure in regulatory engagement practices, including responses out of the Corporate Cyber Security Group;

10. Training and Communication - Encourage and monitor Cyber education, skills training and adoption goals to drive improved Cyber risk culture and awareness

11. Policy & Standard Leadership – Engage on Technology Risk policy governance. Provide direction and guidance in the development, imple

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Truist

View company profile →