Jobs and Careers
MO
VP IT, Cyber and Data Risk Management
Mountain America Credit UnionMountain America Center - In Office (0152), United States, United Statesfull_timeVerifiedPosted 11 Aug 2025
About the role
Please reference the schedule and minimum qualifications listed below before applying.
If you need assistance with filling out our application form or during any phase of the application, interview, or employment process, please notify our Human Resources Team at 801-366-6947 option 1 or email macurecruiting@macu.com and every reasonable effort will be made to accommodate your needs in a timely manner.
Job Summary
The Vice President of IT, Cyber, and Data Risk Management serves as MACU’s second line leader for technology-related risks and governance, reporting directly to the Chief Risk Officer (CRO). This role is responsible for the design, implementation, and ongoing maturity of governance structures and risk oversight for IT, cyber, and data risk, ensuring alignment with the enterprise risk management (ERM) framework and regulatory expectations. This VP plays a critical role in overseeing and independently challenging the organization’s technology and data risk management practices.The VP will define the future-state strategy and lead the evolution of IT and Cyber Risk Governance, working in close partnership with IT, ERM, and Compliance. Additionally, this VP will take ownership of building and institutionalizing second line data risk and governance oversight, establishing foundational policies, standards, and controls to manage data as a strategic risk asset.
This role requires a forward-looking, technically fluent, and highly collaborative leader capable of influencing across lines of defense, applying recognized frameworks (i.e., NIST, COBIT, FFIEC, NCUA, ISO 27001), and providing effective, data-driven challenge where needed.
Job Description
To be effective, an individual must be able to perform each job duty successfully.
IT and Cyber Risk Governance
- Lead the development and oversight of the credit union’s IT and Cyber Risk Governance framework, ensuring alignment with the enterprise risk framework and regulatory expectations.
- Define and maintain cyber and technology risk policies, standards, and taxonomies, using leading practices such as NIST CSF, COBIT, and FFIEC Cybersecurity Assessment Tool.
- Partner with Information Security and IT leadership to evaluate cyber risks, incident trends, emerging threats, and risk response strategies.
- Oversee second-line risk assessments of technology projects, IT controls, vendor platforms, and emerging technology use cases.
- Provide risk oversight for cloud migration, system resilience, access management, and other key IT infrastructure initiatives.
Data Risk and Governance Oversight Program
- Build and lead the enterprise rata risk and governance second line oversight program from the ground up, including policy development, risk assessments, roles and responsibilities (data owners, stewards), and escalation protocols.
- Define frameworks to govern data quality, data lifecycle management, privacy, metadata, and critical data element controls.
- Collaborate with Data and Analytics, IT, Compliance, and business units to embed governance standards into daily data usage and decision-making.
- Identify data risks across systems and products and drive initiatives to reduce exposure and increase integrity and accountability.
Technology Risk Reporting and GRC Enablement
- Define and manage risk reporting routines for cyber, IT, and data risk, providing visibility to risk committees, executive leadership, and the Board.
- Oversee KRIs, metrics, and control testing related to technology and data risks; monitor for risk appetite breaches or early warning indicators.
- Collaborate with the ERM and Operational Risk teams to leverage and extend GRC platform capabilities in support of automation, risk aggregation, and reporting across technology risk domains.
Regulatory Alignment and Exams
- Ensure the IT, cyber, and data risk programs are aligned with NCUA, FFIEC, GLBA, and other regulatory requirements and industry frameworks.
- Serve as a primary liaison for the second line during regulatory exams and internal audits related to cyber, IT, and data risk.
- Monitor evolving regulatory and industry expectations and lead change initiatives to ensure ongoing readiness and responsiveness.
Leadership and Organizational Influence
- Lead a high-performing risk team responsible for second line oversight of technology and data risk domains.
- Provide credible challenge to first line risk decisions, technology implementations, and risk acceptances while maintaining a constructive and solutions-oriented tone.
- Partner across Ri
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s