Director of IT Security Governance, Risk, and Compliance
Federal Home Loan Bank of AtlantaAbout the role
Compensation Grade:
17BASIC PURPOSE:
ESSENTIAL FUNCTIONS:
Governance & Oversight
- Own IT & cyber risk governance as a first line of defense, ensuring alignment with enterprise risk appetite.
- Establish and maintain governance frameworks aligned to FFIEC, NIST CSF, COBIT, COSO, ISO 27001, and supervisory guidance from the FHFA.
- Ensure governance over IT operations and infrastructure risk, including policy adherence, change management, and technology resilience.
Risk Management
- Lead IT & cyber risk identification, assessment, aggregation, and reporting, including emerging risks such as AI, quantum, and vendor concentration risk.
- Partner with the CRO and Enterprise Risk teams to integrate IT & cyber risk into the enterprise risk framework.
- Develop and apply risk assessment methodologies to evaluate impact, likelihood, and concentration of risks.
- Monitor risk exposures, limits, and concentrations to ensure risks remain within appetite.
Regulatory Engagement & Compliance
- Serve as a primary liaison with FHFA examiners and other regulators on IT and cybersecurity matters.
- Lead exam and audit preparation, execution, and remediation tracking; validate evidence of control effectiveness and issue closure.
- Ensure policies, standards, and practices remain aligned with evolving laws, regulations, and regulatory expectations, including privacy and data protection requirements (e.g., GLBA, GDPR).
Control Assurance & Oversight
- Oversee validation of IT and cyber control design, testing, and remediation.
- Provide governance oversight of access governance, vendor/third-party risk, cloud adoption, and IT operational controls.
- Champion automation and continuous monitoring to strengthen assurance and reduce manual processes.
Reporting & Metrics
- Aggregate and report IT & cyber risks, key risk indicators (KRIs), and key performance indicators (KPIs) to the CIO, executive leadership, and Board committees.
- Deliver insights on emerging trends, vulnerabilities, and regulatory findings to inform executive decision-making.
KNOWLEDGE, SKILLS, ABILITIES:
- Proven success in risk aggregation, effective challenge, remediation oversight, and IT governance.
- Demonstrated ability to influence executive leadership and present to Audit and Risk Committees.
- Ability to operate in a complex, matrixed organization with multiple stakeholders and competing priorities.
MINIMUM REQUIREMENTS
- A bachelor's degree and 15+ years of IT risk, cybersecurity governance, or compliance leadership in financial services or a regulatory environment. Advanced degree (MBA, MS in Information Security, or related) preferred. CISSP, CISM, CRISC, or CISA certifications are a plus.
- Direct experience engaging with federal regulators (FHFA, OCC, FFIEC) in exams or supervisory interactions.
Work Location: This individual must reside within commuting distance from our Atlanta, GA office. This position may not be filled in New Jersey, either in-person or remotely.
Work Schedule: Onsite with an opportunity to work remote partially.
Visa Sponsorship: Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Director, Cluster Leader - Unified Client Portal (50386)
Citrin Cooperman
$250,000/yr
Sr. Director, Affordable Housing Portfolio Management
TIAA
$224,000/yr
Department Faculty - Associate Director of Clinical Training, Clinical Psychology - Washington, D.C. (Hybrid)
The Chicago School