AVP, Operational Risk – Information Technology Oversight
Operational Risk Management is part of the 2nd Line of Defense (2LOD) at Synchrony. This role performs independent operational risk oversight of information technology, assessing and monitoring risks related to IT programs, emerging technologies, and third-party risks specific to the IT function. The position reports to the VP, Information Technology Oversight.
Responsibilities
- Engage the Information Technology organization in reviewing and assessing operational risks in the selection, deployment, and use of new technologies, including re-use of existing technology in new ways.
- Monitor risks accepted by the business and provide an independent assessment of risk-taking activities.
- Perform formal assessments of technology risks using common Risk Management processes, including Targeted Reviews, Concurrent Reviews, and Continuous Monitoring.
- Investigate potential risks taken by Information Technology teams and escalate through ORM processes.
- Monitor Cloud Computing and Public Cloud Service activities (AWS, Azure) to develop control objectives based on regulatory guidance and assess risks in Synchrony’s deployment.
- Contribute to and validate delivery on Alpha, Beta, and General Availability requirements for Cloud and new technology certifications across IT teams (Applications and Infrastructure). Confirm evidence and sustainability of requirements for each phase.
- Represent 2LOD at forums such as Cloud Design Authority (CDA), Architecture Review Board (ARB), Enterprise Architecture Forum, and Program Increments (PI) sessions for sprint teams (Cloud, Security, etc.).
- Review risks within the IT third-party supplier base, considering unique risks based on vendor relationships and services (e.g., purchased software, SaaS, service providers, staff augmentation).
- Manage risks and issues within Synchrony’s enterprise governance application (eGRC).
- Support 2nd Line of Defense processes such as the Enterprise Risk Assessment (ERA) and Risk and Control Self-Assessment (RCSA).
- Perform other duties and special projects as assigned.
Requirements
- Bachelor’s degree with 5+ years of information technology and/or data analytics experience in financial services or a banking institution.
- Strong understanding of operational risks in Technology, including software obsolescence, application design for resiliency (performance and availability), and meeting business demands.
Skills
- Familiarity with information security and risk management concepts.
- Proven analytical skills with strong attention to detail and quality control.
- Experience in financial services or banking with an understanding of the regulatory environment.
- Experience in IT operations and/or application support.
- Experience with data sourcing, reporting, and designing new analytical capabilities.
- Experience with Internal Audits and/or Regulatory Exams, including preparing materials for external inquiries.
- Ability to work in ambiguous environments and explain complex concepts.
- Strong presentation and communication skills (written and oral) for all organizational levels.
- Experience writing formal findings for Senior Management.
- Proficiency in Microsoft Suite (Word, Excel, PowerPoint).
- Excellent interpersonal skills and ability to foster relationships.
- Curiosity and ability to learn new concepts.
Pay
The salary range for this position is $90,000 – $155,000 USD annually, eligible for an annual bonus based on individual and company performance. Actual compensation will be based on work experience, skill level, or knowledge. Salaries are adjusted according to market in CA, NY Metro, and Seattle.
Schedule
This role offers flexibility with the option to work from home near a Synchrony Hub or in an office. You will be required to commute to your nearest Hub (virtual or physical) for in-person engagement activities such as business or team meetings, training, and culture events.
Eligibility Requirements
- Must be 18 years or older.
- Must have a high school diploma or equivalent.
- Must be willing to take a drug test, submit to a background investigation, and provide fingerprints as part of the onboarding process.
- Must satisfy the requirements of Section 19 of the Federal Deposit Insurance Act.
- New hires (Level 4-7) must have 9 months of continuous service before posting for other roles; after meeting this requirement, a minimum of 6 months in position is needed before posting for non-exempt roles.
- Employees (Level 8 or greater) must have at least 18 months in position before posting.
- All internal employees must meet performance expectations and have manager approval to post.
- Legal authorization to work in the U.S. is required; sponsorship for employment visas is not available for this role.