Jobs · Finance · North Carolina

Chief Cybersecurity Risk Officer

Truist · Charlotte, NC · 1 wk ago
Finance$300k–$400k/yrFull-time

About the role

The Chief Cybersecurity Risk Officer (CCRO) is a senior executive position responsible for providing comprehensive risk oversight of the organization's cybersecurity organization. Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity while supporting the institution's strategic objectives. This role will serve as the Risk Oversight Leader for all functions within Cybersecurity and lead the implementation of cyber risk oversight for Truist.

Responsibilities

  • Serve as the Chief Cybersecurity Risk Officer with independent oversight and challenge to the Chief Information Security Officer (CISO) for all risk types.
  • Establish and manage cyber risk oversight, including delivery of independent assessments and continuous monitoring.
  • Provide guidance to senior leaders across the company on critical cybersecurity issues for both internal and external stakeholders.
  • Use judgment to escalate significant issues and emerging risks; communicate cyber domain maturity and residual risk to senior management, including the Board of Directors.
  • Consistently and appropriately apply second line of defense corporate authority for managing Truist’s cyber risk.
  • Strategic Leadership: Develop and maintain the enterprise technology management framework, incorporating emerging risks related to cybersecurity. Establish risk appetite statements, key risk indicators, and thresholds for cybersecurity across the organization. Provide independent assessment and challenge of cybersecurity initiatives, ensuring alignment with risk appetite and regulatory expectations.
  • Risk Leadership: Provide independent risk oversight (second line of defense/LOD2) for Truist Protection Services (TPS) through identification, mitigation, monitoring, and reporting of operational, technology, and compliance-related risks within Core Technology and Cyber. Independently challenge LOD1 self-assessments and provide effective challenges to ensure risks remain within stated risk appetite. Integrate and align cybersecurity risk with business unit risk, controls, and assessments.
  • Governance and Oversight: Serve as a non-voting member of the first-line Technology, Data, and Operations risk committee and a voting member of the CIRO-led risk committee. Actively participate in Enterprise and Board Risk Committees (BRC), including:
    • Reviewing and effectively challenging technology and data risk policies, standards, and procedures.
    • Overseeing the assessment and monitoring of critical technology vendors and third-party service providers.
    • Ensuring compliance with regulatory requirements and supervisory guidance related to cybersecurity risk.
  • Risk Assessments: Define, communicate, and drive the Cyber Risk Frameworks and direct the assessment of information security and cyber risk. Provide independent assessment and oversight of the maturity of cybersecurity controls and their adequacy in meeting agreed business outcomes.
  • Risk Continuous Monitoring: Oversee the evaluation of the cybersecurity strategy and operations for potential risks. Monitor cybersecurity project portfolios, developmental methodologies, and progress on project milestones. Lead the review of significant cyber incidents and direct remediation efforts. Use monitoring routines to identify emerging risks and accelerate risk reviews of technology policies, business processes, or control assessments.
  • Risk Reporting: Design standard recurring reporting packages for Cybersecurity to support ongoing reporting of identification, mitigation, and monitoring of material risks. These packages will be used for internal discussions and governance reporting.
  • Regulatory Engagement Oversight: Serve as the primary risk point of contact with regulators on cyber risk matters. Present regular risk assessments and updates to the Board and external stakeholders. Collaborate with Truist Audit Services (TAS) and external auditors on cybersecurity reviews. Provide effective challenge and validation procedures on all regulatory remediations.
  • Talent Management: Lead, manage, and develop teammates directly and indirectly. Leverage industry insights to influence enterprise technology talent management through recommendations to senior leadership. Facilitate Cybersecurity Risk education series, skills training, and industry participation to elevate competence.
  • Risk Culture: Promote a culture of Risk Management across the organization by empowering risk teammates to identify risk exposure in everyday operations and champion improving enterprise programs for building a sustainable business model.

Requirements

  • Bachelor’s degree in computer science, Information Systems, or a data/technology-related field; MBA preferred.
  • Fifteen or more years of progressive experience in cybersecurity-relevant roles within a Category 2 or 3 Large Financial Institution (LFI), with a deep understanding of regulatory requirements for complex financial services organizations (including Federal Reserve and FDIC regulations).
  • In-depth understanding of how data is captured, transformed, and used, with the ability to connect end-to-end processes independently.
  • Fifteen or more years of experience managing people, with demonstrated high competency in recruiting, developing, and coaching/mentoring.
  • Fifteen or more years of experience in a financial institution with emphasis on risk management or equivalent work experience.
  • Extensive knowledge of information security, cyber risk, core technology infrastructure, cloud operations, and technology operations.
  • Experience leveraging modern tools to measure the effectiveness of technology and cyber controls.
  • Experience with enterprise architecture, reference architectures, and emerging technologies.
  • Knowledge of key technology rules/regulations and technology risk management practices (e.g., FFIEC, COBIT, NIST, ITIL).
  • Excellent leadership skills, including the ability to lead direct and indirect reports, including executive-level leaders.
  • Excellent communication (verbal and written), presentation, and facilitation skills; ability to influence and communicate with impact with C-suite executives and board members. Includes the ability to translate technical concepts for various audiences.
  • Excellence in building and leading high-performing teams.

Preferred Qualifications

  • Bachelor’s degree in finance or business equivalent.
  • Professional designations such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Project Manager (CPM).
  • Strategic business and financial planning experience.
  • Innovation mindset and strong understanding of industry-recognized tooling to support enterprise data programs and strong control environments.
  • Experience with audit processes and techniques.
  • Exposure to and experience with adapting cybersecurity capabilities in a post-Mythos threat environment.

Pay

The annual base salary for this position is $300,000 to $400,000.

Benefits

All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits. Truist offers:

  • Medical, dental, and vision insurance.
  • Life insurance, disability, and accidental death and dismemberment coverage.
  • Tax-preferred savings accounts and a 401k plan.
  • No less than 10 days of vacation (prorated based on date of hire and full-time/part-time status) during the first year of employment, along with 10 sick days and paid holidays.
  • Depending on the position and division, eligibility for a defined benefit pension plan, restricted stock units, and/or a deferred compensation plan.

Schedule

1st shift (United States of America).

This is a regular, full-time position.

Similar jobs

Chief Risk Officer

National Life GroupAddison, TX· 3 wk ago
Finance$300k–$440k/yrapply on job-boards.greenhouse.io

Chief Risk Officer

Enrichment Federal Credit UnionOak Ridge, TN· 1 mo ago
Quality Assurance$175k–$200k/yrapply on ddjmyers.com

Chief Risk Officer

Cboe Global MarketsChicago, IL· 1 mo ago
Financeapply on careers.cboe.com