Jobs · Finance · Ohio

Information Technology Enterprise Risk Manager

Northwest Bank · Columbus, OH · 2 wk ago
FinanceFull-time

About the role

The Information Technology Enterprise Risk Manager supports the execution and oversight of Northwest's Operational Risk framework, focusing on information technology, information security, and data risks. This role adapts industry-leading practices to identify, assess, monitor, and report key technology risks, embedding risk awareness into strategic and operational decision-making.

Responsibilities

  • Provide oversight of Risk and Control Self-Assessment (RCSA) activities within technology-related processes, performing credible challenge of conclusions and monitoring routines.
  • Independently assess risks and drive actions to address root causes of significant residual operational risk by challenging historical and proposed practices.
  • Validate first-line control testing and independently test information technology, information security, and data controls to verify design and operational effectiveness.
  • Leverage the Enterprise Risk Management framework to mature second-line technology and information security risk assessments, document controls, identify gaps, and create action plans for critical IT processes.
  • Support key risk assessments and perform credible challenge of methodologies and results, including GLBA, Authentication and Access Assessments, PCI DSS, and HIPAA compliance.
  • Consult with the first line on creating issues to address control gaps/failures and monitor remediation progress, ensuring timely mitigation and closure.
  • Establish metrics to quantify and measure technology risks and review action plans for deficient metrics.
  • Oversee front-line management of IT/IS/Data activities, including documentation of IT changes, end-of-life technology, resiliency enhancements, business impact analysis, vulnerability management, and addressing technology failures.
  • Provide credible challenge of first-line IT/IS/Data policies and standards to ensure compliance with corporate governance requirements.
  • Analyze losses associated with IT failures, disruptions, and errors to determine root causes, lessons learned, and recommendations for future risk avoidance.
  • Ensure compliance with Northwest’s policies, procedures, and Federal/State regulations.
  • Navigate Microsoft Office Software and department-specific applications to maximize efficiency.
  • Collaborate as part of a team and work with on-site equipment.
  • Perform additional duties as assigned by management.

Requirements

  • Bachelor’s degree in Management Information Systems, Cybersecurity, or Business Administration.
  • 8–12 years of cybersecurity/information technology experience.
  • 6–8 years of prior financial institution experience.

Skills

  • Deep understanding of information technology, information security, and data principles and best practices.
  • Proficiency in risk management methodologies, frameworks, and execution of Risk and Control Self-Assessment (RCSA).
  • Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA).
  • Experience with vulnerability scanning and penetration testing tools.
  • Strong analytical and problem-solving skills.
  • Excellent communication and reporting abilities.

Licenses and Certifications

  • ITIL (Infrastructure Library) certification.
  • Certified Information System Auditor (CISA).
  • Certified Information Security Manager (CISM).
  • Certified Risk and Information Systems Control (CRISC).
  • Certified Information Systems Security Professional (CISSP).

Similar jobs

Enterprise Risk Manager

Y-12 National Security ComplexOak Ridge, TN· 1 mo ago
Financeapply on career-hcm03.ns2cloud.com

Enterprise Risk Manager

VerveNew York, United States· 1 mo ago
Finance$150k–$180k/yrapply on job-boards.greenhouse.io