Jobs · Information Technology

SVP & Director of IT Governance - Cyber Security

WesBanco · Wheeling, WV · 1 wk ago
RemoteRemoteInformation TechnologyFull-time

About the Role

Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit, and executive leadership to ensure the technology risk posture aligns to regulatory expectations, enterprise risk appetite, and industry frameworks. This position is 100% remote within the Bank's footprint, with occasional in-person meetings.

Responsibilities

  • Owns and matures the enterprise IT GRC program, including policies, standards, procedures, and control frameworks aligned to NIST CSF 2.0, CIS Controls v8, FFIEC CAT/Architecture, and applicable regulatory guidance (OCC, FDIC, Federal Reserve).
  • Establishes and maintains the technology policy hierarchy (policy → standard → procedure → control) with defined ownership and periodic review cadence.
  • Serves as program owner for the technology governance council structure (e.g., IT Steering, Technology Risk), including agenda-setting, reporting, and action item tracking.
  • Operationalizes AI governance standards (NIST AI RMF, ISO/IEC 42001), including AI inventory, risk tiering, lifecycle controls, and oversight of vendor AI use cases.
  • Directs the enterprise technology risk assessment program (annual and event-driven) across infrastructure, applications, data, cloud, and third-party environments; ensures methodology aligns to ERM/RCSA and risk appetite.
  • Maintains and evolves the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exception workflows.
  • Leads risk assessment and advisory activities for emerging technologies (AI/ML, cloud, RPA), translating technical exposures into business impact and decision options.
  • Develops and reports technology risk metrics and KRIs for senior leadership and Board committees; drives a data-driven risk culture.
  • Serves as the primary IT GRC point of contact for regulatory examinations (OCC, FDIC, Federal Reserve) and internal/external audit engagements related to technology, cybersecurity, and operational risk.
  • Monitors and interprets evolving regulatory requirements and supervisory guidance (FFIEC, SR letters, OCC bulletins, GLBA Safeguards, privacy laws) and translates them into actionable obligations and control updates.
  • Manages technology audit and exam finding remediation: tracks issue aging, validates evidence, and ensures sustainable control improvements with clear ownership and timelines.
  • Partners cross-functionally to support intersecting risk programs (e.g., model risk governance/SR 11-7 alignment, BSA/AML technology controls, and data governance).
  • Leads the technology and cybersecurity components of Third-Party Risk Management (TPRM), including onboarding due diligence, periodic reviews, and ongoing monitoring for critical/high-risk vendors.
  • Defines vendor risk tiering criteria and control requirements for SaaS, cloud, and AI providers; ensures contract provisions address security, privacy, SLAs, and right-to-audit.
  • Coordinates with Procurement and Legal to ensure contractual risk provisions (e.g., DPA, data handling, incident notification) are implemented and enforced.
  • Designs and implements a continuous controls monitoring (CCM) approach leveraging GRC tooling to automate evidence collection, control attestations, and targeted testing.
  • Oversees control self-assessments (CSA) across IT domains (identity and access management, change management, vulnerability management, data protection) and validates remediation effectiveness.
  • Partners with Cybersecurity on security control maturity assessments (CIS Controls, NIST SP 800-53) and annual FFIEC CAT completion.
  • Leads or co-leads the annual SOC 1/SOC 2 review process for material service providers and supports SOX ITGC scoping, testing coordination, and remediation tracking.
  • Builds, leads, and mentors a team of GRC analysts/specialists; establishes performance expectations, succession coverage, and professional development pathways.
  • Drives GRC tool strategy and platform optimization (e.g., ServiceNow GRC, Archer, or equivalent) to enable scalable risk and compliance workflows.
  • Develops and manages the IT GRC program budget, including tooling, vendor contracts, and staffing plans.
  • Champions a risk-aware culture through executive communications, training, and proactive engagement with Technology and business teams.
  • Willingness to travel quarterly for onsite meetings.

Requirements

  • Bachelor’s degree in Information Systems, Computer Science, Business, or related field and/or equal education or experience required.
  • Minimum of 10 years of progressive experience in IT risk, GRC, cybersecurity, or technology audit required.
  • Minimum of 3 years in a leadership or program management role required.
  • Minimum of 5 years of experience in a regulated financial institution (bank, credit union, or bank holding company); community or regional bank experience preferred.
  • Proficient in Microsoft Office products including Outlook, Word, PowerPoint, and Excel.
  • Deep working knowledge of FFIEC IT Examination Handbook, NIST CSF, CIS Controls, and NIST SP 800-63B.
  • Strong familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001.
  • Proficiency with ITGC/SOX (as applicable) and SOC 2 review processes.
  • Working knowledge of cloud risk and compliance considerations (AWS, Azure, or GCP) and shared responsibility models.
  • Experience configuring and operating GRC platforms (ServiceNow, Archer, or equivalent).
  • Understanding of networking concepts (e.g., firewalls, VPNs, DNS) and security protocols (e.g., TLS, SSH).
  • Ability to manage or materially contribute to regulatory examinations and audit cycles, including remediation of findings.
  • Excellent verbal and written communication and presentation skills with the ability to define and solve problems.
  • Demonstrated leadership ability and skills, with a team-oriented and positive outlook.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM), Certified Information Systems Auditor (CISA), or Certified Risk & Information Systems Control (CRISC) are desirable.

Other Requirements

Banking is a highly regulated industry, and you will be expected to acquire and maintain proficiency in the Bank's policies and procedures, adhere to all applicable laws, rules, and regulations, and complete all assigned compliance training in a timely manner.

Similar jobs

Director of IT & Cybersecurity

CrunchbaseIllinois, United States· 1 mo ago
RemoteInformation Technology$206k–$242k/yrapply on crunchbase.na.teamtailor.com

Director of IT & Cybersecurity

CrunchbaseColorado, United States· 1 mo ago
RemoteInformation Technology$206k–$242k/yrapply on crunchbase.na.teamtailor.com

Director of IT & Cybersecurity

CrunchbaseFlorida, United States· 1 mo ago
RemoteInformation Technology$206k–$242k/yrapply on crunchbase.na.teamtailor.com