Technology Risk Senior Specialist
Regular, full-time position. Candidate must be located in or willing to self-relocate to Charlotte, NC; Raleigh, NC; Richmond, VA; or Atlanta, GA. In-office requirement is 5 days per week; no full remote or relocation assistance available at this time.
About the role
Key contributor to the Truist second-line-of-defense (LoD2) Technology Risk team responsible for independent risk oversight of one or more Technology Risk Framework domains and/or Business Unit Technology areas. Partner with Enterprise Technology teammates and stakeholders in assigned oversight areas, advise on risk-related topics, effectively challenge through risk programs, and independently evaluate technology risk in the Truist environment.
Responsibilities
- Provide independent risk oversight (i.e., LOD2) for Truist Technology and related consult to Truist Business Units through the effective identification, mitigation, monitoring, and reporting of technology risk and other related risks (e.g., operational, compliance) within Enterprise Technology.
- Serve as a subject matter expert and steward of the Technology Risk Framework to identify, report, and mitigate technology risks.
- Execute independent assessment and oversight of the maturity of technology and adequacy of technology controls to achieve business outcomes for performance, stability, security, and service availability.
- Strengthen and sustain proactive risk culture through conducting effective risk-focused management and partnership routines with technology teams and internal partners.
- Interface with senior leaders and key partners across the organization.
- Review and challenge outcomes of first-line-of-defense risk program execution.
- Monitor legal, regulatory, compliance, and audit matters for assigned Enterprise Technology oversight area(s) and ensure timely action.
- Lead complex projects that have broad technology and enterprise-level impact with implications and/or resource requirements beyond risk management.
- Provide informal leadership to others and serve as a resource on complex solutions.
- Operate comfortably in interdisciplinary, matrix environments.
- Use acumen and skills to effectively bridge business and IT functions seamlessly.
- Pivot quickly between advisory consultant and implementation consultant roles.
Requirements
- Bachelor’s Degree or an equivalent combination of education and experience.
- 10+ years of banking, technology, operations, or risk management experience.
- Strong business acumen, management experience, problem-solving, critical thinking, influencing, and decision-making skills.
- Experience operating independently and navigating ambiguity to deliver value.
- Excellent interpersonal and communication skills demonstrating the ability to establish credibility with all levels of management effectively.
- Demonstrated ability to organize and manage complex initiatives and deliver high-quality, executive-level work products.
- Comfort with data and applying analysis to derive value-add insights.
- Adept with Microsoft Office products.
Preferred Qualifications
- Demonstrated ability to act as a trusted second-line partner to first-line Technology, Data, and Operations leaders, including Enterprise Architecture and CTO teams, balancing independent risk oversight with practical, solution-oriented guidance.
- Experience operating in a second-line-of-defense role within a regulated financial services environment, providing independent risk oversight, effective challenge, and credible advisory support to technology and engineering teams.
- Strong expertise in cloud risk management, with hands-on knowledge of AWS and its use within financial institutions, including assessment of inherent and residual risk, control design, and ongoing monitoring.
- Demonstrated understanding of both application and infrastructure risk in cloud environments.
- Experience supporting enterprise cloud transformation initiatives (e.g., migration from on-prem to cloud), ensuring risks are identified, managed, and aligned with the firm’s risk appetite and regulatory expectations.
- Solid understanding of Secure SDLC and change management practices in a financial services context, including how controls are embedded across development, testing, deployment, and release cycles.
- Prior developer, engineering, or architecture experience, or deep familiarity working with development teams, enabling effective oversight of CI/CD pipelines, standardized deployment patterns, and automated controls.
- Ability to evaluate control effectiveness across key risk domains, including identity and access management, data protection, vulnerability management, incident response, business continuity, and third-party risk.
- Strong communication and influencing skills, with the ability to translate complex technical risks into clear, actionable insights for senior management, risk committees, auditors, and regulators.
- Relevant certifications such as AWS Certified Solutions Architect or Security – Specialty, CISSP, CISM, CRISC, or similar technology risk credentials.
Pay
Annual base salary for this position is $170,000–$185,000.
Benefits
All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits. Truist offers:
- Medical, dental, and vision insurance.
- Life insurance, disability, and accidental death and dismemberment coverage.
- Tax-preferred savings accounts and a 401k plan.
- No less than 10 days of vacation (prorated based on date of hire and full-time/part-time status) during the first year of employment, along with 10 sick days and paid holidays.
- Depending on the position and division, eligibility may also include a defined benefit pension plan, restricted stock units, and/or a deferred compensation plan.