About the Role:We're looking for a Cybersecurity Risk Manager who can spot weaknesses before they become problems. In this role, you'll evaluate risks in our technology systems, our use of artificial intelligence, and the vendors we rely on. You'll turn complex technical issues into clear guidance for leaders and help shift our security program from reactive to proactive-using data, intelligence, and forward-thinking strategies.
What You'll Do:- Lead high-value technical risk assessments that directly strengthen the Credit Union's security and protect members' financial well-being.
- Shape the organization's AI and emerging-tech strategy by evaluating new technologies, automation trends, and advanced attacker capabilities.
- Become a trusted advisor to leadership by turning complex technical findings into clear, actionable insights that influence major decisions.
- Build and operationalize the AI Governance Program-defining responsible, ethical, and compliant AI use across the enterprise and its vendors.
- Lead rigorous third-party security and AI reviews that shape vendor selection, strengthen partnerships, and reduce supply-chain risk.
- Stay ahead of evolving threats by monitoring vendor breaches, correlating alerts, and tracking AI-driven attack techniques to proactively strengthen defenses.
- Own incident readiness and response through tabletop exercises, scenario planning, and post-incident improvements that elevate organizational resilience.
- Drive meaningful control enhancements by collaborating with IT and business teams to uncover root causes and improve security across systems and processes.
- Transform risk data into intelligence by making AI, vendor, and cyber event information actionable within Archer IRM.
- Grow and mentor analysts-building a stronger, more capable Information Security team while serving as the escalation point for complex risk decisions.
Qualifications:- Bachelor's degree in cybersecurity, information assurance, or risk (or equivalent experience).
- 5+ years of risk management experience required, ideally in a financial institution.
- Certification in Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or equivalent certification preferred.
- Hands-on experience with enterprise risk management tools (Archer IRM preferred).
- Strong technical understanding of cybersecurity risks, systems, and controls.
- Ability to explain complex technical issues in simple, clear terms.
- Knowledge of GLBA, NIST, and FFIEC requirements.
- Strong problem-solving skills, attention to detail, and ability to manage multiple priorities.
- High integrity and ability to handle confidential information.
- Proficiency with Microsoft Office.