About this roleTitle:Director, Data Risk Oversight (Second Line)
Location:New York, NY
Team:Risk & Quantitative Analysis (RQA) - Enterprise Risk Management
Reports To:Head of Operational Risk Specialists, RQA Enterprise Risk Management
Business Overview
Our Risk & Quantitative Analysis (RQA) group provides independent oversight of BlackRock's fiduciary and enterprise risks. The Enterprise Risk Management (ERM) function within RQA oversees risks that directly impact the corporate entity - including operational, technology, third party, model, and data risk - rather than the fiduciary risks assumed by funds and clients.
As a second line of defense function, our mission is to ensure senior management has defined and implemented effective risk management controls that protect our clients and our firm, while supporting the achievement of firm-wide business goals within our risk tolerance. RQA is committed to investing in our people to build both individual capability and a strong, collaborative team, within a culture of inclusion that encourages teamwork, innovation, and the development of future leaders.
The Opportunity
Data risk is being formally introduced into BlackRock's Enterprise Risk Management Framework, supported by a new enterprise Data Risk Management Policy and a Data Risk Oversight Committee (DROC) that reports into the Enterprise Risk Committee. As the volume, complexity, and strategic importance of data continue to grow - driven by the expansion of AI, data as a revenue-generating product, and growth in private markets - we are strengthening the independent oversight of data risk across the firm with a priority focus on critical investment data (CID).
We are seeking a Director to lead our Data Risk Oversight team within ERM. This role is focused on the quality, integrity, and reliability of enterprise data across its lifecycle - the risk that data is inaccurate, incomplete, untimely, or otherwise unfit for purpose - rather than on data security or cybersecurity, which are governed separately by the firm's Technology Risk & Cybersecurity Committee. The successful candidate will provide independent review and challenge of first line data owners, hold them accountable for compliance with the firm's data risk requirements, and give our senior committees and boards a clear, evidence-based view of the residual data risk the firm is running.
Key Responsibilities
Oversight of First Line Data Owners
- Provide independent oversight, review, and challenge of first line data owners and data stewards, ensuring they identify, assess, and manage data risk in line with the firm's data risk management policies and standards.
- Hold the first line accountable for compliance with data risk requirements across the data lifecycle - including ownership and accountability, data quality controls, metadata and lineage documentation, and fitness for purpose.
- Assess the design and operating effectiveness of first line data quality controls, including data quality rules, thresholds, validation checks, and reconciliation processes, and challenge remediation where controls are insufficient.
- Partner with first line teams across Aladdin Data, portfolio management, capital markets and operations, and their functional data owners to embed clear ownership and a strong culture of accountability for data risk.
- Review and challenge Risk and Control Self-Assessments (RCSAs) for data risk, ensuring material data risks are transparently assessed, linked to appropriate controls, and that residual risk is formally accepted only within the firm's risk tolerance.
Data Incidents and Operating Events
- Oversee the follow-up of data-related incidents and operating events, ensuring they are captured, triaged, and escalated in line with BlackRock's incident management and operating event processes.
- Provide independent challenge on root cause analysis, remediation, and preventative actions, confirming that lessons learned are embedded and that thematic issues are identified across events.
- Ensure timely escalation of significant data incidents to the DROC and, where appropriate, the Enterprise Risk Committee and boards.
- Track remediation and issues to closure, monitoring Risk & Control Issues (RCIs) and control improvements arising from events and assessments, and escalating overdue or unresolved items.
Metrics, Risk Indicators, and Reporting
- Develop and maintain data risk metrics and indicators, including Enterprise Risk Indicators (ERIs) with clear thresholds that inform an assessment of the firm's data risk profile.
- Establish ownership and reporting of data risk indicators, and translate underlying data into a concise, decision-useful view of residual risk for the DROC, the Enterprise Risk Committee, and the Board Risk Committee.
- Produce board- and committee-ready reporting that clearly articulates inherent risk, the control environment, and the resulting level of residual data risk the firm is running relative to its risk tolerance.
- Support the maturation of the data risk framework, including the data risk and control taxonomy, expansion of RCSA coverage, and continuous enhancement of oversight practices as the risk landscape evolves.
Governance and Stakeholder Engagement
- Act as a key contributor to the Data Risk Oversight Committee (DROC), supporting its mandate to monitor the firm's compliance posture against data risk management policies and standards and to escalate matters as appropriate.
- Collaborate with Legal & Compliance, Internal Audit, Information Security, and Privacy to ensure a coordinated approach to data governance and a clear delineation between data quality oversight and data security oversight.
- Engage with regulators and internal audit on data risk matters, supporting the firm's commitments to establish and operate an effective enterprise data risk oversight framework.
Leadership Expectations
- Build and lead a high-performing data risk oversight team, setting direction and developing specialist talent as the discipline scales.
- Influence senior stakeholders across the first and second lines, exercising sound, independent judgment and the confidence to challenge constructively while maintaining trusted relationships.
- Champion a culture in which first line teams own and manage data risk, supported by clear frameworks, standards, and guidance.
- Communicate complex data risk topics simply and credibly to the most senior audiences, including executive committees and the board.
What We Look For
- 10+ years of experience in data risk, data governance, operational or enterprise risk management, or a closely related control or audit discipline, ideally within asset management, banking, or financial services.
- Strong understanding of data quality and data governance principles across the data lifecycle - ownership, metadata, lineage, data quality controls, and fitness for purpose - with the ability to distinguish and coordinate with data security and privacy disciplines.
- Demonstrated experience providing independent oversight, review, and challenge of first line teams, and holding stakeholders accountable for control performance.
- A track record of designing risk metrics and indicators and producing decision-useful reporting for senior committees and boards.
- Experience following up on incidents and operating events, including root cause analysis, remediation tracking, and escalation.
- Excellent judgment, critical reasoning, and the ability to challenge the status quo and drive pragmatic solutions across cross-functional teams.
- Clear, credible communication skills, with the ability to influence outcomes at the most senior levels.
- Familiarity with industry-leading frameworks (e.g., DAMA DMBOK, COSO ERM, NIST CSF 2.0) and relevant regulatory expectations (e.g., OCC guidance) is preferred.
- A bachelor's degree is required; an advanced degree or relevant professional certification (e.g., CDMP, CRISC, CISA) is a plus.
For New York, NY Only the salary range for this position is USD$194,000.00 - USD$270,000.00 . Additionally, employees are eligible for an annual discretionary bonus, and benefits including healthcare, leave benefits, and retirement benefits. BlackRock operates a pay-for-performance compensation philosophy and your total compensation may vary based on role, location, and firm, department and individual performance.
Our benefitsTo help you stay energized, engaged and inspired, we offer a wide range of benefits including a strong retirement plan, tuition reimbursement, comprehensive healthcare, support for working parents and Flexible Time Off (FTO) so you can relax, recharge and be there for the people you care about.
Our hybrid work modelBlackRock's hybrid work model is designed to enable a culture of collaboration and apprenticeship that enriches the experience of our employees, while supporting flexibility for all. Employees are currently required to work at least 4 days in the office per week, with the flexibility to work from home 1 day a week. Some business groups may require more time in the office due to their roles and responsibilities. We remain focused on increasing the impactful moments that arise when we work together in person - aligned with our commitment to performance and innovation. As a new joiner, you can count on this hybrid model to accelerate your learning and onboarding experience here at BlackRock.
Guidance on AI use for candidatesAt BlackRock, AI has long been part of how we work - enhancing decision-making, improving operations, and helping us deliver better outcomes for clients. We encourage candidates to use AI thoughtfully to learn, prepare, and work more effectively; but during our interview process, we want to focus on getting to know you through your own experiences, thinking, and judgment. To support you, we've provided
guidance on when and how to use AI during our hiring process so you can approach each step with confidence and showcase your best self.