First Command Financial Services

Director, Technology Risk & Operational Resilience

First Command Financial Services • $150K — $180K *
Finance & Insurance
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science or Information Systems; Master's preferred
  • 12+ years in technology risk, operational risk, cybersecurity, or business continuity
  • 5+ years of leadership experience in enterprise-wide risk programs
  • Experience in regulated financial services like banking or insurance
  • Strong communication skills and experience with executive leadership

Responsibilities

  • Lead technology risk, third-party risk management, and operational resilience teams
  • Challenge first-line risk assessments and control activities
  • Evaluate technology risk exposures and monitor emerging trends
  • Establish operational resilience frameworks and crisis preparedness programs
  • Prepare executive risk insights and reports for management and the Board

Benefits

  • Hybrid work environment
  • Professional development opportunities
  • Mentorship program
  • Industry-standard certifications support
Full Job Description
Job Description

How will your role impact First Command?

The Director, Technology Risk & Operational Resilience is a senior leader within Enterprise Risk Management responsible for leading the Company's technology risk, third-party risk management, and business resiliency teams and providing independent oversight and effective challenge of related first-line risk management activities. Reporting to the SVP, Chief Risk Officer, the Director establishes governance and risk oversight frameworks, monitors exposure against approved risk appetite and tolerances, evaluates interconnected and emerging risks, and provides decision-oriented insights to executive leadership and the Board.

The Director oversees enterprise risk practices related to technology, critical third parties, operational resilience, business continuity, crisis preparedness, and disaster recovery. The role partners with Technology, Information Security, Operations, Procurement, Legal, Compliance, Internal Audit, and business leadership to promote clear risk ownership, timely escalation, effective remediation, and resilience of critical business services.

What will the employee do in this role?

Technology Risk Oversight
  • Lead the second-line technology risk function and the enterprise third-party risk management and business resiliency teams, while providing independent oversight and effective challenge of first-line technology, cybersecurity, business continuity, crisis management, and disaster recovery capabilities.
  • Challenge first-line risk assessments, control activities, remediation plans, and risk acceptance decisions.
  • Provide independent risk oversight and effective challenge of material technology exposures, including cybersecurity, cloud services, data and technology dependencies, artificial intelligence, technology transformation, and end-of-life or unsupported platforms.
  • Provide an independent risk perspective on significant technology investments, architecture decisions, system implementations, cloud migrations, acquisitions, and material changes to critical services.
  • Evaluate technology risk exposures against approved risk appetite statements and tolerance thresholds.
  • Monitor emerging technology risks and industry trends and advise executive leadership on potential impacts to the organization.
  • Oversee technology risk metrics, key risk indicators (KRIs), and executive reporting.

Third-Party Risk Oversight
  • Lead the enterprise TPRM governance and oversight function, including risk-tiering standards, due diligence requirements, ongoing monitoring, issue escalation, reporting, and effective challenge of third-party risk decisions.
  • Define roles and accountability among business relationship owners, Procurement, Information Security, Legal, Compliance, and the TPRM function throughout the third-party lifecycle.
  • Provide independent challenge and oversight of vendor risk assessments, due diligence activities, ongoing monitoring, and remediation efforts.
  • Oversee risks associated with critical third-party service providers, strategic partners, cloud service providers, and outsourced business operations.
  • Monitor concentration risk, fourth-party risk, and critical supplier dependency risks.
  • Assess third-party risk management practices against regulatory expectations, industry standards, and organizational risk appetite.
  • Escalate material third-party risks and control weaknesses to executive leadership and governance committees.

Operational Resilience & Business Resiliency
  • Establish and oversee the enterprise operational resilience framework, including critical business services, key dependencies, disruption tolerances, and severe-but-plausible scenarios.
  • Lead the business resiliency and crisis preparedness program, including business impact analyses, continuity planning, exercises, and enterprise event readiness.
  • Provide independent oversight and effective challenge of Technology-owned disaster recovery strategies, recovery capabilities, testing results, and remediation plans.
  • Assess interconnected dependencies across people, processes, technology, facilities, data, and third parties.
  • Aggregate business continuity, disaster recovery, crisis management, and third-party resilience results into an enterprise view of operational resilience.

Risk Governance & Regulatory Engagement
  • Establish and maintain governance frameworks, policies, standards, and reporting processes supporting technology risk, third-party risk, and operational resilience.
  • Monitor compliance with applicable regulatory expectations and industry guidance, including banking, securities, insurance, and advisory regulations.
  • Support regulatory examinations, independent reviews, and internal and external audits.
  • Serve as a trusted advisor to the CRO on emerging risks, regulatory developments, and strategic risk implications.
  • Develop and maintain risk appetite metrics, escalation thresholds, and Board-level monitoring indicators.
  • Ensure material risk issues, emerging threats, and tolerance breaches are appropriately escalated.

Executive & Board Reporting
  • Prepare executive-level risk insights and presentations for management committees, executive leadership, the Risk Management Committee, and the Board of Directors.
  • Communicate trends, emerging risks, risk concentrations, resilience concerns, and program maturity assessments.
  • Provide independent risk perspectives on significant technology initiatives, acquisitions, vendor relationships, and strategic business initiatives.
  • Support enterprise risk reporting and integration of technology, third-party, and resilience risks into the broader ERM framework.

Leadership & Talent Development
  • Lead, mentor, and develop a high-performing team of risk professionals.
  • Establish performance objectives and professional development plans that enhance organizational capabilities.
  • Foster a culture of effective challenge, accountability, collaboration, and continuous improvement.
  • Drive maturity and capability enhancements across technology risk, third-party risk, and resilience disciplines.

Who will you lead?
  • Supervise all job activities of the IT risk management staff, including third-party risk management team, business resiliency team, and technology risk management team

What skills & qualifications do you need?

Education
  • Bachelor's degree in computer science, Information Systems, or a related field; Master's degree preferred

Work Experience
  • 12+ years of progressive experience across technology risk, operational risk, cybersecurity risk, third-party risk management, business continuity, disaster recovery, or operational resilience with demonstrated depth in multiple disciplines.
  • 5+ years of leadership experience managing enterprise-wide risk programs and professional staff.
  • Experience within a regulated financial services organization, including banking, wealth management, broker-dealer, advisory, insurance, or asset management businesses.
  • Demonstrated experience interacting with executive leadership, Board committees, regulators, and auditors.
  • Experience establishing or materially advancing risk frameworks, governance, reporting, and program maturity.

Preferred Certifications
  • Certified Information Systems Auditor (CISA); Certified Information Systems Security Professional (CISSP); Professional Risk Manager (PRM); Certified Risk Manager (CRM); Certification in Risk Management Assurance (CRMA); Certified in Risk and Information Systems Control (CRISC); Certified Information Security Manager (CISM)

Required Knowledge, Skills and Abilities
  • Demonstrated ability to provide credible, independent challenge while maintaining constructive relationships with senior leaders and first-line risk owners.
  • Ability to synthesize complex technology, third-party, and resilience information into clear risk conclusions and actionable executive insights.
  • Strong knowledge of technology risk, cybersecurity risk, operational resilience, third-party risk, business continuity, disaster recovery, and enterprise risk management principles.
  • Ability to evaluate interconnected risks and dependencies across legal entities, business lines, technologies, processes, facilities, and service providers.
  • Strong executive communication, governance, negotiation, and influencing skills.
  • Sound judgment in escalating material risks, tolerance breaches, control weaknesses, and unresolved remediation.
  • Demonstrated ability to lead specialized teams, establish priorities, manage capacity, and develop talent.
  • Ability to operate effectively in a complex, regulated, and evolving financial services environment.
  • Proficiency with risk management platforms, data visualization tools, and Microsoft 365 applications.

#LI-NC1 #LI-HYBRID

About First Command Financial Services

First Command Financial Services, Inc. is a financial planning organization that focuses on serving the unique needs of military families. The company was founded in 1958 by a retired Air Force officer and has since grown to serve clients across the United States. First Command offers a range of financial planning services, including investment management, retirement planning, insurance, and banking. The company is committed to providing personalized service and education to help military families achieve their financial goals.
Learn more about First Command Financial Services
Size
500 employees
Industry

Similar Jobs

More Jobs at First Command Financial Services

More Finance & Insurance Jobs

Find similar Director, Technology Risk & Operational Resilience jobs: