Overview
Who we're looking for
Reporting to the National Manager, Domain Risk Leads, the Domain Risk Lead will play a critical role in advancing the IT Risk department's mission by executing established risk assessment frameworks for IT and Data Risk. This includes ensuring alignment with COBIT and other recognized IT and Data Management standards, while integrating these practices into the broader Enterprise Risk Management (ERM) framework.
Through proactive risk oversight and governance, the Domain Risk Leader is accountable for ensuring that technology releases meet quality expectations and that any residual risks are clearly articulated, enabling informed decision-making across the business.
What you'll be doing
• Own and govern the domain risk management framework in alignment with enterprise risk appetite, strategic priorities, and business objectives.
• Direct the maintenance of a comprehensive, continuously updated risk register, ensuring risks are accurately documented, tracked, and actioned.
• Develop and implement risk mitigation strategies that materially reduce exposure to the organization and embed risk management into core business operations.
• Ensure adherence to internal policies, organizational standards, and applicable regulatory and control requirements.
• Lead oversight of domain risk incidents, root cause analysis, corrective actions, and remediation tracking to closure.
• Evaluate the design and effectiveness of controls and recommend enhancements to strengthen the control environment.
• Lead annual technology risk assessments and ensure outcomes are actionable, risk-based, and aligned to business and enterprise expectations
• Deliver concise, high-impact risk reporting and executive communications to senior leadership on key risks, findings, trends, and remediation progress.
• Serve as a trusted advisor to senior stakeholders, influencing decisions and promoting a strong risk-aware culture across the domain.
What you bring
• Bachelor's degree in BA or BS
• 7+ years of experience in IT risk management, audit, or cybersecurity experience
• Strong analytical and problem-solving abilities
• Experience with managing risk for enterprise technology and data
• Deep understanding of risk frameworks such as COBIT, NIST, and ISO 27001
• Implementation and/or use of GRC systems
• Experience with operational risk management and/or auditing, Sarbanes Oxley, (SOX), FFIEC requirements
• Familiarity with security best practices for enterprise systems, including encryption, access control, and monitoring
• Working knowledge or the principles of technology and data risk management including ITGCs, IT application controls, GLBA, Information Security, Release Management, CI/CD, control design, and testing within complex enterprise data environments
• Banking Regulations and Industry Frameworks preferably working in a banking institution
Added bonus if you have
• Masters or graduate degree
• 10+ years of experience in IT risk management, audit, or cybersecurity experience
• Certified Information Systems Auditor (CISA)
• Certified Information Systems Security Professional (CISSP)
• Certified Information Security Manager (CISM)
• Certified Risk in Risk and Information Systems Control (CRISC)
• Prior working experience using Archer GRC
• Experience implementing/designing controls related to AI or Cloud technology
What we'll bring
During your interview process, our team can fill you in on all the details of our industry-leading benefits and career
development opportunities. A few highlights include:
• A work environment built on teamwork, flexibility, and respect
• Professional growth and development programs to help advance your career, as well as tuition reimbursement
• Team Member Vehicle Purchase Discount
• Toyota Team Member Lease Vehicle Program (if applicable)
• Comprehensive health care and wellness plans for your entire family
• Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota
regardless of whether you contribute (if applicable)
• Paid holidays and paid time off
• Referral services related to prenatal services, adoption, childcare, schools and more
• Tax Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA)
• Relocation assistance (if applicable)