Bachelor's degree in business, management, law, or related field.
Minimum 8 years of banking or financial services experience, with at least 5 years in enterprise risk management or related fields.
Strong analytical skills with experience in governance, risk, and compliance platforms.
Proven experience presenting to Executive Management and Risk committees.
Familiarity with GRC platforms like Archer, MetricStream, or ServiceNow.
Responsibilities
Lead and maintain the Risk and Control Self-Assessment (RCSA) program.
Develop and review RCSA governance and foundational documentation.
Evaluate the effectiveness of the RCSA program through benchmarking and regulatory guidance.
Oversee the end-to-end RCSA process, ensuring assessments are accurate and aligned with risk definitions.
Aggregate and report RCSA results to Executive Management and Risk Committees.
Provide independent oversight and challenge of Line 1 risk assessments.
Develop RCSA-specific training to promote a strong risk culture.
Benefits
Base pay plus bonuses
Medical, dental, and vision insurance
401k plan
Health Savings and Flexible Spending Accounts
Vacation and sick time
Paid holidays
Paid parental leave
Tuition reimbursement
Additional benefits
Full Job Description
As part of this role you will:
Lead and maintain key elements of an effective Risk and Control Self-Assessment (RCSA) program.
Develop, maintain, and periodically review RCSA-related governance and foundational documentation, including the RCSA Methodology, risk and control definitions, scoring criteria, and assessment standards, ensuring alignment with the Bank's Risk Appetite and ERM framework.
Continuously evaluate the design, maturity, and effectiveness of the RCSA program and related reporting through peer benchmarking, regulatory guidance, ongoing education, and examination or audit feedback.
Lead and oversee the end-to-end RCSA process, including planning, execution, quality assurance, challenge, and issue escalation, coordinating with Lines 1, 2, and 3 to ensure assessments are complete, accurate, consistently applied, and aligned with established risk and control definitions.
Oversee the aggregation, analysis, and reporting of RCSA results for Executive Management, Risk Committees, and the Board, including inherent risk, control effectiveness, residual risk, emerging themes, threshold breaches, and alignment with Risk Appetite.
Oversee alignment of RCSA outputs with the Key Risk Indicator (KRI) lifecycle, ensuring RCSA results are informed by KRI results and provide forward-looking insight into key risks and control performance.
Ensure effective integration between the RCSA program and issues management and risk event/loss event processes, including linkage of identified control gaps to remediation plans and ongoing monitoring.
Provide independent Line 2 oversight, consultation, and credible challenge of Line 1 risk and control assessments, analysis of residual risk trends, control effectiveness concerns, root cause drivers, assessment quality, and related assessments (e.g., new products and services, process changes).
Develop and oversee RCSA-specific training and guidance to promote consistent understanding of risk and control concepts, assessment expectations, scoring discipline, and accountability, reinforcing a strong risk and control culture across the organization.
Assist, as needed, with preparation of RCSA-related materials, summaries, and themes for RCPC reporting and governance forums.
Serve as a member, chair, advisor, or attendee of designated risk governance committees, providing RCSA-related analysis, independent challenge, escalation of material concerns, and reporting of key themes, control weaknesses, and emerging risks. Membership duties may be assigned to one or more of the following risk committees:
Enterprise Risk Management Working Group (Chair)
Enterprise Risk Management Committee
Operational Risk Committee
Executive Retail Operations Committee
Asset Liability Committee
Credit Policy Management Committee
Information Security Committee
Participate in enterprise initiatives impacting RCSAs through selected corporate projects and initiatives to assess and advise on RCSA implications, risk and control impacts, and required assessment updates from a Line 2 perspective.
Oversee the implementation, configuration, and ongoing use of technology tools supporting the RCSA program (e.g., Archer IM and ERM modules), including workflow, data quality, reporting, and user experience.
Perform ad-hoc RCSA and risk analyses by conducting targeted RCSA-related analyses as requested by the Chief Risk Officer or ERM governance bodies to address emerging risks, control concerns, or regulatory inquiries.
Assist the Chief Risk Officer in acquisition due diligence and post-integration activities by assessing RCSA maturity, identifying material risks and control gaps, and supporting integration into the Bank's RCSA framework.
Participate in regulatory examinations and internal/external audit discussions to support alignment, address findings, and enhance the RCSA program based on feedback and recommendations.
Stay current on regulatory expectations, industry standards, and leading practices related to RCSA, risk management, control assessment methodologies, and forward-looking risk indicators.
To be successful in this position, we require the following:
Bachelor's degree in business, management, law or related field of study.
Minimum 8 years of banking or financial services experience, including at least 5 years in enterprise risk management, operational risk, compliance, audit, governance, or a related risk discipline.
Strong analytical skills and experience utilizing enterprise governance, risk and compliance platforms, reporting tools, and data visualization solutions.
Experience presenting to Executive Management and Risk committees.
Experience with GRC platforms (Archer, MetricStream, ServiceNow GRC, etc.).