Role SummaryWe are seeking a Senior Manager, Technology & Cyber Risk Management, to join the AI, Model and Technology risk team in the Chief Risk Officer organization. This second-line role provides independent oversight and credible challenges of technology, cyber, cloud, data, third-party, resilience, and AI-related risks across the enterprise. The role partners with technology, cybersecurity, business, compliance, operational risk, legal, and internal audit stakeholders to ensure risks are identified, assessed, monitored, reported, and managed in line with enterprise risk appetite and regulatory expectations.
Responsibilities- Provide second-line oversight and credible challenge to management of technology, cyber, cloud, resilience, third-party technology, data protection, and AI-related risks across the enterprise.
- Lead and support risk assessments, control reviews, thematic deep dives, and oversight of major technology change, cyber, and AI-enabled initiatives.
- Lead or support AI, model & technology incident management program ensuring timely identification, reporting, escalation, root cause analysis, remediation and lessons learned for technology, cyber, data and AI incidents.
- Assess whether risks, controls, remediation plans, exceptions, and risk acceptances are appropriately identified, challenged, escalated, and managed.
- Develop risk reporting, KRIs, dashboards, and committee materials that provide senior leaders with clear insight into technology, cyber, and AI risk trends.
- Support enhancements to technology, cyber, and AI risk frameworks, policies, standards control frameworks, assessment methodologies, and governance routines, including alignment to recognized AI governance and GenAI security frameworks.
- Monitor regulatory developments, industry guidance, threat trends, audit findings, incidents, and emerging technology risks to inform second-line oversight priorities.
- Collaborate with Technology, Cybersecurity, Compliance, Operational Risk, Third-Party Risk, Business Resilience, Legal, and Internal Audit to drive consistent risk coverage and effective remediation.
- Partner with business risk managers to support broader technology, data, and operations business risk initiatives
Business knowledge - Strong understanding of the three-lines-of-defense model and the role of a second-line risk function in oversight, challenge, aggregation, and reporting.
- Understanding of enterprise risk and business risk domains, and demonstrated success of integrating technology & cyber risk management activities into overall business unit and enterprise risk management plans
- Knowledge of technology and cyber risk domains, including information security, cloud, infrastructure, application security, data protection, resilience, incident management, third-party technology risk, identity and access management, and AI risk management.
- Understanding of financial services regulatory expectations related to technology, cyber, operational resilience, third-party risk, data governance, and AI/model risk intersections.
- Familiarity with risk and control frameworks such as NIST CSF 2.0, NIST 800-53, ISO 27001/27002, COBIT, COSO, FFIEC guidance, NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 23894, SR 11-7 model risk management guidance, and OWASP Top 10 for Large Language Model Applications.
QualificationsRequired:- Typically requires 8+ years of relevant experience in technology risk, cyber risk, information security, technology audit, operational risk, enterprise risk management, regulatory supervision, or related financial services risk disciplines.
- Bachelor's degree or the equivalent combination of education and relevant experience in information technology, cybersecurity, computer science, engineering, risk management, finance, business, or a related field; advanced degree preferred.
- Experience providing independent risk oversight, credible challenge, risk advisory, or assurance for technology, cyber, cloud, third-party technology, or AI-enabled processes in a complex, regulated environment.
- Ability to synthesize complex technical and risk issues into clear executive-ready narratives, dashboards, committee materials, and recommendations.
- Strong stakeholder management, analytical, communication, and prioritization skills, including the ability to influence outcomes without direct authority.
- Relevant certifications preferred, such as CISSP, CISM, CISA, CRISC, CGEIT, cloud security certifications, or AI governance/risk credentials.
FINRA RequirementsFINRA licenses are not required and will not be supported for this role.
Work FlexibilityThis role is eligible for hybrid work, with up to one day per week from home.
Base Salary RangesPlease review the job posting for the location of this specific opportunity.
$122,000.00 - $209,000.00 for the location of: Maryland, Colorado, Washington and remote workers
$135,000.00 - $230,000.00 for the location of: Washington, D.C.
$153,000.00 - $261,000.00 for the location of: New York, California
Placement within the range provided above is based on the individual's relevant experience and skills for the role. Base salary is only one component of our total compensation package. Employees may be eligible for a discretionary bonus, which is determined upon company and individual performance.
BenefitsWe value your goals and needs, at work and in life. As an associate, you'll be supported with resources, benefits, and work-life balance so you can thrive in ways that matter to you.
Featured employee benefits to enrich your life:
- A generous retirement plan
- Health and wellness benefits, including online therapy
- Paid time off for vacation, illness, medical appointments, and volunteering days
- Family care resources, including fertility and adoption benefits
Learn more about our benefits.