... direct people management experience leading technology risk, information security governance, risk, and compliance, or information technology audit professionals * Demonstrated experience applying ...
IT Risk and Compliance Analyst
Portland, OR · On-site
$99K - $100K/yr
The ideal candidate will be responsible for ensuring that IT risk management processes are embedded in the enterprise, enabling optimal risk assessments returns. This role involves supporting IT risk ...
Quick apply
IT Risk and Compliance Analyst
Portland, OR · On-site
$99K - $100K/yr
The ideal candidate will be responsible for ensuring that IT risk management processes are embedded in the enterprise, enabling optimal risk assessments returns. This role involves supporting IT risk ...
IT Security Risk Management Analyst
Odell, OR · On-site
... ation Security Governance Work Shift: Day Work Days: MON-FRI Scheduled Hours: 8:30 AM-5 PM Scheduled Daily Hours: 8 HOURS Pay Range: $96,000.00-$120,000.00 The Security Risk Management Analyst will ...
IT Security Risk Management Analyst
Odell, OR · On-site
... ation Security Governance Work Shift: Day Work Days: MON-FRI Scheduled Hours: 8:30 AM-5 PM Scheduled Daily Hours: 8 HOURS Pay Range: $96,000.00-$120,000.00 The Security Risk Management Analyst will ...
OR · On-site
Job Details The Director, Enterprise Risk Management is responsible for managing and maturing the ... Understanding of technology directions, trends and strategic business impact on key client ...
Director of Legal & Risk Management
Dufur, OR · On-site
The Director of Legal & Risk Management partners closely with Executive Leadership to proactively ... Partner with Technology, CX, and Marketing teams on privacy policies, terms of service, consent ...
Quick apply
Director of Legal & Risk Management
Dufur, OR · On-site
The Director of Legal & Risk Management partners closely with Executive Leadership to proactively ... Partner with Technology, CX, and Marketing teams on privacy policies, terms of service, consent ...
The Director of Legal & Risk Management partners closely with Executive Leadership to proactively ... Partner with Technology, CX, and Marketing teams on privacy policies, terms of service, consent ...
The Director of Legal & Risk Management partners closely with Executive Leadership to proactively ... Partner with Technology, CX, and Marketing teams on privacy policies, terms of service, consent ...
Director of Legal & Risk Management
OR · On-site
The Director of Legal & Risk Management partners closely with Executive Leadership to proactively ... Partner with Technology, CX, and Marketing teams on privacy policies, terms of service, consent ...
Director of Legal & Risk Management
OR · On-site
The Director of Legal & Risk Management partners closely with Executive Leadership to proactively ... Partner with Technology, CX, and Marketing teams on privacy policies, terms of service, consent ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
The impact you'll make This position reports to the Director, Internal Audit, based in the US. As ... Evaluate IT system configurations, access controls, change management, and segregation of duties.
The impact you'll make This position reports to the Director, Internal Audit, based in the US. As ... Evaluate IT system configurations, access controls, change management, and segregation of duties.
OR · On-site
... risk assessment, faster incident mitigation and fostering a culture learning and continuous ... Own the transformation of critical operational processes, specifically Change Management and ...
OR · On-site
... risk assessment, faster incident mitigation and fostering a culture learning and continuous ... Own the transformation of critical operational processes, specifically Change Management and ...
Consultant, Risk Management
$75 - $150/hr
We provide data-driven, technology-enabled advisory, implementation, and staffing solutions to the ... Treliant's Risk Management service line is looking for Consultants who will work on client teams ...
Consultant, Risk Management
$75 - $150/hr
We provide data-driven, technology-enabled advisory, implementation, and staffing solutions to the ... Treliant's Risk Management service line is looking for Consultants who will work on client teams ...
OR · On-site
Oversee and support the Senior Director, Physical Security and Business Resiliency in developing ... Familiarity with emerging trends, best practices, and technologies in risk management and across ...
OR · On-site
Oversee and support the Senior Director, Physical Security and Business Resiliency in developing ... Familiarity with emerging trends, best practices, and technologies in risk management and across ...
Director, Technology Partnerships
OR · Remote
$160K/yr
Director, Technology Partnerships Overview We are seeking a results-oriented Technology Partnership ... The ideal candidate will have a proven track record in sales, account management, and a deep ...
Director, Technology Partnerships
OR · Remote
$160K/yr
Director, Technology Partnerships Overview We are seeking a results-oriented Technology Partnership ... The ideal candidate will have a proven track record in sales, account management, and a deep ...
Director of Risk & Compliance Overview The Director of Risk & Compliance is responsible for leading ... management. Experience leveraging data, reporting, and technology to improve operational ...
Director of Risk & Compliance Overview The Director of Risk & Compliance is responsible for leading ... management. Experience leveraging data, reporting, and technology to improve operational ...
IT Director
Bend, OR · On-site
$102K - $107K/yr
... our next IT Director. This position oversees all IT functions of the organization, provides ... Risk Management: Identifying, assessing, and mitigating risks associated with IT projects. * ...
Quick apply
IT Director
Bend, OR · On-site
$102K - $107K/yr
... our next IT Director. This position oversees all IT functions of the organization, provides ... Risk Management: Identifying, assessing, and mitigating risks associated with IT projects. * ...
SUMMARY The IT Risk Analyst II is responsible for measuring and identifying technical risks within ... Capable of managing varied assignments and working independently. * Ability to define problems ...
New
SUMMARY The IT Risk Analyst II is responsible for measuring and identifying technical risks within ... Capable of managing varied assignments and working independently. * Ability to define problems ...
New
This is a leadership role where you will pair your product development and people management ... Long periods of time sitting and/or standing in front of a computer using video technology. * May ...
This is a leadership role where you will pair your product development and people management ... Long periods of time sitting and/or standing in front of a computer using video technology. * May ...
... management, people risk, financial risk monitoring and emerging risk identification. The Sr. Director will partner closely with leaders, technology and operations teams, finance, HR and risk program ...
... management, people risk, financial risk monitoring and emerging risk identification. The Sr. Director will partner closely with leaders, technology and operations teams, finance, HR and risk program ...
Director Technology Risk Management information
What does a Director of Technology Risk Management do?
How does a Director of Technology Risk Management typically collaborate with other departments to ensure effective risk mitigation?
What are the key skills and qualifications needed to thrive as a Director of Technology Risk Management, and why are they important?
What is the difference between Director Technology Risk Management vs Cybersecurity Manager?
| Aspect | Director Technology Risk Management | Cybersecurity Manager |
|---|---|---|
| Primary Focus | Overseeing technology risk strategies and enterprise risk mitigation | Managing cybersecurity operations and security measures |
| Certifications | CRISC, CISSP, CISM | CISSP, CISA, CEH |
| Work Environment | Strategic, cross-departmental, executive level | Operational, technical teams, security operations centers |
| Industry Usage | Financial, healthcare, large enterprises | IT security firms, corporate IT departments |
The main difference is that the Director Technology Risk Management focuses on broad technology risk strategies across the organization, while the Cybersecurity Manager concentrates on implementing and managing cybersecurity measures. Both roles require similar certifications but differ in scope and strategic versus operational responsibilities.
Job description
The Team:Â
Upstart's Risk team is enhancing its second line of defense function in support of our application to establish Upstart Bank, N.A., a de novo national bank. The Risk team is responsible for Upstart's enterprise risk management program and risk governance, and for providing independent oversight and credible challenge across all core risk categories- including operational risk, third party risk, technology and information security risk, and treasury risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment, monitoring, reporting, and control of material risks, in alignment with OCC, FDIC, and FFIEC regulatory expectations.
As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk framework- leveraging and enhancing Upstart's existing technology and information security risk infrastructure to meet bank regulatory standards- and will provide independent oversight and credible challenge of the first-line technology and information security functions across all technology domains, including IT operations, cybersecurity, cloud infrastructure, affiliate-provided technology, and core banking systems. This role reports to the head of third party and technology risk and manages a team of two technology and security risk professionals.Â
How you'll make an impact
- Provide independent second-line review and credible challenge of first-line technology and information security activities, including but not limited to: cybersecurity controls, software development lifecycle (SDLC) and incident response programs, technology resiliency and third-party arrangements
- Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security risk assessments; and provide independent oversight of technology and security risks in alignment with OCC guidance on cloud computing
- Serve as a primary second-line point of contact for OCC examiners, internal audit, and other external stakeholders on technology risk and information security program topics and inquiries; prepare and deliver technology risk reporting to risk committees, the CRO, and the board.Â
- Build and lead a growing Technology Risk team, shaping how the bank identifies, prioritizes, and responds to its most important technology and security risks in alignment with applicable industry regulations
- Partner with first-line IT and cybersecurity teams, TPRM, ERM, Legal, and Compliance to ensure technology and information security risk is integrated into enterprise risk programs, cross-functional risk assessments, and the bank's overall 2LOD reporting and governance structure
Minimum QualificationsÂ
- Bachelor's degree or equivalent practical experience in information technology, cybersecurity, or a related field
- 8+ years of experience in technology risk, information security risk management, IT audit, or GRC in a banking or financial services environment
- 3+ years of direct people management experience leading technology risk, information security governance, risk, and compliance, or information technology audit professionals
- Demonstrated experience applying FFIEC IT Examination Handbook standards and OCC guidance on technology risk and information security in a bank or federally regulated institution
- Experience engaging banking regulators (OCC, FDIC, or Federal Reserve) on technology risk, cybersecurity, or IT controls examination matters
Preferred Qualifications
- Experience building or significantly enhancing a technology risk or information security GRC program in a de novo bank, early-stage bank, or similar environment where the program required meaningful design and build-out
- Knowledge of cloud risk management and OCC/FFIEC guidance on cloud computing (OCC Bulletin 2020-46), particularly in cloud-native or fintech-adjacent technology environments
- Familiarity with affiliate technology risk oversight, including independent oversight of bank-affiliate technology service arrangements, associated data segregation requirements, and Regulation W implications
- Experience with GRC tool implementation or administration in a bank regulatory context
- Current professional certification in information security or technology risk management (CISSP, CISA, CRISC, CISM, or comparable)
- Knowledge of AI/ML technology risk and related governance considerations in a fintech, lending, or model-intensive operating environment
Position location This role is available in the following locations: RemoteÂ
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSeniorÂ