Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit ...
Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit ...
Develop and execute strategies for integrated risk management (IRM), governance, risk, and compliance (GRC), and Security Operations (SecOps) leveraging the ServiceNow platform. * Design and ...
Develop and execute strategies for integrated risk management (IRM), governance, risk, and compliance (GRC), and Security Operations (SecOps) leveraging the ServiceNow platform. * Design and ...
Lead, Governance, Risk & Compliance (Remote)
Gaithersburg, MD · Remote
$171K/yr
... GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise ...
Lead, Governance, Risk & Compliance (Remote)
Gaithersburg, MD · Remote
$171K/yr
... GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise ...
Director, Technology Risk & Digital Enablement
Cockeysville, MD · On-site
$150 - $230/hr
Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or ... US GAAP and risk assessment practice. * Robust understanding of regulatory and external ...
Director, Technology Risk & Digital Enablement
Cockeysville, MD · On-site
$150 - $230/hr
Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or ... US GAAP and risk assessment practice. * Robust understanding of regulatory and external ...
Lead, Governance, Risk & Compliance (Remote)
Gaithersburg, MD · Remote
$169K/yr
... GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise ...
Lead, Governance, Risk & Compliance (Remote)
Gaithersburg, MD · Remote
$169K/yr
... GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise ...
Lead, Governance, Risk & Compliance (Remote)
Gaithersburg, MD · On-site +1
$171K/yr
... GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise ...
Lead, Governance, Risk & Compliance (Remote)
Gaithersburg, MD · On-site +1
$171K/yr
... GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise ...
Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements). * Embed data-driven risk management techniques into ...
Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements). * Embed data-driven risk management techniques into ...
Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or ... US GAAP and risk assessment practice. * Robust understanding of regulatory and external ...
Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or ... US GAAP and risk assessment practice. * Robust understanding of regulatory and external ...
Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements). * Embed data-driven risk management techniques into ...
Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements). * Embed data-driven risk management techniques into ...
IRC Analyst
Westminster, MD · Hybrid
$70K - $110K/yr
Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with risks and controls. * Develop and execute detailed test procedures using strong criticalthinking skills.
IRC Analyst
Westminster, MD · Hybrid
$70K - $110K/yr
Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with risks and controls. * Develop and execute detailed test procedures using strong criticalthinking skills.
Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)
Aberdeen, MD · On-site
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. Act as onsite liaison between ASA(ALT ...
Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)
Aberdeen, MD · On-site
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. Act as onsite liaison between ASA(ALT ...
This role is ideal for engineers who can bridge modern data engineering and software development with Governance, Risk, and Compliance (GRC) expectations in regulated enterprise environments.
This role is ideal for engineers who can bridge modern data engineering and software development with Governance, Risk, and Compliance (GRC) expectations in regulated enterprise environments.
Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)
Aberdeen, MD · On-site
$120 - $150/hr
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. * Act as onsite liaison between ASA(ALT ...
Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)
Aberdeen, MD · On-site
$120 - $150/hr
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. * Act as onsite liaison between ASA(ALT ...
Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)
Aberdeen, MD · On-site
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. * Act as onsite liaison between ASA(ALT ...
Senior Information Systems Security Officer (ISSO)/Information Systems Security Manager (ISSM)
Aberdeen, MD · On-site
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. * Act as onsite liaison between ASA(ALT ...
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. * Act as onsite liaison between ASA(ALT ...
Lead system onboarding efforts into RegScale and support the configuration, optimization, and automation of governance, risk, and compliance (GRC) processes. * Act as onsite liaison between ASA(ALT ...
Gross Mendelsohn, one of the Mid-Atlantic's leading independent CPA and advisory firms, is seeking a strategic and technically strong Director of Cybersecurity Governance, Risk & Compliance (GRC) to ...
Gross Mendelsohn, one of the Mid-Atlantic's leading independent CPA and advisory firms, is seeking a strategic and technically strong Director of Cybersecurity Governance, Risk & Compliance (GRC) to ...
Cyber Cloud Assessment Engineer, Sr.
Fort George G Meade, MD · On-site
$110K/yr
Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR). * Review and verify the ...
Cyber Cloud Assessment Engineer, Sr.
Fort George G Meade, MD · On-site
$110K/yr
Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR). * Review and verify the ...
ServiceNow IRM/GRC Developer
Rockville, MD · On-site
$70 - $75/hr
Manage change activities in JIRA, including risk evaluation and approvals. * Orchestrate migrations ... Proven experience with IRM or GRC ServiceNow applications. * Successful end-to-end delivery of at ...
ServiceNow IRM/GRC Developer
Rockville, MD · On-site
$70 - $75/hr
Manage change activities in JIRA, including risk evaluation and approvals. * Orchestrate migrations ... Proven experience with IRM or GRC ServiceNow applications. * Successful end-to-end delivery of at ...
Cloud SCA-R, Senior
Fort George G Meade, MD · On-site
$115K/yr
Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR). * Review and verify the ...
Cloud SCA-R, Senior
Fort George G Meade, MD · On-site
$115K/yr
Validate CSO controls within eMASS or other government-provided Governance, Risk, and Compliance (GRC) tools; ensure accurate tracking in the Mission Status Report (MSR). * Review and verify the ...
Senior Analyst, Operational Risk Management - Financial Controls (Hybrid)
Baltimore, MD · Hybrid
$80K - $95K/yr
Navigate company Governance Risk & Compliance (GRC) tool to record, update and report on various risk issues, risk events, action plans, etc. Qualifications * Bachelor's degree in accounting, finance ...
Senior Analyst, Operational Risk Management - Financial Controls (Hybrid)
Baltimore, MD · Hybrid
$80K - $95K/yr
Navigate company Governance Risk & Compliance (GRC) tool to record, update and report on various risk issues, risk events, action plans, etc. Qualifications * Bachelor's degree in accounting, finance ...
Grc Risk information
What is the difference between Grc Risk vs Grc Analyst?
| Aspect | Grc Risk | Grc Analyst |
|---|---|---|
| Certifications | ISO 31000, CRISC, COSO | CISA, CRISC, CISSP |
| Work Environment | Risk management teams, compliance departments | IT, audit, compliance teams |
| Industry Usage | Financial, healthcare, corporate sectors | IT, finance, consulting firms |
| Primary Focus | Identifying and managing enterprise risks | Analyzing controls, assessing risks in systems |
Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.
What are popular job titles related to Grc Risk jobs in Maryland?
For Grc Risk jobs in Maryland, the most frequently searched job titles are:
What job categories do people searching Grc Risk jobs in Maryland look for?
The top searched job categories for Grc Risk jobs in Maryland are:
What cities in Maryland are hiring for Grc Risk jobs?
Cities in Maryland with the most Grc Risk job openings:
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 20 days ago
WesBanco rating
7.4
Based on 14 frontline employees who took The Breakroom Quiz
107th of 175 rated banks
Job description
SUMMARY:
Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit, and executive leadership to ensure the technology risk posture aligns to regulatory expectations, enterprise risk appetite, and industry frameworks. Requires deep expertise in banking technology regulations, enterprise risk frameworks, and control design, balanced with the executive presence to communicate complex risk themes to technical and non-technical audiences, including Board-level committees.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Owns andmaturesthe enterprise IT GRC program, including policies, standards, procedures, and control frameworks aligned to NIST CSF 2.0, CIS Controls v8, FFIEC CAT/Architecture, and applicable regulatory guidance (OCC, FDIC, Federal Reserve).
Establishes andmaintainsthe technology policy hierarchy (policy standard procedure control) with defined ownership and periodic review cadence.
Serves as program owner for the technology governance council structure (e.g., IT Steering, Technology Risk), including agenda-setting, reporting, and action item tracking.
Operationalizes AI governance standards (NIST AI RMF, ISO/IEC 42001), including AI inventory, risk tiering, lifecycle controls, and oversight of vendor AI use cases.
Directs the enterprise technology risk assessment program (annual and event-driven) across infrastructure, applications, data, cloud, and third-party environments; ensuremethodologyaligns to ERM/RCSA and risk appetite.
Maintains and evolves the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exceptionworkflows.
Leads risk assessment and advisory activities for emerging technologies (AI/ML, cloud, RPA), translating technical exposures into business impact and decision options.
Develops and reports technology risk metrics and KRIs for senior leadership and Board committees; drive a data-driven risk culture.
Serves as the primary IT GRC point of contact for regulatory examinations (OCC, FDIC, Federal Reserve) and internal/external audit engagements related to technology, cybersecurity, and operational risk.
Monitors and interprets evolving regulatory requirements and supervisory guidance (FFIEC, SR letters, OCC bulletins, GLBA Safeguards, privacy laws) and translate them into actionable obligations and control updates.
Manages technology audit and exam finding remediation: track issue aging,validateevidence, and ensure sustainable control improvements with clear ownership and timelines.
Partners cross-functionally to support intersecting risk programs (e.g., model risk governance/SR 11-7 alignment, BSA/AML technology controls, and data governance) as applicable.
Leads the technology and cybersecurity components of Third-Party Risk Management (TPRM), including onboarding due diligence, periodic reviews, and ongoing monitoring for critical/high-risk vendors.
Defines vendor risk tiering criteria and control requirements for SaaS, cloud, and AI providers; ensure contract provisions address security, privacy, SLAs, and right-to-audit.
Coordinateswith Procurement and Legal to ensure contractual risk provisions (e.g., DPA, data handling, incident notification) are implemented and enforced.
Design and implement a continuous controlsmonitoring(CCM) approach leveragingGRC toolingto automate evidence collection, control attestations, and targeted testing.
Overseescontrolself-assessments (CSA) across IT domains (identity and access management, change management, vulnerability management, data protection) andvalidateremediation effectiveness.
Partners with Cybersecurity on security control maturity assessments (CIS Controls, NIST SP 800-53) and annual FFIEC CAT completion.
Leads or co-leads the annual SOC 1/SOC 2 review process for material service providers and support SOX ITGC scoping, testing coordination, and remediation tracking (as applicable).
Builds, leads, and mentors a team of GRC analysts/specialists; establish performance expectations, succession coverage, and professional development pathways.
Drives GRC tool strategy and platform optimization (e.g., ServiceNow GRC, Archer, or equivalent) to enable scalable risk and compliance workflows.
Develops and manages the IT GRC program budget, including tooling, vendor contracts, and staffing plans.
Champions a risk-aware culture through executive communications, training, and proactive engagement with Technology and business teams.
OTHER REQUIREMENTS:
Banking is a highly regulated industry and you will be expected to acquire and maintain a proficiency in the Bank's policies and procedures, and adhere to all laws, rules and regulations that are applicable to your conduct and the work you will be performing. You will also be expected to complete all assigned compliance training in a timely manner.
Proficient in Microsoft Office products including Outlook, Word, PowerPoint and Excel.
Deep working knowledge of FFIEC IT Examination Handbook, NISTCSF ,CISControls ,, and NIST SP 800-63B.
Strong familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001.
Proficiencywith ITGC/SOX (as applicable) and SOC 2 review processes.
Working knowledge of cloud risk and compliance considerations (AWS, Azure, or GCP) and shared responsibility models.
Experience configuring and operating GRC platforms (ServiceNow, Archer, or equivalent).
Understanding ofnetworking concepts(e.g., firewalls, VPNs, DNS) and security protocols (e.g., TLS, SSH).,
Ability to learn other banking systems
Ability to manage or materially contribute to regulatory examinations and audit cycles, including remediation of findings.
Ability to learn new technologies and keep up with industry trends.
Professional demeanor in appearance, interpersonal relations, work ethic and attitude.
Ability to interact effectively across all levels of the organization.
Demonstrated ability to manage multiple priorities and delegate effectively to meet critical deadlines under difficult time restraints.
Understanding of account documentation and retention requirements.
Excellent verbal and written skills and presentation skills with the ability to define and solve problems.
Team player with a positive outlook
Demonstrated leadership ability and skills.
Ability to work independently and meet communicated deadlines.
Excellent analytical, problem-solving and decision-making skills.
Willingness to travelquarterly for onsite meetings.
ADDITIONAL INFORMATION:
The wage range for the SVP & Director of IT Governance position is $150,000 - $160,000 annually and is eligible for transition bonus and incentives. The position includes 27 days of PTO (Paid Time Off) and 5 days of STD (Short Term Disability) and 11 annual paid holidays.
WesBanco has an excellent benefits package to include medical, dental, and vision, Health Care Flexible Spending, Dependent Care Flexible Spending, Transportation Fringe Benefit Plan, Group Life, Long Term Disability, Optional Life, access to voluntary benefit products such as Cancer, Term & Universal Life, Accident, Short-Term Disability and Critical Illness policies, and other ancillary benefit products. WesBanco also offers 401(k) with employee match.
Bachelor's degree in Information Systems, Computer Science, Business, or related field and/or equal education or experience required
Minimum of 10 years of progressive experience in IT risk, GRC, cybersecurity, or technology audit required.
Minimum of 3 years in a leadership or program management required.
Minimum of 5 years of experience in a regulated financial institution (bank, credit union, or bank holding company); community or regional bank experience preferred.
Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM), Certified Information Systems Auditor (CISA), or Certified Risk & Information Systems Control (CRISC) are desirable.
About WesBanco
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
1,001 - 5,000 Employees
Headquarters location
Wheeling, WV, US
Year founded
1968