1

Operational Risk Jobs in Phoenix, AZ (NOW HIRING)

Risk Treatment Specialist

Tempe, AZ ยท On-site

$108K - $185K/yr

Operational Risk, Financial Risk, Cyber Resilience, Cybersecurity, Risk Management, IT Risk and Control, and/or IT Audit * Strong working knowledge of the inherent risks in the financial services ...

Third Party Risk Manager, AVP

Tempe, AZ ยท On-site

$91K - $107K/yr

Basic understanding of Operational Risk Management Programs and frameworks * Experience managing Third-Party relationships. * Knowledge of regulatory bodies governing financial services. * Strong ...

Third Party Risk Manager, AVP

Tempe, AZ ยท Hybrid

$91K - $107K/yr

Basic understanding of Operational Risk Management Programs and frameworks * Experience managing Third-Party relationships. * Knowledge of regulatory bodies governing financial services. * Strong ...

Third Party Risk Manager, AVP

Tempe, AZ ยท Hybrid

$91K - $107K/yr

Basic understanding of Operational Risk Management Programs and frameworks * Experience managing Third-Party relationships. * Knowledge of regulatory bodies governing financial services. * Strong ...

next page

Showing results 1-20

Operational Risk information

See Phoenix, AZ salary details

$38.7K

$85.2K

$153.9K

How much do operational risk jobs pay per year?

As of Jul 20, 2026, the average yearly pay for operational risk in Phoenix, AZ is $85,231.00, according to ZipRecruiter salary data. Most workers in this role earn between $65,000.00 and $103,800.00 per year, depending on experience, location, and employer.

How does an Operational Risk professional typically interact with other departments within an organization?

Operational Risk professionals work closely with a variety of teams, such as compliance, internal audit, IT, and business units, to identify and assess risks that could impact the organization's operations. They often facilitate risk assessments, lead training sessions on risk awareness, and collaborate on developing controls and mitigation strategies. Building strong relationships and communicating effectively across departments is essential, as much of the role involves influencing others and ensuring risk management practices are integrated into daily operations.

What is operational risk?

Operational risk refers to the potential for losses resulting from inadequate or failed internal processes, people, systems, or external events. Unlike credit or market risk, operational risk is related to the day-to-day operations of a business and can include issues such as fraud, system failures, natural disasters, or human error. Managing operational risk is essential for organizations to ensure business continuity, regulatory compliance, and to protect their reputation and assets.

What are the 4 operational risks?

Operational risk in the context of operational risk roles refers to the potential for loss resulting from inadequate or failed internal processes, people, systems, or external events. The four main types are process risk, people risk, systems risk, and external event risk. Managing these risks involves implementing controls, monitoring, and compliance measures to minimize impact.

What is the highest paying risk management job?

The highest paying risk management roles are often senior positions such as Chief Risk Officer (CRO) or Director of Risk Management, with salaries exceeding $200,000 annually. These roles require extensive experience, advanced certifications like FRM or PRM, and strong leadership skills in overseeing enterprise-wide risk strategies.

What is an operational risk job?

An operational risk job involves identifying, assessing, and managing risks arising from internal processes, people, systems, or external events that could disrupt business operations. Professionals in this field analyze data, develop risk mitigation strategies, and often use tools like risk management software to ensure organizational stability and compliance.

What is the difference between Operational Risk vs Credit Analyst?

AspectOperational RiskCredit Analyst
Required CredentialsCertifications like FRM, PRM often preferredCertifications such as CFA, credit-specific courses
Work EnvironmentBanking, financial institutions, risk management departmentsBanking, lending institutions, financial services
Employer & Industry UsageUsed across financial sectors to manage risksUsed in lending to assess creditworthiness
Comparison Search IntentUnderstanding risk management rolesAssessing credit risk and loan eligibility

Operational Risk focuses on identifying and mitigating risks within business operations, including processes, systems, and people. Credit Analysts evaluate the creditworthiness of individuals or companies to determine loan eligibility. While both roles are within the financial industry, Operational Risk professionals concentrate on risk management frameworks, whereas Credit Analysts focus on credit assessment and lending decisions.

Is risk advisory a good career?

Risk advisory is a viable career path within the broader field of operational risk management, focusing on identifying and mitigating organizational risks. It often requires strong analytical skills, knowledge of industry regulations, and certifications such as FRM or CRM. The role offers opportunities for advancement and specialization in areas like compliance, cybersecurity, and financial risk.

What are the key skills and qualifications needed to thrive as an Operational Risk professional, and why are they important?

To thrive as an Operational Risk professional, you need strong analytical skills, risk assessment expertise, and a background in finance, business, or risk management, often supported by relevant certifications such as FRM or ORM. Familiarity with risk management frameworks, data analysis tools, and governance, risk, and compliance (GRC) systems is typically required. Exceptional communication, attention to detail, and problem-solving abilities are crucial soft skills for identifying risks and collaborating across departments. These skills ensure that operational risks are effectively identified, assessed, and mitigated, protecting the organization from potential losses and regulatory issues.
What are the most commonly searched types of Operational Risk jobs in Phoenix, AZ? The most popular types of Operational Risk jobs in Phoenix, AZ are:
What are popular job titles related to Operational Risk jobs in Phoenix, AZ? For Operational Risk jobs in Phoenix, AZ, the most frequently searched job titles are:
Infographic showing various Operational Risk job openings in Phoenix, AZ as of July 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $85,231 per year, or $41 per hour.
Technology Risk Director- CyberSecurity

Technology Risk Director- CyberSecurity

Citizens

Phoenix, AZ โ€ข On-site

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 23 days ago


Job description

Description

As a First Line of Defense Cybersecurity Risk Director within the Enterprise Technology Security (ETS) Risk organization, you will provide strategic leadership in protecting the organization against evolving cyber threats while enabling business innovation. This role is accountable for the design, execution, and continuous maturity of the cybersecurity risk management framework, ensuring cyber risks are proactively identified, assessed, mitigated, monitored, and transparently reported.ย  You will serve as a trusted advisor to senior leadership, translating complex cybersecurity and technology risks into clear business impacts and risk-based decisions aligned to enterprise risk appetite. The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and business leaders to ensure cybersecurity risk strategies are fully integrated with business objectives, regulatory expectations, and enterprise resilience goals.ย  You will also lead and develop a high performing team of cybersecurity risk professionals, fostering a culture of strong risk discipline, constructive challenge, and continuous improvement across the organization.

Key Responsibilities

Leadership & Strategy

  • Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise.
  • Define and evolve the cybersecurity risk management strategy and operating model, ensuring alignment with enterprise risk appetite, regulatory requirements, and business priorities.
  • Translate cyber and technology risks into business relevant impacts, enabling senior management to make informed, risk-based decisions.

Cybersecurity Risk Management & Oversight

  • Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and monitoring of cyber and technology risks.
  • Define and maintain key risk indicators (KRIs), controls, and control testing strategies to measure cybersecurity risk exposure and control effectiveness.
  • Provide oversight of Risk and Control Self Assessments (RCSAs), Targeted Risk Reviews, business initiative risk assessments, and issue management, ensuring timely remediation and sustainable risk reduction.
  • Maintain visibility into detailed cyber risk assessments, advising business and technology leaders on prioritized mitigation strategies and risk tradeoffs.

Business Partnership & Advisory

  • Act as a strategic risk advisor to business lines and technology leaders, providing day to day guidance on regulatory compliance, risk mitigation, and industry best practices.
  • Advise on new products, processes, technologies, and strategic initiatives, ensuring appropriate risk identification, control design, and governance approvals are in place.
  • Guide business partners through enterprise governance forums and approval processes, ensuring cyber risks are understood, documented, and appropriately managed.

Regulatory, Audit & External Engagement

  • Serve as the primary risk lead for regulatory exams and audits related to cybersecurity and technology risk for assigned products or functions.
  • Partner with Internal Audit, and second line stakeholders, leading exam preparation, responses, and ongoing issue remediation.
  • Ensure compliance with applicable laws, regulations, and supervisory guidance, including FFIEC, GLBA, SOX, and other relevant standards.

Collaboration & Stakeholder Management

  • Build and maintain strong, trusted relationships with business partners, technology leaders, security teams, project stakeholders, and subject matter experts.
  • Collaborate across lines of defense to provide effective challenge while enabling responsible innovation and delivery.
  • Promote a culture of cybersecurity awareness and operational resilience across the organization.

Qualifications - Experience & Skills

  • 10+ years of experience in Cybersecurity and/or Information Technology, with deep exposure to enterprise environments.
  • 10+ years of risk management experience within financial services, preferably in cybersecurity, technology risk, or operational risk.
  • Strong experience with cloud technologies (IaaS, PaaS, SaaS), DevSecOps, web applications, operating systems, databases, and networking.
  • Broad knowledge of cybersecurity domains including:
    • Network and infrastructure security
    • Vulnerability and configuration management
    • Identity and Access Management including Customer Identity
    • API and application security
    • Data protection and cryptography
    • Operational resilience
    • Incident, problem, and change management
  • Experience operating in a highly regulated environment under significant supervisory scrutiny.
  • Solid understanding of internal controls, risk assessments, and governance processes.
  • Working knowledge of FFIEC guidance, GLBA, SOX, and related regulatory frameworks.
  • Familiarity with leading industry frameworks, including Cybersecurity Risk Institute, NIST Cybersecurity Framework, Cloud Security Alliance, NIST 800 53, and ISO 27001.
  • Demonstrated ability to synthesize complex risk data, prioritize mitigation actions, and influence outcomes.
  • Exceptional communication and executive presence skills, with the ability to engage all levels of the organization.
  • Proven leadership, coaching, and talent development experience.
  • Strong project and program management capabilities across multiple stakeholders.

Education & Certifications (Preferred)

  • Bachelor's Degree required; Master's Degree preferred.
  • Professional certifications strongly preferred, including:
    • Certified Information Systems Security Professional (CISSP)
    • Certified Cloud Security Professional (CCSP)
    • Cloud security specialty certification in AWS and Azure
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)
    • Certified in Risk and Information Systems Control (CRISC)

Hours & Work Schedule

  • Hours per Week: 40
  • Work Schedule: Monday-Friday
  • Hybrid: 4 days onsite, 1 day remote

Pay Transparency

The salary range for this position is $190,000 - $240,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to the work location, and relevant skills and experience.

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens' paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits .

#LI-Citizens1

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Education:Why Work for UsEmployment Type: 1ST