About the Role
The Vice President, Head of Enterprise Risk Management (ERM) is a senior leadership role responsible for designing, implementing, and continuously maturing the Credit Union’s enterprise risk management framework. This role provides strategic oversight across all risk disciplines, including ERM, Compliance, Business Continuity Planning (BCP), and Vendor Risk Management. The VP will lead the organization’s efforts to identify, assess, monitor, and mitigate risks across all NCUA risk categories, while ensuring alignment with regulatory expectations, industry best practices, and organizational strategy. A critical component of this role is strong expertise in technology and IT-related risks, including cybersecurity, data governance, and IT compliance.
Responsibilities
- Lead the development, implementation, and ongoing enhancement of a formal Enterprise Risk Management (ERM) framework aligned with regulatory expectations and industry standards (e.g., COSO ERM Framework).
- Establish a holistic risk management approach that integrates risk awareness into strategic planning and operational decision-making.
- Provide enterprise-wide oversight of risk identification, assessment, mitigation, and monitoring activities.
- Maintain oversight across all seven NCUA risk categories, including Credit Risk, Interest Rate Risk, Liquidity Risk, Operational Risk, Compliance Risk, Strategic Risk, and Reputation Risk.
- Ensure risks are effectively assessed, documented, and managed across all business units.
- Design and oversee the Enterprise Risk Assessment program to identify emerging and top organizational risks.
- Lead the implementation and ongoing enhancement of Risk and Control Self-Assessments (RCSA) across the organization.
- Ensure consistency, quality, and reliability of risk assessments across business lines.
- Partner with business leaders to strengthen control environments and risk mitigation strategies.
- Develop, refine, and maintain the organization’s Risk Appetite Framework, ensuring alignment with strategic objectives and board expectations.
- Establish and monitor Key Risk Indicators (KRIs) and thresholds to proactively manage risk exposure.
- Provide actionable insights and early warning signals to executive leadership.
- Deliver comprehensive, timely, and insightful risk reporting to executive management.
- Establish strong risk governance structures, including policies, committees, and escalation protocols.
- Ensure transparency and clarity regarding risk exposure, trends, and emerging risks.
- Oversee the Compliance function, ensuring adherence to applicable laws, regulations, and regulatory guidance.
- Maintain strong regulatory relationships and support regulatory examinations and audits.
- Ensure integration of compliance risk into the broader ERM framework.
- Provide executive oversight of Business Continuity and Disaster Recovery programs.
- Ensure organizational resilience through robust continuity planning, testing, and response capabilities.
- Oversee crisis management frameworks and incident response coordination.
- Oversee the Third-Party/Vendor Risk Management program, ensuring appropriate due diligence, risk assessment, and ongoing monitoring.
- Ensure compliance with regulatory expectations related to third-party risk management.
- Evaluate concentration risk, critical vendor dependencies, and operational resilience risks.
- Serve as a key leader overseeing technology-related risks, including Cybersecurity Risk, Information Security, Data Privacy & Governance, and Cloud & Third-Party Technology Risks.
- Partner with IT and Information Security leadership to ensure robust risk identification and mitigation practices.
- Ensure compliance with relevant regulatory guidance and frameworks (e.g., FFIEC guidance, NCUA expectations).
- Translate complex technical risks into clear business and executive-level insights.
- Lead, mentor, and develop a multi-functional risk team spanning ERM, Compliance, Business Continuity Planning (BCP), and Vendor Risk Management.
- Foster a strong risk culture across the organization through training, communication, and leadership.
- Serve as a trusted advisor to executive leadership on all risk-related matters.
- Collaborate cross-functionally with Finance, IT, Internal Audit, and business units.
Requirements
- Bachelor’s degree required
- Advanced degree preferred (e.g., MS in Risk Management or related field)
- 12–15+ years of progressive experience in risk management, compliance, or related fields within financial services (credit union or banking experience strongly preferred)
- 10–15 years of experience in senior leadership roles
Skills
- Deep knowledge of enterprise risk management frameworks (e.g., COSO ERM)
- Strong understanding of NCUA regulations and supervisory expectations
- Demonstrated expertise in Risk Appetite Frameworks & KRIs, RCSA Programs & Enterprise Risk Assessments, and Risk Governance & Reporting
- Strategic thinking with strong execution capabilities
- Exceptional communication and relationship management skills
- Proven ability to build and mature risk programs within a dynamic environment
- Strong analytical, problem-solving, and decision-making capabilities
- High integrity and sound judgment
Location
- San Francisco
Experience Level
- 12–15+ years of progressive experience
- 10–15 years of experience in senior leadership roles
Education Level
- Bachelor’s degree required
- Advanced degree preferred (e.g., MS in Risk Management or related field)
Salary/Compensations
- Annual salary of $156,000 to $234,000
Benefits
- Competitive compensation and benefits package
- 401(k) and Employer Match
- Health, Vision, Dental and Life Insurance
- Annual Incentive/Bonus Program
- Tuition Reimbursement Program
- 11 Paid Holidays + Competitive PTO package
- Home & Consumer Loan Program (Discounted Rates)
- Professional development and training programs
- On-demand personal coaching resource
- Wellness Program (Discounted Gym Membership)
About the Company
- SF Fire Credit Union first opened its doors in 1951 from a modest 10′ × 15′ office space in 17 Engine.
- The San Francisco-based credit union has grown to $1.7B in assets and a membership that extends from regional firefighters throughout many neighbors in San Francisco, San Mateo and Marin Counties.
- Members benefit from shared trust, continuous innovation of products and services, competitive rates, and excellent member service.
- Values: Be Personal, Be a Leader, Be Outside the Box, Be Real, Be the Connection.
- Culture: default to trust, embrace feedback, desire to innovate.
- Vision: empower members to accomplish their dreams and build lasting financial security.
- Work environment: feels like a big family, values good sense of humor, motivated by higher purpose, 'in-this-together' attitude, values work/life balance.
- Relatively small organization at about 200 employees.
Equal Opportunity
- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
