About the Role
Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managed consistent with enterprise risk appetite, regulatory expectations, and sound industry practice. May support one or more focus areas based on business need, including Enterprise Technology Risk, Data Security Risk, Access Management Risk, Offensive Security Risk, Vulnerability Management Risk, AI Security Risk, and Asset and Inventory Management Risk.
Responsibilities
- Provide independent review, oversight, and credible challenge of first-line technology risk management activities, controls, and decisions.
- Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards.
- Provide independent challenge and oversight of risk identification and assessment activities.
- Review and challenge risk and control self-assessments, issues management, remediation plans, control validation outcomes, and key risk indicators.
- Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events.
- Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness.
- Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees.
- Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements.
- Provide ongoing risk advisory support while maintaining second-line independence and accountability for effective challenge.
- Recommend opportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity.
- Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
- Provide independent challenge and oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains.
- Provide independent challenge and oversight of information security risk management practices across threat management, network, endpoint, cloud, architecture, data, access, AI, or application security domains.
- Assess alignment of technology risk and control activities to enterprise policies, risk frameworks, and applicable industry standards.
- Evaluate whether risk assessments, control inventories, issues management, and key risk indicators are executed consistently and effectively across the technology organization.
- Challenge risk identification activities related to significant technology changes, new products or capabilities, and cross-functional initiatives.
- Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed.
Requirements
- Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire.
- This position is ineligible for employment Visa sponsorship.
- Typically has 12 years of experience or demonstrated portfolio consistent with experience required of the role in technology risk, information security, operational risk, or related disciplines within a regulated or otherwise complex operating environment.
- Strong understanding of risk management practices, control frameworks, and second-line oversight within a three lines of defense model.
- Demonstrated experience providing independent review, challenge, or governance of first-line technology, security, data, or operational risk activities.
- Strong ability to assess control design and effectiveness, synthesize risk data, identify themes, and translate technical issues into business risk.
- Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross-functional partners.
- Strong critical thinking, judgment, and problem-solving skills, with the ability to provide practical, risk-based recommendations in a complex environment.
- Ability to operate independently, manage competing priorities, and maintain effective working relationships while preserving second-line objectivity.
- Background and drug screen.
Skills
- Technology risk management
- Information security
- Operational risk
- Risk assessments
- Issues management
- Control validation
- Key risk indicators
- Governance reporting
- Escalation
- Risk appetite
- Regulatory expectations
- Industry practice
- Enterprise Technology Risk
- Data Security Risk
- Access Management Risk
- Offensive Security Risk
- Vulnerability Management Risk
- AI Security Risk
- Asset and Inventory Management Risk
- Cybersecurity
- Cloud security
- Threat management
- Network security
- Endpoint security
- Architecture security
- Data security
- Access management
- AI security
- Application security
- ISO 27002
- PCI DSS
- NIST
- FFIEC
- SOC 2
- Project management
- Process management
Location
- Scottsdale
- San Francisco
- Chicago
- New York
- Phoenix, AZ
Work Type
- Hybrid
- Full-time
Experience Level
- 12 years of experience
Education Level
- Bachelor’s degree or equivalent
- Advanced degree or additional related education and/or experience preferred
Salary/Compensations
- $184,000 - $230,000 (Phoenix, AZ/ Chicago, IL / Washington, DC)
- $221,000 - $276,000 (New York, NY/ San Francisco, CA)
Benefits
- Discretionary incentive plan
- Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans
- Company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
- 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
- Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
- 12 weeks of Paid Parental Leave
- Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
About the Company
- At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more.
- As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
- Early Warning Services® delivers innovative payment and risk solutions to financial institutions nationwide.
- For over 25 years, Early Warning has been a leader in technology that helps protect and advance the financial system.
- We serve a diverse network of approximately 2,500 financial institutions, government entities and payment companies.
- Our product solutions enable real-time funds availability for a variety of payment types through our payments network.
Equal Opportunity
- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
- Early Warning Services, LLC (“Early Warning”) considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws.
- The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.
- Early Warning Services® aims to make our recruitment process accessible to any and all users. If you have a disability or a special need that requires accommodation to navigate our website or complete the application process, please email recruiting@earlywarningservices.com for an assistance request.
- View supplemental EEO is the law poster
- Early Warning has developed and maintains a written AAP and upholds pay transparency nondiscrimination.
- E-Verify Early Warning Services LLC is a proud participant in E-Verify, a federal program to help ensure a legal and authorized workforce.
- As part of our hiring process, we electronically verify the employment eligibility of all new hires through E-Verify.
- Privacy Notice Effective: June 4, 2026 This privacy notice is intended to inform California residents of the personal information we collect, how it’s used and disclosed, and the rights you have in regard to such information. Click below for the full privacy notice https://www.earlywarning.com/privacy-notice-employment-applicants
