About the Role
Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managed consistent with enterprise risk appetite, regulatory expectations, and sound industry practice.
Responsibilities
- Provide independent review, oversight, and credible challenge of first-line technology risk management activities, controls, and decisions.
- Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards.
- Provide independent challenge and oversight of risk identification and assessment activities.
- Review and challenge risk and control self-assessments, issues management, remediation plans, control validation outcomes, and key risk indicators.
- Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events.
- Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness.
- Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees.
- Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements.
- Provide ongoing risk advisory support while maintaining second-line independence and accountability for effective challenge.
- Recommend opportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity.
- Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
- Provide independent challenge and oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains.
- Provide independent challenge and oversight of information security risk management practices across threat management, network, endpoint, cloud, architecture, data, access, AI, or application security domains.
- Assess alignment of technology risk and control activities to enterprise policies, risk frameworks, and applicable industry standards.
- Evaluate whether risk assessments, control inventories, issues management, and key risk indicators are executed consistently and effectively across the technology organization.
- Challenge risk identification activities related to significant technology changes, new products or capabilities, and cross-functional initiatives.
- Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed.
Requirements
- Typically has 12 years of experience or demonstrated portfolio consistent with experience required of the role in technology risk, information security, operational risk, or related disciplines within a regulated or otherwise complex operating environment.
- Strong understanding of risk management practices, control frameworks, and second-line oversight within a three lines of defense model.
- Demonstrated experience providing independent review, challenge, or governance of first-line technology, security, data, or operational risk activities.
- Strong ability to assess control design and effectiveness, synthesize risk data, identify themes, and translate technical issues into business risk.
- Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross-functional partners.
- Strong critical thinking, judgment, and problem-solving skills, with the ability to provide practical, risk-based recommendations in a complex environment.
- Ability to operate independently, manage competing priorities, and maintain effective working relationships while preserving second-line objectivity.
- Background and drug screen.
Skills
- Technology risk
- Information security
- Operational risk
- Risk management practices
- Control frameworks
- Second-line oversight
- Three lines of defense model
- Control design and effectiveness assessment
- Risk data synthesis
- Problem-solving
- Stakeholder management
- Critical thinking
- Judgment
- ISO 27002
- PCI DSS
- NIST
- FFIEC
- SOC 2
- CISA
- CISM
- CISSP
- CCSP
- CRISC
- GSNA
- CGIH
Location
- Scottsdale
- San Francisco
- Chicago
- New York
- Phoenix, AZ
- Washington, DC
Work Type
- Hybrid
Experience Level
- 12 years of experience
Education Level
- Bachelor’s degree or equivalent
- Advanced degree or additional related education and/or experience preferred
Salary/Compensations
- $184,000 - $230,000 (Phoenix, AZ/ Chicago, IL / Washington, DC)
- $221,000 - $276,000 (New York, NY/ San Francisco, CA)
Benefits
- Discretionary incentive plan
- Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans
- Company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
- 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
- Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
- 12 weeks of Paid Parental Leave
- Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
About the Company
- At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more.
- As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Equal Opportunity
- Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
- Early Warning Services, LLC (“Early Warning”) considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.
