Information Technology Enterprise Risk ManagerThe Information Technology Enterprise Risk Manager within the Risk Management organization is responsible for supporting the execution and oversight of Northwest's Operational Risk framework as it relates to information technology, information security and data risks.
This role will adapt previous experience and industry leading practices to identify, assess, monitor, and report key technology risks, helping to embed risk awareness into strategic and operational decision-making.
This role will help to support activities including, but not limited to, Risk and Control Self-Assessments (RCSA), risk management training, issues management, risk management and policy and procedure governance.Essential FunctionsProvide oversight of the Risk and Control Self-Assessment (RCSA) activities within technology-related processes, performing credible challenge of the conclusions derived from the RCSA, and monitoring routinesIndependently assess risks and drive actions to address the root causes that persistently lead to significant residual operational risk by challenging both historical and proposed practicesValidate the first line's control testing and independently test the first line's information technology, information security and data controls to verify the design and operational effectivenessLeverage the current Enterprise Risk Management framework and partner with IT, IS and Data teams to further mature the second line of defense technology and information security risk assessments, document controls, identify gaps, and create action plans for critical IT processes, including validation and testing to ensure IT risk programs are implemented and executed appropriatelyProvide support to key risk assessments and perform credible challenge of methodologies and results, including the annual Gramm-Leach-Bliley Act (GLBA) Assessment, Authentication and Access Assessments, Payment Card Industry Data Security Standard assessment and HIPAA complianceConsult with the first line on the creation of issues to address control gaps/failures and monitor the progress of remediation, ensuring timely and accurate mitigation, and providing credible challenge to support the timely closure of issuesSupport the establishment of metrics to quantify and measure technology risks and provide review and challenge to the action plans of deficient metricsPerform oversight of the front-line's management of IT/IS/Data activities and exception handling, including the documentation of IT changes, end-of-life technology, resiliency enhancements and testing, business impact analysis, vulnerability management, completion of action items related to addressing technology failures and disruptions, CDEs and data rulesProvide credible challenge of the first line's IT/IS/Data policies and standards ensuring compliance under Northwest's corporate governance requirementsAnalyze losses in the Business associated with IT failures, disruptions and errors to understand how losses were incurred, determined lessons learned, identify root causes and developing recommendations for future risk avoidanceAdditional Essential FunctionsEnsure compliance with Northwest's policies and procedures, and Federal/State regulationsNavigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiencyWork as part of a teamWork with on-site equipmentWhat You Bring to the TeamAdditional job duties as assigned by managementQualificationsBachelor's Degree Degree in Management Information Systems, Cybersecurity, or Business Administration8 - 12 years Cybersecurity/information technology experienceAnd 6 - 8 years Prior financial institution experienceDeep understanding of information technology, information security and data principles and best practicesProficient in risk management methodologies, frameworks, and execution of the Risk and Control Self-Assessment (RCSA)Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)Experience with vulnerability scanning and penetration testing toolsStrong analytical and problem-solving skillsExcellent communication and reporting abilitiesLicenses and CertificationsInfrastructure Library (ITIL) Certified Information System AuditorCertified Information Security Manager (CISM)Certified Risk and Information Systems ControlCertified Information Systems Security Professional (CISSP)Northwest is an equal opportunity employer.
We are committed to creating an inclusive environment for all employees.