Information Technology Enterprise Risk Manager
northwest · Pittsburgh
Job description
About the role
The Information Technology Enterprise Risk Manager works within Northwest's Risk Management organization to oversee the operational risk framework for IT, information security, and data. The role embeds risk awareness into strategic and operational decisions across the enterprise.
Key responsibilities
- Provide oversight of Risk and Control Self‑Assessment (RCSA) activities for technology processes, challenging conclusions and monitoring outcomes.
- Independently assess risks, drive root‑cause remediation, and validate first‑line control testing for IT, IS, and data controls.
- Partner with IT, IS, and Data teams to mature second‑line risk assessments, document controls, identify gaps, and create action plans for critical processes.
- Support key assessments such as GLBA, PCI‑DSS, HIPAA, and authentication/access reviews, providing credible challenge of methodologies and results.
- Consult with the first line on issue creation, monitor remediation progress, and ensure timely closure of control gaps.
- Develop and track metrics to quantify technology risks and review action plans for deficient metrics.
- Analyze business losses related to IT failures, determine lessons learned, and recommend future risk avoidance strategies.
Required profile
- Bachelor’s degree in Management Information Systems, Cybersecurity, or Business Administration.
- 8‑12 years of cybersecurity/IT experience plus 6‑8 years in a financial institution.
- Deep understanding of IT, information security, and data principles and best practices.
Required skills
- ITIL certification.
- Certified Information System Auditor (CISA).
- Certified Information Security Manager (CISM).
- Certified Risk and Information Systems Control (CRISC).
- Certified Information Systems Security Professional (CISSP).
- Experience with vulnerability scanning and penetration testing tools.
- Proficiency in risk management methodologies and RCSA execution.
- Knowledge of compliance frameworks such as NIST CSF, GLBA, PCI‑DSS, and HIPAA.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 11 hours ago
Expires 1 month from now
6 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
northwest
Pittsburgh