Chief Cyber Risk & Security Oversight Leader

Fayette Chamber of Commerce

Atlanta (GA)

On-site

USD 300,000 - 400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
Life insurance
Disability insurance
401k plan
Paid vacation
Paid sick days
Paid holidays

Job summary

Truist Financial Corporation in Atlanta, GA is seeking a Chief Cybersecurity Risk Officer (CCRO) to provide comprehensive risk oversight of the cybersecurity organization. Reporting to the CIRO, this senior executive will lead cyber risk oversight across all cybersecurity functions and interact with the Board on residual risk and regulatory matters.

The CCRO will establish risk appetite, oversee independent assessments, and challenge technology initiatives to align with risk tolerance.

Qualifications

  • 1. Bachelor’s degree in computer science, Information Systems, or data/technology related field; MBA preferred.
  • 2. Fifteen+ (15+) years of progressive experience in cybersecurity relevant roles within a Category 2 or 3 Large Financial Institution (LFI) with a deep understanding of regulatory requirements for complex financial services organization (including both Federal Reserve and FDIC regulations). In depth understanding of how data is captured, transformed, and used and the ability to connect end-to-end processes independently.
  • 3. Fifteen+ (15+) years of experience or equivalent proficiency in managing people with demonstrated high competency in recruiting, developing, and coaching/mentoring.
  • 4. Fifteen+ (15+) years of experience in a financial institution with emphasis on risk management or equivalent work experience.
  • 5. Extensive knowledge on information security, cyber risk, core technology infrastructure, cloud operations, and technology operations.
  • 6. Experience in leveraging modern tools to measure effective of technology and cyber controls.
  • 7. Experience with enterprise architecture, reference architectures and emerging technologies.
  • 8. Knowledge of key technology rules/regulations and technology risk management practices (e.g. FFIEC, COBIT, NIST, ITIL).
  • 9. Excellent leadership skills including the ability to lead direct and indirect reports, including executive level leaders.
  • 10. Excellent communication (verbal and written), presentation and facilitation skills; ability to influence and communicate with impact with C-suite executives and board members. This includes the ability to translate technical concepts for various audiences.
  • 11. Excellence in building and leading high-performing teams.

Responsibilities

  • 1. Strategic Leadership: Develop and maintain the enterprise technology management framework, incorporating emerging risks related to cyber security. Establish risk appetite statements, key risk indicators, and thresholds for cyber security across the organization. Provide independent assessment and challenge of cyber security initiatives, ensuring alignment with risk appetite and regulatory expectations. Lead the evaluation of strategic cyber security decisions and their impact on the organization’s risk profile.
  • 2. Risk Leadership: Provide independent risk oversight (i.e., second line of defense/LOD2) for Truist Protection Services (TPS) through the effective identification, mitigation, monitoring and reporting of operational, technology and compliance related risks within Core Technology and Cyber. This role includes independently challenging LOD1 self-assessments and providing effective challenges of CCS to ensure applicable risk types remain within our stated risk appetite.
  • 3. Governance and Oversight: Serve as a non-voting member of the first line owned Technology, Data and Operations risk committee, a voting member of the CIRO led risk committee and actively participate in the Enterprise and Board Risk Committees (BRC). This includes (a) reviewing and effectively challenging technology and data risk policies, standards, and procedures, (b) overseeing the assessment and monitoring of critical technology vendors and third-party service providers, and (c) ensuring compliance with regulatory requirements and supervisory guidance related to cybersecurity risk.
  • 4. Risk Assessments: Define, communicate and drive the Cyber Risk Frameworks and direct the assessment of information security and cyber risk. Provide independent assessment and oversight of the maturity of CCS and adequacy of cybersecurity controls in meeting agreed business outcomes for cybersecurity. Assessments should leverage agreed upon metrics produced by Business Units (LOD1), but challenge and validated as appropriate.
  • 5. Risk Continuous Monitoring: Oversee the evaluation of the cybersecurity strategy and operations for potential risks and biases. Furthermore, monitor the cybersecurity project portfolios, developmental methodologies and progress on project milestones. Lead the review of significant cyber incidents and direct remediation efforts to remediate incident root causes. Using monitoring routines to identify emerging risk and/or consider accelerate risk reviews of technology policies/standards, business processes or control assessments.
  • 6. Risk Reporting: Design the standard recurring reporting packages for Cyber Security to support ongoing reporting of identification, mitigation, monitoring of material risks. These reporting packages will be used for internal discussions and/or governance reporting.
  • 7. Regulatory Engagement Oversight: Serve as the primary risk point of contact with regulators on cyber risk matters. This includes presenting regular risk assessments and updates to the Board and external stakeholders and collaborating with Truist Audit Services (TAS) / external auditors on cybersecurity reviews. Additionally, this role should provide effective challenge and validation procedures on all regulatory remediations where management actions are being reviewed and validated for closure.
  • 8. Talent Management: Lead, manage and develop teammates directly and indirectly. Leverage industry insights to influence enterprise technology talent management through recommendations to Truist senior leadership to inform decisions on resource allocations (both competence and capacity). Where needed, encourage and facilitate Cybersecurity Risk education series, skills training, and industry participation in conference to elevate competence of the risk teammates and enable risk management to meet its objectives of maintaining a strong stature and influence with the company.
  • 9. Risk Culture: Promote the culture of Risk Management across the organization by empowering risk teammates to embrace leadership direction, identify risk exposure in everyday operations and champion improving the enterprise programs for building a sustainable business model, meeting the objectives outlines by leadership and the Board of Directors.

Skills

Leadership
Communication
Regulatory knowledge
Cyber risk management
Executive collaboration

Education

Bachelor’s degree in computer science or information systems
MBA preferred

Tools

FFIEC knowledge
COBIT knowledge
NIST knowledge
ITIL knowledge

Job description

Truist Financial Corporation in Atlanta, GA is seeking a Chief Cybersecurity Risk Officer (CCRO) to provide comprehensive risk oversight of the cybersecurity organization. Reporting to the CIRO, this senior executive will lead cyber risk oversight across all cybersecurity functions and interact with the Board on residual risk and regulatory matters.

The CCRO will establish risk appetite, oversee independent assessments, and challenge technology initiatives to align with risk tolerance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Cyber Risk & Assurance Officer
Chief Cyber Risk & Assurance Officer

Truist • Richmond (VA)

On-site
USD 300,000 - 400,000
Senior Cyber Risk Oversight Executive
Senior Cyber Risk Oversight Executive

Truist • Greensboro (NC)

On-site
USD 300,000 - 400,000
Medical, dental, vision insurance
401(k) plan
Paid vacation & sick leave
Strategic Cyber Risk Executive – Board‑level Oversight
Strategic Cyber Risk Executive – Board‑level Oversight

Truist • Raleigh (NC)

On-site
USD 300,000 - 400,000
Medical, dental, vision benefits
401(k) with company match
Paid time off
Strategic Cyber Risk & Oversight Leader
Strategic Cyber Risk & Oversight Leader

Truist • Charlotte (NC)

On-site
USD 300,000 - 400,000
Medical, dental, vision
401(k) plan
Paid vacation & sick days
Senior Cyber Risk Officer — Second‑Line Oversight
Senior Cyber Risk Officer — Second‑Line Oversight

Habitat For Humanity Of Durham • Raleigh (NC)

On-site
USD 300,000 - 400,000
Health benefits
Paid time off
401(k) plan
Chief Cyber Risk Officer: Security & Risk Oversight
Chief Cyber Risk Officer: Security & Risk Oversight

Truist • Atlanta (GA)

On-site
USD 300,000 - 400,000
Medical, dental, vision benefits
401k plan and retirement benefits
Paid time off and holidays
Chief Cybersecurity Risk Officer
Chief Cybersecurity Risk Officer

Truist • Charlotte (NC)

On-site
USD 300,000 - 400,000
Medical, dental, vision
401(k) plan
Paid vacation & sick days
Chief Cybersecurity Risk Officer
Chief Cybersecurity Risk Officer

Truist • Greensboro (NC)

On-site
USD 300,000 - 400,000
Medical, dental, vision insurance
401(k) plan
Paid vacation & sick leave
Chief Cybersecurity Risk Officer
Chief Cybersecurity Risk Officer

Truist • Atlanta (GA)

On-site
USD 300,000 - 400,000
Medical, dental, vision benefits
401k plan and retirement benefits
Paid time off and holidays
Chief Cybersecurity Risk Officer
Chief Cybersecurity Risk Officer

Truist • Raleigh (NC)

On-site
USD 300,000 - 400,000
Medical, dental, vision benefits
401(k) with company match
Paid time off