Director Cybersecurity Operational Risk Oversight

Citizens Bank

Westwood (MA)

On-site

USD 178,000 - 220,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental and vision coverage
Retirement benefits
Education reimbursement
Flexible work arrangements

Job summary

Citizens Bank seeks a Director of Operational Risk Management Oversight - Cybersecurity Risk to provide independent oversight, review, and challenge of cybersecurity risks and collaborate with stakeholders across the enterprise to ensure risks are well defined and managed.

The role leads a small team, advises risk partners, and interacts with all three lines of defense and regulators. It requires strong leadership, regulatory awareness, and expert cybersecurity knowledge.

Qualifications

  • 8 years demonstrated cybersecurity domain expertise.
  • 4 years risk management experience in financial services.
  • Expert knowledge of cybersecurity risks and controls.
  • Experience in an organization with strong regulatory oversight.

Responsibilities

  • Lead a team of three for independent oversight, review, and challenge of cyber risk programs.
  • Advise first line risk partners on complex issues and drive remediation actions.
  • Understand external environment and regulatory priorities affecting risk.
  • Participate in cybersecurity incident response and post-incident analysis.
  • Lead targeted risk assessments on emerging issues with independent opinion.
  • Manage governance, policy, and program assurance across the enterprise.

Skills

Cybersecurity domain expertise
Risk management
Executive relationship building
Leadership and team development
Influencing and conflict resolution
Business writing
MS Office (Word/Excel/PowerPoint/Visio

Education

Bachelor's degree
CISSP
CISM
CISA
CRISC

Tools

MS Visio
PowerPoint

Job description

As the Director of Operational Risk Management Oversight - Cybersecurity Risk, you will provide independent oversight, review, and challenge of cybersecurity related risks and collaborate with key stakeholders across the enterprise ensuring material risks within these groups are well defined and managed appropriately.

Primary responsibilities will include:

  • Leading a team of three in independent oversight, review, and challenge of risk management activities within the cybersecurity first line of defense.This includes evaluating the effectiveness of their formal risk program activities including but not limited to:Risk and Control Self-Assessments, issues management, controls management, new business initiative risk assessments.
  • Serving as an advisor to first line risk partners on complex risk issues and challenges, while identifying and assessing aggregate enterprise-wide risks.Collaborating with key stakeholders, including all three lines of defense, escalating emerging risk issues that require remediation and working directly with stakeholders while driving accountability.Maintaining strong relationships with all three lines of defense, as well as the regulatory agencies.
  • Understanding the external environment, including emerging risks within the industry and the priorities of the regulatory agencies. Determining how these changes affect the risk profile of the enterprise and working with appropriate stakeholders to ensure mitigation strategies are underway.
  • Participating in the cybersecurity incident response activities to ensure risks are accurately assessed in real time and mitigating actions are appropriate.Post incident, leading or participating in root cause analysis and opining on next steps.
  • Leading targeted risk assessments on emerging issues to provide an independent opinion on the impact on the enterprise.
  • Operating within existing governance structures with an eye towards making these processes more efficient and effective.Managing applicable policy and program governance, while performing assurance activities to assess corporate wide compliance.
  • The role may be co-located as needed with the relevant business and must be actively engaged to support the business with providing domain-relevant advice, monitoring, and credible expert challenge to ensure the independent Operational Risk Management Program is effectively implemented.

Required Experience, Skills and Competencies:

  • 8 years demonstrated cybersecurity domain expertise
  • 4 years risk management experience from working in the financial services industry
  • Expert knowledge of cybersecurity risks and controls
  • Experience in a financial services organization that is under strong regulatory oversight and scrutiny
  • Ability to develop and maintain high impact relationships with senior executives
  • History of developing and leading a team
  • Decisiveness and sound judgment on a consistent basis
  • Capacity to challenge status quo
  • Influencing and conflict resolution skills
  • Excellent business writing skills
  • Proven leadership and management skills in a professional environment
  • Proficient use of MS Word, MS Excel and PowerPoint and Visio

Education

  • Bachelor’s degree Required
  • Certifications Preferred: CISSP, CISM, CISA, Certified in Risk and Information System Control or other relevant risk certifications

Hours and Work Schedule

Hours per Week: 40

Work Schedule: Monday-Friday

Pay Transparency

The salary range for this position is $178,000 - $220,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to budget, the work location, and relevant skills and experience.

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Equal Employment and Opportunity Employer

Job Applicant Data Privacy Policy

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Director, Regulatory Practices - Enterprise Services Risk Operations
Director, Regulatory Practices - Enterprise Services Risk Operations

Information Technology Senior Management Forum • McLean (VA)

On-site
USD 230,000 - 263,000
Director, Regulatory Practices - Enterprise Services Risk Operations
Director, Regulatory Practices - Enterprise Services Risk Operations

Capital One • Richmond (VA)

On-site
USD 210,000 - 239,000
Director, Regulatory Practices - Enterprise Services Risk Operations
Director, Regulatory Practices - Enterprise Services Risk Operations

Capital One National Association • McLean (VA)

On-site
USD 230,000 - 263,000
Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens Bank • Johnston (RI)

Hybrid
USD 90,000 - 120,000
Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens • Johnston (RI)

Hybrid
USD 80,000 - 120,000
Career growth opportunities
Collaborative work environment
Director, Regulatory Practices - Enterprise Services Risk Operations
Director, Regulatory Practices - Enterprise Services Risk Operations

Capital One Group • McLean (VA), Northern (KY)

Hybrid
USD 230,000 - 263,000
First Line Risk Sr Analyst
First Line Risk Sr Analyst

Citizens Bank • Boston (MA)

Hybrid
USD 80,000 - 85,000
Medical, dental and vision coverage
Retirement benefits
Flexible work arrangements
+1
Director, Risk Management: Cyber & Third Party Risk
Director, Risk Management: Cyber & Third Party Risk

Capital One National Association • McLean (VA)

On-site
USD 230,000 - 263,000
Director, Integrated Security
Director, Integrated Security

Cornerstone Capital • Houston (TX), Northern (KY)

Hybrid
USD 150,000 - 210,000
Full benefits package
Bonus potential