Director, Technology Risk & Operational Resilience

First Command

Fort Worth (TX)

Hybrid

USD 180,000 - 280,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

First Command is seeking a Director of Technology Risk & Operational Resilience in Fort Worth, TX. This senior role leads technology risk, third-party risk management, and resilience programs, partnering with technology, security, operations, procurement, and legal to ensure clear risk ownership and effective remediation across critical services.

The candidate will build governance, monitor risk appetite, and present insights to executives and the Board while developing a high-performing team

Qualifications

  • Bachelor's degree in computer science, information systems, or related field; Master’s preferred.
  • 12+ years in technology/operational risk, cybersecurity risk, third-party risk, or resilience.
  • 5+ years leading enterprise-wide risk programs with staff.
  • Experience with regulated financial services and executive communication with leadership.
  • Proven ability to establish governance, reporting, and program maturity.

Responsibilities

  • Lead second-line technology risk, third-party risk management, and resilience teams.
  • Provide independent risk oversight of technology investments, cloud migrations, and critical services.
  • Oversee enterprise risk governance, regulatory engagement, and board reporting.
  • Develop risk appetite metrics, escalation thresholds, and governance frameworks.
  • Lead talent development and foster a culture of accountability and continuous improvement.

Skills

Executive communication
Risk management leadership
Strategic thinking
Influencing/negotiation
Synthesize complex information

Education

Bachelor's degree in CS/IS or related
Master's degree preferred

Tools

Risk management platforms
Data visualization tools
Microsoft 365

Job description

How will your role impact First Command?

The Director, Technology Risk & Operational Resilience is a senior leader within Enterprise Risk Management responsible for leading the Company’s technology risk, third-party risk management, and business resiliency teams and providing independent oversight and effective challenge of related first-line risk management activities. Reporting to the SVP, Chief Risk Officer, the Director establishes governance and risk oversight frameworks, monitors exposure against approved risk appetite and tolerances, evaluates interconnected and emerging risks, and provides decision-oriented insights to executive leadership and the Board.

The Director oversees enterprise risk practices related to technology, critical third parties, operational resilience, business continuity, crisis preparedness, and disaster recovery. The role partners with Technology, Information Security, Operations, Procurement, Legal, Compliance, Internal Audit, and business leadership to promote clear risk ownership, timely escalation, effective remediation, and resilience of critical business services.

What will the employee do in this role?

Technology Risk Oversight

  • Lead the second-line technology risk function and the enterprise third-party risk management and business resiliency teams, while providing independent oversight and effective challenge of first-line technology, cybersecurity, business continuity, crisis management, and disaster recovery capabilities.
  • Challenge first-line risk assessments, control activities, remediation plans, and risk acceptance decisions.
  • Provide independent risk oversight and effective challenge of material technology exposures, including cybersecurity, cloud services, data and technology dependencies, artificial intelligence, technology transformation, and end-of-life or unsupported platforms.
  • Provide an independent risk perspective on significant technology investments, architecture decisions, system implementations, cloud migrations, acquisitions, and material changes to critical services.
  • Evaluate technology risk exposures against approved risk appetite statements and tolerance thresholds.
  • Monitor emerging technology risks and industry trends and advise executive leadership on potential impacts to the organization.
  • Oversee technology risk metrics, key risk indicators (KRIs), and executive reporting.

Third-Party Risk Oversight

  • Lead the enterprise TPRM governance and oversight function, including risk-tiering standards, due diligence requirements, ongoing monitoring, issue escalation, reporting, and effective challenge of third-party risk decisions.
  • Define roles and accountability among business relationship owners, Procurement, Information Security, Legal, Compliance, and the TPRM function throughout the third-party lifecycle.
  • Provide independent challenge and oversight of vendor risk assessments, due diligence activities, ongoing monitoring, and remediation efforts.
  • Oversee risks associated with critical third-party service providers, strategic partners, cloud service providers, and outsourced business operations.
  • Monitor concentration risk, fourth-party risk, and critical supplier dependency risks.
  • Assess third-party risk management practices against regulatory expectations, industry standards, and organizational risk appetite.
  • Escalate material third-party risks and control weaknesses to executive leadership and governance committees.

Operational Resilience & Business Resiliency

  • Establish and oversee the enterprise operational resilience framework, including critical business services, key dependencies, disruption tolerances, and severe-but-plausible scenarios.
  • Lead the business resiliency and crisis preparedness program, including business impact analyses, continuity planning, exercises, and enterprise event readiness.
  • Provide independent oversight and effective challenge of Technology-owned disaster recovery strategies, recovery capabilities, testing results, and remediation plans.
  • Assess interconnected dependencies across people, processes, technology, facilities, data, and third parties.
  • Aggregate business continuity, disaster recovery, crisis management, and third-party resilience results into an enterprise view of operational resilience.

Risk Governance & Regulatory Engagement

  • Establish and maintain governance frameworks, policies, standards, and reporting processes supporting technology risk, third-party risk, and operational resilience.
  • Monitor compliance with applicable regulatory expectations and industry guidance, including banking, securities, insurance, and advisory regulations.
  • Support regulatory examinations, independent reviews, and internal and external audits.
  • Serve as a trusted advisor to the CRO on emerging risks, regulatory developments, and strategic risk implications.
  • Develop and maintain risk appetite metrics, escalation thresholds, and Board-level monitoring indicators.
  • Ensure material risk issues, emerging threats, and tolerance breaches are appropriately escalated.

Executive & Board Reporting

  • Prepare executive-level risk insights and presentations for management committees, executive leadership, the Risk Management Committee, and the Board of Directors.
  • Communicate trends, emerging risks, risk concentrations, resilience concerns, and program maturity assessments.
  • Provide independent risk perspectives on significant technology initiatives, acquisitions, vendor relationships, and strategic business initiatives.
  • Support enterprise risk reporting and integration of technology, third-party, and resilience risks into the broader ERM framework.

Leadership & Talent Development

  • Lead, mentor, and develop a high-performing team of risk professionals.
  • Establish performance objectives and professional development plans that enhance organizational capabilities.
  • Foster a culture of effective challenge, accountability, collaboration, and continuous improvement.
  • Drive maturity and capability enhancements across technology risk, third-party risk, and resilience disciplines.
Who will you lead?
  • Supervise all job activities of the IT risk management staff, including third-party risk management team, business resiliency team, and technology risk management team
What skills & qualifications do you need?
Education
  • Bachelor’s degree in computer science, Information Systems, or a related field; Master’s degree preferred
Work Experience
  • 12+ years of progressive experience across technology risk, operational risk, cybersecurity risk, third-party risk management, business continuity, disaster recovery, or operational resilience with demonstrated depth in multiple disciplines.
  • 5+ years of leadership experience managing enterprise-wide risk programs and professional staff.
  • Experience within a regulated financial services organization, including banking, wealth management, broker-dealer, advisory, insurance, or asset management businesses.
  • Demonstrated experience interacting with executive leadership, Board committees, regulators, and auditors.
  • Experience establishing or materially advancing risk frameworks, governance, reporting, and program maturity.
Preferred Certifications
  • Certified Information Systems Auditor (CISA); Certified Information Systems Security Professional (CISSP); Professional Risk Manager (PRM); Certified Risk Manager (CRM); Certification in Risk Management Assurance (CRMA); Certified in Risk and Information Systems Control (CRISC); Certified Information Security Manager (CISM)
Required Knowledge, Skills and Abilities
  • Demonstrated ability to provide credible, independent challenge while maintaining constructive relationships with senior leaders and first-line risk owners.
  • Ability to synthesize complex technology, third-party, and resilience information into clear risk conclusions and actionable executive insights.
  • Strong knowledge of technology risk, cybersecurity risk, operational resilience, third-party risk, business continuity, disaster recovery, and enterprise risk management principles.
  • Ability to evaluate interconnected risks and dependencies across legal entities, business lines, technologies, processes, facilities, and service providers.
  • Strong executive communication, governance, negotiation, and influencing skills.
  • Sound judgment in escalating material risks, tolerance breaches, control weaknesses, and unresolved remediation.
  • Demonstrated ability to lead specialized teams, establish priorities, manage capacity, and develop talent.
  • Ability to operate effectively in a complex, regulated, and evolving financial services environment.
  • Proficiency with risk management platforms, data visualization tools, and Microsoft 365 applications.

#LI-NC1 #LI-HYBRID

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Technology Risk & Operational Resilience
Director, Technology Risk & Operational Resilience

First Command Financial Services, Inc. • Fort Worth (TX)

On-site
USD 180,000 - 240,000
Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

BankUnited • Town of Florida (NY)

On-site
USD 150,000 - 210,000
Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

bankunitedexternal • Town of Florida (NY)

On-site
USD 140,000 - 210,000
Tech Risk & Controls - Executive Director
Tech Risk & Controls - Executive Director

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 180,000 - 260,000
First Line Operations Risk Advisor
First Line Operations Risk Advisor

synovuscareers • Atlanta (GA)

On-site
USD 120,000 - 160,000
Tech Risk & Controls Lead - Continuous Controls Monitoring
Tech Risk & Controls Lead - Continuous Controls Monitoring

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 120,000 - 180,000
Director, Cyber Risk
Director, Cyber Risk

Asurion • Nashville (TN)

On-site
USD 150,000 - 200,000
Tech Risk and Controls Lead - Infrastructure Platforms
Tech Risk and Controls Lead - Infrastructure Platforms

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 130,000 - 190,000
IP Tech Risk and Controls Director
IP Tech Risk and Controls Director

JPMorgan Chase & Co. • Kentucky

On-site
USD 180,000 - 280,000
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 240,000