Information Technology Enterprise Risk Manager

Northwest

Pittsburgh, Northern (Allegheny County, KY)

Hybrid

USD 110,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Northwest is seeking an Information Technology Enterprise Risk Manager to support the enterprise risk framework across technology, information security and data risks. This role will identify, assess, monitor and report key technology risks, embedding risk awareness into strategic and operational decision-making.

The position requires leading RCSA activities, testing controls, and collaborating with IT and Data teams to mature risk assessments while ensuring GLBA, HIPAA and PCI DSS compliance.

Qualifications

  • Experience leading IT risk and control assessments.
  • Familiarity with GLBA, HIPAA, PCI DSS and related regulations.
  • Strong analytical and reporting abilities.
  • Experience with RCSA processes.
  • Knowledge of IT governance and risk frameworks.

Responsibilities

  • Oversee RCSA activities for technology-related processes.
  • Validate IT/IS/Data controls and test effectiveness.
  • Partner with IT, IS and Data teams to mature risk assessments.
  • Support GLBA, HIPAA and PCI DSS assessments.
  • Provide credible challenge and remediation tracking.

Skills

IT risk management
RCSA
Information security
Data risk
Regulatory compliance
Threat & vulnerability

Education

Bachelor's Degree

Tools

NIST CSF
GLBA
PCI DSS
HIPAA
ITIL

Job description

## Information Technology Enterprise Risk ManagerApplylocations: Pittsburgh, PA: Columbus, OHtime type: Full timeposted on: Posted Yesterdayjob requisition id: R-102085OH0713 NW Bancshares HQ, PA0728 Pittsburgh Business Office**Job Description**The Information Technology Enterprise Risk Manager within the Risk Management organization is responsible for supporting the execution and oversight of Northwest's Operational Risk framework as it relates to information technology, information security and data risks. This role will adapt previous experience and industry leading practices to identify, assess, monitor, and report key technology risks, helping to embed risk awareness into strategic and operational decision-making. This role will help to support activities including, but not limited to, Risk and Control Self-Assessments (RCSA), risk management training, issues management, risk management and policy and procedure governance. **Essential Functions** • Provide oversight of the Risk and Control Self-Assessment (RCSA) activities within technology-related processes, performing credible challenge of the conclusions derived from the RCSA, and monitoring routines • Independently assess risks and drive actions to address the root causes that persistently lead to significant residual operational risk by challenging both historical and proposed practices • Validate the first line’s control testing and independently test the first line’s information technology, information security and data controls to verify the design and operational effectiveness • Leverage the current Enterprise Risk Management framework and partner with IT, IS and Data teams to further mature the second line of defense technology and information security risk assessments, document controls, identify gaps, and create action plans for critical IT processes, including validation and testing to ensure IT risk programs are implemented and executed appropriately • Provide support to key risk assessments and perform credible challenge of methodologies and results, including the annual Gramm-Leach-Bliley Act (GLBA) Assessment, Authentication and Access Assessments, Payment Card Industry Data Security Standard assessment and HIPAA compliance • Consult with the first line on the creation of issues to address control gaps/failures and monitor the progress of remediation, ensuring timely and accurate mitigation, and providing credible challenge to support the timely closure of issues • Support the establishment of metrics to quantify and measure technology risks and provide review and challenge to the action plans of deficient metrics • Perform oversight of the front-line’s management of IT/IS/Data activities and exception handling, including the documentation of IT changes, end-of-life technology, resiliency enhancements and testing, business impact analysis, vulnerability management, completion of action items related to addressing technology failures and disruptions, CDEs and data rules • Provide credible challenge of the first line’s IT/IS/Data policies and standards ensuring compliance under Northwest’s corporate governance requirements • Analyze losses in the Business associated with IT failures, disruptions and errors to understand how losses were incurred, determined lessons learned, identify root causes and developing recommendations for future risk avoidance **Additional Essential Functions** • Ensure compliance with Northwest’s policies and procedures, and Federal/State regulations • Navigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiency • Work as part of a team • Work with on-site equipment **What You Bring to the Team** • Additional job duties as assigned by management **QUALIFICATIONS** To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. **Education** Bachelor's Degree Degree in Management Information Systems, Cybersecurity, or Business Administration **Work Experience** 8 - 12 years Cybersecurity/information technology experience And 6 - 8 years Prior financial institution experience **Additional Knowledge, Skills and Abilities** • Deep understanding of information technology, information security and data principles and best practices • Proficient in risk management methodologies, frameworks, and execution of the Risk and Control Self-Assessment (RCSA) • Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA) • Experience with vulnerability scanning and penetration testing tools • Strong analytical and problem-solving skills • Excellent communication and reporting abilities • Deep understanding of information technology and information security principles and best practices • Proficient in risk management methodologies and frameworks • Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA) • Experience with vulnerability scanning and penetration testing tools • Strong analytical and problem-solving skills • Excellent communication and reporting abilities **Licenses and Certifications** Infrastructure Library (ITIL) Certified Information System Auditor Certified Information Security Manager (CISM) Certified Risk and Information Systems Control Certified Information Systems Security Professional (CISSP) Northwest is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.At Northwest, we’re here for what's next. Whether we're finding opportunities for families, businesses and communities or opening doors for our team, we share a passion for helping the people around us succeed. And we know that in order to provide the highest level of care, we need to understand unique experiences and perspectives. That's why, whether you're interested in a corporate role or something customer-facing, your talent and voice matter. Here, you belong. Working at Northwest, you'll find that we recognize our employees for the important work they do through competitive compensation and benefits, professional development opportunities and by regularly celebrating wins along the way. So, take a look at the opportunities here. And join us as we move into the future making a difference for the people we serve.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Technology Enterprise Risk Manager
Information Technology Enterprise Risk Manager

Northwest Bank • North Carolina

On-site
USD 120,000 - 180,000
Information Technology Enterprise Risk Manager
Information Technology Enterprise Risk Manager

Northwest Bank • Columbus (OH)

On-site
USD 120,000 - 180,000
Commercial Information Systems Administrator III
Commercial Information Systems Administrator III

Northwest Consumer Discount Company • Warren

On-site
USD 85,000 - 105,000
Competitive compensation
Professional development opportunities
Inclusive work environment
Divisional Chief Information Officer - Digital Services
Divisional Chief Information Officer - Digital Services

Northwest • Columbus (OH)

On-site
USD 250,000 - 350,000
IT50 - Lead Software Engineer
IT50 - Lead Software Engineer

Northwest • Columbus (OH)

On-site
USD 120,000 - 170,000
Technical IT Audit Lead
Technical IT Audit Lead

LE001 Northwest Bank • Kentucky

On-site
USD 100,000 - 120,000
Senior Credit Review Auditor
Senior Credit Review Auditor

Northwest Consumer Discount Company • Independence Township (OH)

On-site
USD 60,000 - 80,000
Competitive compensation
Professional development opportunities
Lead Software Engineer - Workday Integrations & Security
Lead Software Engineer - Workday Integrations & Security

LE001 Northwest Bank • United States

On-site
USD 140,000 - 195,000
Trust Officer
Trust Officer

Northwest Consumer Discount Company • Erie

On-site
USD 70,000 - 90,000
Competitive compensation
Professional development opportunities
Celebration of employee achievements
Core App Developer II
Core App Developer II

Northwest Consumer Discount Company • Columbus (OH)

On-site
USD 70,000 - 90,000
Competitive compensation
Professional development opportunities
Recognition for employee achievements