Technology Risk, Cyber Governance & Third-Party Risk Manager

bankunitedexternal

Town of Florida (NY)

On-site

USD 140,000 - 210,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

BankUnited is seeking a senior Technology Risk professional in New York to provide independent second-line oversight of technology, cybersecurity, cloud, and third-party risks. You will challenge initiatives, assess controls, and influence risk decisions across IT, security, procurement, and business units.

You will lead third-party risk due diligence, review vendor security, and contribute to risk reporting, regulatory readiness, and governance through risk-informed guidance and robust

Qualifications

  • Bachelor's degree in engineering or computer sciences required.
  • 8+ years of experience in technology risk management, cybersecurity governance, third‑party risk, or related fields.
  • Experience with regulatory compliance and enterprise risk management is preferred.

Responsibilities

  • Provide independent second‑line oversight of technology, cybersecurity, cloud, and third‑party risks.
  • Lead cybersecurity due diligence, vendor security reviews, and risk assessments for third‑party relationships.
  • Collaborate with Legal, Procurement, Compliance and business stakeholders during risk management activities.
  • Develop and deliver risk reports, governance materials, and management communications.

Skills

Technology Risk Management
Cybersecurity Governance
Third-Party Risk Management
Information Security
Technology Audit
Cybersecurity Risk Assessments
Regulatory Compliance
Enterprise Risk Management

Education

Bachelor's degree in engineering or computer sciences

Job description

JOB SUMMARY

This position is responsible for providing independent second-line oversight of technology, cybersecurity, third-party, cloud, and emerging technology risks across the organization. The role serves as a trusted advisor and challenge function to Information Technology, Information Security, Enterprise Architecture, Procurement, Legal, Compliance, Enterprise Risk Management, and business stakeholders.

The incumbent leads cybersecurity third-party risk management activities, performs independent risk assessments, evaluates technology control environments, reviews technology and security architectures, and provides governance oversight of technology initiatives and vendor relationships. The position is responsible for identifying, assessing, monitoring, and communicating technology-related risks while ensuring alignment with the organization's risk appetite, regulatory requirements, and industry best practices.

This role also supports regulatory examinations, internal and external audits, enterprise risk reporting, technology governance forums, and ongoing enhancement of technology risk and third-party risk management programs.

ESSENTIAL DUTIES AND RESPONSIBILITIES
  • Technology Risk Governance & Second-Line Oversight:
    • Serves as an independent Second Line of Defense (2LOD) challenge function for technology, cybersecurity, cloud, data, AI, and third-party risks.
    • Provides objective review and challenge of technology initiatives, cybersecurity programs, system implementations, and vendor onboarding activities.
    • Assesses whether proposed controls, architectures, and risk mitigation strategies are appropriately designed and commensurate with organizational risk.
    • Evaluates risk acceptance requests, compensating controls, documented exceptions, and remediation plans.
    • Ensures technology risks remain within approved risk appetite thresholds.
    • Participates in governance committees, steering committees, risk forums, and working groups as a technology risk subject matter expert.
    • Advises management regarding technology risk, cybersecurity risk, operational risk, and third-party risk implications.
  • Cybersecurity Third-Party Risk Management:
    • Leads cybersecurity due diligence reviews for new and existing third-party relationships.
    • Evaluates vendor security controls through reviews of SOC reports, ISO certifications, SIG questionnaires, audit reports, penetration tests, security policies, regulatory documentation, and other independent attestations.
    • Assesses vendor risks associated with cloud hosting, managed services, software development, professional services, artificial intelligence, critical infrastructure, and data processing.
    • Evaluates subcontractor and fourth-party dependencies and associated risks.
    • Reviews third-party incidents, breaches, control failures, and operational disruptions for potential impacts to the organization.
    • Develops cybersecurity due diligence opinions and risk recommendations for business owners and management.
    • Presents vendor risk assessments and residual risk determinations to stakeholders and governance bodies.
    • Supports ongoing monitoring activities for critical and high‑risk third‑party relationships.
  • Contract & Third-Party Governance Review:
    • Reviews contractual requirements related to information security, cybersecurity, privacy, resilience, artificial intelligence, business continuity, regulatory compliance, and audit rights.
    • Assesses contractual provisions related to:
      • Breach notification
      • Security obligations
      • Data retention and destruction
      • Subprocessor management
      • Right-to‑audit provisions
      • Regulatory cooperation
      • AI model training restrictions
      • Cloud hosting controls
      • Data residency requirements
    • Identifies contractual gaps and recommends risk mitigation strategies.
    • Collaborates with Legal, Procurement, Compliance, and business stakeholders during contract negotiations.
  • Technology Risk Assessments:
    • Performs risk assessments for applications, systems, technologies, cloud implementations, and technology projects.
    • Assess cybersecurity, operational, regulatory, architectural, resilience, and data protection risks.
    • Evaluates security architectures, cloud deployments, integrations, and emerging technologies.
    • Reviews technology designs for alignment with security standards, regulatory guidance, and enterprise control requirements.
    • Identifies control weaknesses, security gaps, and operational risks.
    • Recommends practical risk mitigation strategies and compensating controls.
  • Technology & Security Advisory Services:
    • Provides risk and cybersecurity consultation to technology teams, security teams, architects, project teams, and business stakeholders.
    • Assists teams in understanding regulatory requirements and industry expectations.
    • Supports development of secure and compliant technology solutions.
    • Advises stakeholders on cybersecurity frameworks, cloud security, third‑party risk, technology resilience, data protection, and emerging threats.
    • Provides technical guidance during vendor selection, technology implementations, and operational changes.
  • Architecture Review & Security Governance:
    • Participates in Security Review Boards, Architecture Review Boards, and technology governance forums.
    • Reviews proposed technology architectures for risk, security, resilience, recoverability, and compliance considerations.
    • Challenges incomplete documentation, undefined controls, security gaps, unsupported assumptions, and unresolved risks.
    • Ensures technology initiatives maintain appropriate design documentation and evidence of control implementation prior to approval.
  • Risk Program Development:
    • Designs, develops, and enhances technology risk and third‑party risk management methodologies.
    • Maintains and improves inherent risk assessment methodologies, questionnaires, and governance processes.
    • Develops standards, procedures, templates, reporting mechanisms, and program documentation.
    • Establishes scalable approaches for cybersecurity assessments, vendor monitoring, and risk reporting.
    • Supports implementation of continuous monitoring capabilities and risk intelligence programs.
    • Evaluates opportunities to improve process efficiency through automation, workflow optimization, and technology solutions.
  • Regulatory, Audit & Examination Support:
    • Supports regulatory examinations and interactions with banking regulators.
    • Coordinates responses to technology risk, cybersecurity, and third‑party risk examination requests.
    • Partners with Internal Audit and External Audit during reviews of technology and security controls.
    • Develops management responses, remediation plans, and supporting evidence.
    • Tracks and monitors corrective actions through completion.
    • Supports enterprise compliance efforts related to GLBA, FFIEC guidance, NYDFS, PCI DSS, and other applicable regulations.
  • Risk Reporting & Executive Communications:
    • Develops and presents risk reports, assessments, dashboards, and governance materials.
    • Communicates complex technology risks in a manner understandable to executive leadership and business stakeholders.
    • Prepares examiner‑facing and executive‑facing documentation.
    • Presents assessment conclusions, residual risks, trends, and recommendations.
    • Contributes to board and management reporting as required.
  • Leadership, Mentorship & Knowledge Sharing:
    • Serves as a subject matter expert for technology risk, cybersecurity governance, and third‑party risk management.
    • Provides coaching and guidance to analysts and peers regarding assessment methodologies, evidence evaluation, and risk communication.
    • Promotes consistency, quality, and repeatability within risk management processes.
    • Shares knowledge of regulatory expectations, industry practices, and emerging technology risks.
  • Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti‑money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.).
  • Adheres to Bank policies and procedures and completes required training.
  • Identifies and reports suspicious activity.
SUPERVISORY RESPONSIBILITIES
  • Supervises function, projects or services and/or one or more employees, as applicable.
  • Carries out supervisory responsibilities in accordance with the organization's policies and applicable laws.
  • Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance coaching; rewarding and disciplining employees; addressing complaints and resolving problems.
QUALIFICATIONS
Education
  • Bachelor's degree in engineering or computer sciences
Experience
  • 8+ years of experience in one or more of the following:
    • Technology Risk Management
    • Cybersecurity Governance
    • Third-Party Risk Management
    • Information Security
    • Technology Audit
    • Cybersecurity Risk Assessments
    • Regulatory Compliance
    • Enterprise Risk Management
  • Preferred Expertise
    • Technology Risk Governance
    • Cybersecurity Third‑Party Risk Management
    • Cloud Security
    • Security Architecture
    • Artificial Intelligence Governance
    • Technology Control Frameworks
    • Regulatory Compliance
    • Vendor Risk Assessments
    • Contract Risk Review
    • Security Operations
    • Business Continuity & Operational Resilience
Licenses and Certifications
  • Certifications such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), and CC (Certified in Cybersecurity) are highly preferred.
Knowledge, Skills, and Abilities
  • Frameworks & Regulatory Knowledge
  • Demonstrated expertise in:
    • NIST Cybersecurity Framework
    • NIST SP 800 Series
    • FFIEC Guidance
    • GLBA Safeguards Rule
    • COBIT
    • ISO 27001
    • ISO 42001
    • PCI DSS
    • NYDFS Cybersecurity Regulation
    • Third‑Party Risk Management Guidance
Additional Information
  • Candidates residing in locations within BankUnited's footprint may be given preference.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

BankUnited • Town of Florida (NY)

On-site
USD 150,000 - 210,000
Technology Risk, Cyber Governance & Third-Party Risk Manager
Technology Risk, Cyber Governance & Third-Party Risk Manager

BankUnited • Miami (FL), Northern (KY)

Hybrid
USD 140,000 - 190,000
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)

bankunitedexternal • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)

BankUnited • Town of Florida (NY)

On-site
USD 90,000 - 150,000
Cyber Threat Intelligence Analyst I
Cyber Threat Intelligence Analyst I

bankunitedexternal • Town of Florida (NY)

On-site
USD 100,000 - 150,000
SVP & Director of IT Governance - Cyber Security
SVP & Director of IT Governance - Cyber Security

wesbancocareers • Uniontown (OH)

On-site
USD 140,000 - 230,000
Cyber Threat Intelligence Analyst I
Cyber Threat Intelligence Analyst I

BankUnited • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Director, Technology Risk & Operational Resilience
Director, Technology Risk & Operational Resilience

First Command Financial Services, Inc. • Fort Worth (TX)

On-site
USD 180,000 - 240,000
Director, Technology Risk & Operational Resilience
Director, Technology Risk & Operational Resilience

First Command • Fort Worth (TX)

Hybrid
USD 180,000 - 280,000
Sr. Technology Controls Testing Analyst
Sr. Technology Controls Testing Analyst

BankUnited • Miami (FL)

On-site
USD 110,000 - 160,000