VP, Technology Risk
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, Data Security, IT Consultant, IT Project Manager
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting‑edge solutions like Zelle®, Paze℠ and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall PurposeThe Vice President of Technology Risk serves as a senior leader within the Second Line of Defense (2
LOD), responsible for providing independent oversight, challenge, and governance of Technology Risk across a heavily regulated Fin Tech environment and reporting directly to the Chief Technology Risk Officer (CTRO). This role ensures that the organization’s technology ecosystem—including infrastructure, cloud environments, data platforms, product engineering, and IT operations—operates within risk appetite and aligns to regulatory expectations typically applied to banking institutions.
The VP acts as a Subject Matter Expert (SME) in Technology Risk Management, bringing deep expertise in cyber risk, IT controls, operational resilience, cloud governance, third‑party risk, as well as regulatory and industry frameworks such as FFIEC, OCC, CFPB, NIST, ISO 27001, PCI DSS, and CRI. The role partners closely with the 1
LOD Technology, Security, and Product teams to ensure that business goals and risks are adequately addressed, while maintaining objective independence to oversee, assess, and challenge risk management decisions.
- Direct independent oversight and challenges to the design, implementation, and effectiveness of technology risk management practices across the enterprise.
- Direct evaluations of risks related to disaster recovery, site reliability, service continuity, major incident response, and systemic outages.
- Oversee assessments of resilience across cloud environments (AWS, Azure, etc.), SaaS/PaaS integrations, and critical third‑party providers.
- Advise on scenario testing, impact tolerances, and regulatory expectations for resilience.
- Help define and maintain the corporate Technology Risk Framework, ensuring alignment to banking‑industry standards (e.g., CRI, NIST CSF, FFIEC CAT, ISO 27001).
- Partner with Engineering, Infrastructure, Cloud, IT Ops, Cybersecurity, and Product to ensure technology solutions and services align with control expectations.
- Provide proactive guidance on risk/control requirements during product development, cloud migration, data strategy, AI governance, and change management initiatives.
- Support periodic risk assessments, including IT general controls, cloud risks, cyber risks, AI/ML risks, data management risks, and operational resilience assessments, and govern the tracking, challenge, and closure of technology and cyber findings and issues.
- Monitor and refine risk and performance indicators (KRI/KPI), Risk and Control Self Assessments (RCSA), emerging technology risks, and deviations from established risk appetite.
- Serve as a Subject Matter Expert for technology‑related regulatory inquiries, examinations, and audits (internal/external).
- Help interpret and communicate regulatory requirements from global bodies (e.g., OCC, FCA, MAS, EBA, ESMA) to Technology and Security leaders.
- Provide expertise for assessing control gaps and remediation plans; evaluating adequacy, sustainability, and timeliness of corrective actions.
- Provide senior leadership and Board‑level risk reporting on technology risk posture, trends, and emerging issues.
- Communicate risk insights in clear, non‑technical terms for executive decision‑making.
- Mentor junior risk analysts and managers; build a high‑performing IT Risk team.
- Promote a strong risk culture and effective communication between 1
LOD and 2
LOD. - Represent Technology Risk in enterprise committees (Risk Committees,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).