Senior IT Risk Manager, Identity & Access Management
Listed on 2026-01-11
-
IT/Tech
Cybersecurity, Information Security
Senior IT Risk Manager, Identity & Access Management
Join to apply for the Senior IT Risk Manager, Identity & Access Management role at Charles Schwab
At Schwab, you’re empowered to make an impact on your career. Here, innovative thought meets creative problem solving, helping us “challenge the status quo” and transform the finance industry together.
In Technology Risk Management (TRM), a part of Corporate Risk Management (CRM), we partner with technology and business teams who are implementing technologies and processes to ensure the risks associated with the use of these are identified and managed. We do this to ensure we meet our corporate risk appetite, following an established framework for identifying, evaluating, measuring, monitoring, and reporting that risk in order to protect client assets, client information, and firm assets.
You will bring an understanding of technologies in the identity, authentication, and access management space to identify the risks associated with use of these technologies and determine if risks are sufficiently managed.
The Senior IT Risk Manager, Identity & Access Management, as a second line function, is responsible for:
- Proactively identifying, measuring, assessing and reporting on risks associated with managing the identity lifecycle, managing access to information resources, and authentication/authorization mechanisms.
- Overseeing identity and access risk management policy, assessing adherence to policy, and reporting maturity progress to management.
- Assessing ongoing adherence to security standards and best practices by conducting recurring and ad-hoc risk assessments on platforms, applications, and processes.
- Providing consultation/guidance to our first line partners on policy and standard requirements and best practices to reduce risk.
What You’ll Do:
- Conduct policy/standard oversight; collaborate with technology and business teams to assure risks and risk management requirements are understood; assess IAM processes for compliance with published standards, regulatory requirements, and best practices; perform risk assessments and testing where appropriate.
- Identify risks, examine control portfolios (and their underlying processes), and assess whether these are designed sufficiently to and are effectively reducing risk to levels within the firm’s risk appetite.
- Assist business partners through the risk response process by documenting gaps as issues, providing input to remediation plans and/or risk acceptances, and providing oversight for the management/lifecycle of these gaps.
- Maintain and evolve the measurement of RAMMs/KPIs/KRIs to monitor risk reduction.
- Assess the IAM risk management space, including roadmaps and projects, on a periodic basis to evolve strategy to adapt to emerging threats and capabilities.
- Collaborate with technology and business teams to ensure creation of IAM policies and standards reflecting the firm’s risk appetite and best practices to ensure robust risk management.
- Work with leadership, internal auditors, and regulators to articulate our IAM risk management framework, execution progress, and how these risks are managed at Schwab.
- Exemplify professionalism and a collaborative spirit in working with fellow risk management professionals and especially with our business partners to help them understand the benefit of identifying and managing risks to support business initiatives.
We believe in the importance of in-office collaboration and fully intend for the selected candidate for this role to work on site four days per week in the specified locations.
Applicants must be currently authorized to work in the United States on a full-time basis without employer sponsorship.
Required Qualifications:
- 5+ years of experience in an Information Technology, Information Security, IT Risk Management, or Technology Audit field.
- Experience working within the identity and access management technology space and a working knowledge of aspects such as provisioning, entitlements, certification, privileged access management, authentication, and other technologies in this space.
- Experience with data analysis and reporting, with sharp analytical skills and strong…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).