Head of Cyber and IT Risk Management (SVP)
Madison-Davis, LLC · New York City Metropolitan Area
Apply & track with Apply EdgeA leading financial-services organization is seeking a Senior Vice President to lead its Cyber and IT Risk Management function.This executive will provide independent risk oversight and credible challenge across technology and cybersecurity, helping the organization identify, assess, communicate, monitor, and mitigate material risks across a complex technology environment.The position requires a combination of technical credibility, enterprise-risk expertise, executive communication, and results-oriented leadership. The successful candidate will lead a blended team while partnering with technology, cybersecurity, operational risk, enterprise risk, Internal Audit, and senior executives.ResponsibilitiesLead the enterprise Cyber and IT Risk Management functionEstablish the strategy, operating model, and priorities for technology-risk oversightAssess inherent and residual technology and cybersecurity risksEvaluate the design and operating effectiveness of mitigating controlsProvide constructive, evidence-based challenge to technology and cybersecurity leadersLead technology and cyber risk assessmentsEstablish risk-based testing, monitoring, and analyticsIdentify risk concentrations, emerging risks, and control weaknessesTranslate complex technical issues into clear business and enterprise-risk termsCommunicate material risks and remediation priorities to senior executives and governance forumsEvaluate cybersecurity processes, vulnerabilities, incidents, architecture, and controlsChallenge risk acceptance and remediation decisions when residual risk remains excessiveDrive complex and long-running remediation initiatives through closureTrack whether risk initiatives produce measurable risk reductionPartner across technology, cybersecurity, enterprise risk, operational risk, and Internal AuditLead and develop a distributed team of employees, contractors, and offshore resourcesImprove accountability and effectiveness across the risk-management functionRole RequirementsSignificant leadership experience in cyber risk, IT risk, technology risk, operational risk, or a closely related disciplineStrong understanding of enterprise and operational risk managementTechnical experience or foundation in cybersecurity, engineering, infrastructure, development, architecture, or a similar fieldAbility to assess complex technology environments and identify material risksExperience evaluating control design, operating effectiveness, mitigating controls, and residual riskBroad knowledge of cybersecurity practices and control domainsExperience leading risk assessments, testing, monitoring, analytics, and remediationAbility to provide credible challenge to senior executivesDemonstrated success driving risk initiatives and remediation through completionStrong executive-level communication and presentation skillsExperience within financial services or another highly regulated enterpriseKnowledge of NIST CSF, FFIEC, or comparable cyber and financial-services risk frameworksExperience leading employee, contractor, and distributed resourcesAbility to work onsite in the Dallas–Fort Worth area approximately three days per weekAbility to travel periodically to CaliforniaNice to HaveBanking experienceCISA, CISSP, CRISC, CDPSE, or comparable certificationExperience across first, second, and third lines of defenseExecutive risk or governance-committee presentation experienceOffshore-team leadershipPublic-cloud security-risk experienceRisk-analytics and risk-based control-testing transformation