OH0713 NW Bancshares HQ, PA0728 Pittsburgh Business Office
Job Description
The Information Technology Enterprise Risk Manager within the Risk Management organization is responsible for supporting the execution and oversight of Northwest's Operational Risk framework as it relates to information technology, information security and data risks. This role will adapt previous experience and industry leading practices to identify, assess, monitor, and report key technology risks, helping to embed risk awareness into strategic and operational decision-making. This role will help to support activities including, but not limited to, Risk and Control Self-Assessments (RCSA), risk management training, issues management, risk management and policy and procedure governance.Essential Functions
Provide oversight of the Risk and Control Self-Assessment (RCSA) activities within technology-related processes, performing credible challenge of the conclusions derived from the RCSA, and monitoring routinesIndependently assess risks and drive actions to address the root causes that persistently lead to significant residual operational risk by challenging both historical and proposed practices
Validate the first line’s control testing and independently test the first line’s information technology, information security and data controls to verify the design and operational effectivenessLeverage the current Enterprise Risk Management framework and partner with IT, IS and Data teams to further mature the second line of defense technology and information security risk assessments, document controls, identify gaps, and create action plans for critical IT processes, including validation and testing to ensure IT risk programs are implemented and executed appropriately
Provide support to key risk assessments and perform credible challenge of methodologies and results, including the annual Gramm-Leach-Bliley Act (GLBA) Assessment, Authentication and Access Assessments, Payment Card Industry Data Security Standard assessment and HIPAA complianceConsult with the first line on the creation of issues to address control gaps/failures and monitor the progress of remediation, ensuring timely and accurate mitigation, and providing credible challenge to support the timely closure of issues
Support the establishment of metrics to quantify and measure technology risks and provide review and challenge to the action plans of deficient metricsPerform oversight of the front-line’s management of IT/IS/Data activities and exception handling, including the documentation of IT changes, end-of-life technology, resiliency enhancements and testing, business impact analysis, vulnerability management, completion of action items related to addressing technology failures and disruptions, CDEs and data rules
Provide credible challenge of the first line’s IT/IS/Data policies and standards ensuring compliance under Northwest’s corporate governance requirementsAnalyze losses in the Business associated with IT failures, disruptions and errors to understand how losses were incurred, determined lessons learned, identify root causes and developing recommendations for future risk avoidanceAdditional Essential Functions
Ensure compliance with Northwest’s policies and procedures, and Federal/State regulationsNavigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiency
Work as part of a teamWork with on-site equipmentWhat You Bring to the Team
Additional job duties as assigned by managementQUALIFICATIONSTo perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.EducationBachelor's Degree
Degree in Management Information Systems, Cybersecurity, or Business Administration Work Experience 8 - 12 years Cybersecurity/information technology experience And6 - 8 years Prior financial institution experience Additional Knowledge, Skills and Abilities
Deep understanding of information technology, information security and data principles and best practicesProficient in risk management methodologies, frameworks, and execution of the Risk and Control Self-Assessment (RCSA)
Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)
Experience with vulnerability scanning and penetration testing tools
Strong analytical and problem-solving skills
Excellent communication and reporting abilities
Deep understanding of information technology and information security principles and best practices
Proficient in risk management methodologies and frameworks
Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)
Experience with vulnerability scanning and penetration testing tools
Strong analytical and problem-solving skills
Excellent communication and reporting abilities
Licenses and Certifications Infrastructure Library (ITIL) Certified Information System Auditor Certified Information Security Manager (CISM) Certified Risk and Information Systems Control Certified Information Systems Security Professional (CISSP)
Northwest is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.
Numbers & Facts
Location
Pittsburgh, Pennsylvania
Skills
Analysis Skillsunmatched
Authenticationunmatched
Best Practicesunmatched
Business Administrationunmatched
Business impact analysis (BIA)unmatched
CISA - Certified Information Systems Auditorunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Communication Skillsunmatched
Computer Securityunmatched
Computer Softwareunmatched
Corporate Governanceunmatched
Data Analysisunmatched
Design Verificationunmatched
Documentationunmatched
Error Handlingunmatched
HIPAA (Health Insurance Portability and Accountability Act)unmatched
ITIL (IT Infrastructure Library)unmatched
Information Technology & Information Systemsunmatched
Internet Securityunmatched
Leachingunmatched
Maintain Complianceunmatched
Management of Information Systems/Technology (MIS)unmatched
Metricsunmatched
Microsoft Officeunmatched
Operational Strategyunmatched
PCI-DSSunmatched
Penetration Testingunmatched
Problem Solving Skillsunmatched
Process Validationunmatched
Regulatory Complianceunmatched
Reporting Skillsunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Risk Management Framework (RMF)unmatched
Root Cause Analysisunmatched
Security Analysisunmatched
Team Playerunmatched
Testingunmatched
Time Managementunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Validation Testingunmatched
Vulnerability Scannersunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.