Truist logo
TruistPosted 1 week ago

Chief Cybersecurity Risk Officer

$300,000–$400,000 year

On-siteAtlanta, Georgia, United States or Charlotte, North Carolina, United States

Full TimeSenior LevelEnterprise

Job Summary

Lead independent cyber risk oversight for Truist by providing comprehensive risk management across cybersecurity functions and serving as the second line of defense. Establish risk appetite statements, key risk indicators, and thresholds while delivering independent assessments and continuous monitoring of the Chief Information Security Officer's initiatives. Provide guidance to senior leaders and the Board on critical cybersecurity issues, escalating significant risks and communicating domain maturity. Define and drive the Cyber Risk Framework, oversee vendor assessments, and lead the review of significant cyber incidents to direct remediation efforts. Serve as the primary risk point of contact with regulators, presenting regular risk updates and validating remediation actions. Manage and develop the risk team, promote a culture of risk management, and ensure alignment with federal and state regulatory requirements.

Required Qualifications

  • Bachelor's degree in computer science, Information Systems, or data/technology related field
  • MBA preferred
  • Fifteen+ (15+) years of progressive experience in cybersecurity relevant roles within a Category 2 or 3 Large Financial Institution (LFI)
  • Deep understanding of regulatory requirements for complex financial services organization (including both Federal Reserve and FDIC regulations)
  • In depth understanding of how data is captured, transformed, and used and the ability to connect end-to-end processes independently
  • Fifteen+ (15+) years of experience or equivalent proficiency in managing people
  • Demonstrated high competency in recruiting, developing, and coaching/mentoring
  • Fifteen+ (15+) years of experience in a financial institution with emphasis on risk management or equivalent work experience
  • Extensive knowledge on information security, cyber risk, core technology infrastructure, cloud operations, and technology operations
  • Experience in leveraging modern tools to measure effective of technology and cyber controls
  • Experience with enterprise architecture, reference architectures and emerging technologies
  • Knowledge of key technology rules/regulations and technology risk management practices (e.g. Federal Financial Institutions Examination Council (FFIEC), Control Objectives for Information and Related Technology (COBIT), NIST (National Institute of Standards and Technology), Information Technology Infrastructure Library (ITIL))
  • Excellent leadership skills including the ability to lead direct and indirect reports, including executive level leaders
  • Excellent communication (verbal and written), presentation and facilitation skills
  • Ability to influence and communicate with impact with C-suite executives and board members
  • Ability to translate technical concepts for various audiences
  • Language Fluency: English (Required)
  • Work Shift: 1st shift (United States of America)

Desired Qualifications

  • Bachelor's degree in finance or business equivalent
  • Professional designations such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (Information Systems Audit and Control Association) (CRISC), Certified Project Manager (CPM)
  • Strategic business and financial planning experience
  • Have an innovation mindset and strong understanding of industry recognized tooling to support enterprise data programs and strong control environments
  • Experience with audit processes and techniques
  • Exposure to and experience with adapting cybersecurity capabilities in a post Mythos threat environment

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce