Director, Cybersecurity Risk Management
$220k - $265kSunTrust Investment Services, Inc.
Senior Leader For Security Governance
Truist is seeking a senior leader to support continued maturation of the Security Governance function within Truist Protection Services (TPS). Reporting to the Head of Security Governance, this role will play a key role in the strategic direction for the management of cyber risks, issues, and controls across TPS to scale governance and accelerate decision-making. This leader will translate key drivers, regulatory expectations, and emerging threats into a coherent program strategy and operating model. The role partners closely with other Security Governance functions (Process, Risk and Control; Policy and Standards Governance and Adherence; Assessments; Third-Party Risk; Issue Management), second line Risk, Audit, Business Information Security Officers (BISOs), Technology, Legal, and business stakeholders to strengthen Truist's cyber risk posture and reduce time-to-remediation at scale. The ideal candidate has led cybersecurity risk, issue management, and/or controls functions in a large, regulated environment; can translate technical risk into clear business decisions; and can drive measurable program outcomes through both strong governance discipline and modern, technology-enabled execution.
Essential Duties And Responsibilities Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
This role leads the governance of a portfolio of issues and related remediation activities. Responsibilities will evolve as the program scales and matures.
- Define and execute program strategy. Establish the vision, operating model, and multi-year roadmap aligning to key drivers, regulatory expectations, enterprise risk appetite, and TPS priorities.
- Own end-to-end management of a portfolio of issues —including intake, classification, prioritization, root-cause analysis, action plan quality, remediation tracking, escalation, and closure validation.
- Drive issue management and mitigation. Identify, document, coordinate, and execute (as applicable) issue management and mitigation activities; partner with control and process owners to ensure timely, sustainable remediation and reduction of repeat findings.
- Govern controls design and operation. Lead the creation, documentation, and ongoing management of cybersecurity controls as applicable—ensuring controls are well-defined, mapped to applicable frameworks and regulations, testable, and continuously monitored for effectiveness.
- Embed agentic AI and automation. Champion a culture of innovation by applying agentic AI, intelligent workflows, and advanced analytics to issue management, control monitoring, evidence collection, and executive reporting—reducing manual effort and accelerating insight.
- Partner across Security Governance. Coordinate seamlessly with Process, Risk and Control; Policy and Standards Governance and Adherence; Assessments; Third-Party Risk; and other Security Governance functions to ensure a consistent, integrated governance experience for TPS.
- Engage the three lines of defense. Build strong partnerships and influence outcomes across first line TPS teams, second line Risk and Compliance, and third line Audit—aligning oversight expectations, strengthening issue management discipline, and reducing residual risk.
- Support regulatory and audit engagements. Lead timely, accurate, and well-evidenced responses to regulatory exams and internal audit activities; ensure sustainable remediation and strong control evidence.
- Deliver executive-ready reporting. Produce concise, decision-grade materials for senior leadership and governance committees, highlighting top risks, issue trends, control health, and prioritized actions.
- Build and develop the team. Hire, develop, and retain a high-performing team of cybersecurity risk, issue management, and controls professionals; set clear goals, provide coaching, and foster a culture of accountability, curiosity, and collaboration.
- Embody "we deliver together." Establish strong cross-functional working relationships across TPS, Technology, Legal, Procurement, Enterprise Risk, and business stakeholders to drive shared outcomes.
Qualifications Required Qualifications The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 1. Bachelor's degree in Information Technology, Information Security, Engineering, or related field. 2. Minimum of 10 years of professional experience in technology governance with progressive management responsibilities. 3. Proven experience managing teams and mitigating technology risks at scale. 4. Strong knowledge of regulatory requirements and compliance frameworks. 5. Expertise in governance assessment methodologies, control frameworks, and enterprise vulnerability management.
- Graduate degree (MBA, MS, or similar) and/or industry certifications (e.g., CISSP, CRISC, CISM, CISA).
- Experience building or transforming cybersecurity issue management and controls programs at scale (e.g., issue lifecycle automation, control rationalization, continuous control monitoring, integrated GRC platforms).
- Experience developing or implementing agentic AI and emerging risk technologies in a GRC context (e.g., AI-assisted root-cause analysis, automated evidence collection, intelligent reporting).
- Experience translating regulatory requirements and audit findings into durable control design and sustainable remediation strategies.
- Experience leading governance functions within a complex, matrixed financial institution and influencing outcomes across first, second, and third lines of defense.
The annual base salary for this position is $220,000 - $265,000
$230.4k - $263k
...Director, Technology & Cyber Risk Metrics Job Description Capital One is one of the fastest growing organizations... ...through technology, we equally prioritize cybersecurity, reliability, software quality, and data management. Technology & Data Risk Management (...SuggestedFull timePart timeLocal area$229.9k - $262.4k
...Sr. Risk Manager, Data Protection This position represents a unique opportunity for those with hands-on cybersecurity technical and operational experience who have a desire to leverage... ...regulatory agencies and the Board of Directors, as needed. Stay current on...SuggestedFull timePart timeLocal areaImmediate start$229.9k - $262.4k
Senior Manager, SRE Risk Advisory and Oversight Capital One is one of the fastest growing organizations in the world today, powered by our... ...innovation through technology, we equally prioritize cybersecurity, reliability, software quality, and data management. Technology...SuggestedFull timePart timeLocal area$132.8k - $219.1k
...it. Job Category Risk Control Compensation Overview... ...skilled and knowledgeable Director within our Cyber Risk... ...contributing their expertise towards cybersecurity initiatives that strengthen... ...Provide human resources management, including coaching, performance...SuggestedLocal area$151.9k - $173.4k
...Overview Manager, Risks Data & Analytics - Hybrid The Enterprise Payments Governance and Oversight team is seeking a dynamic Manager... ...like Issues & Event Management, Risk & Controls (RCSA), or Cybersecurity/Technology Data. Location: West Creek 5 (Richmond, VA)...SuggestedFull timePart timeWork at officeLocal area- ...Consumer Credit Risk Management Ensure the efficient and balanced risk management of the credit adjudication, credit policy, portfolio management, loss forecast, and overall credit processes for the assigned Consumer Credit horizontal domain or business unit within...Full timePart timeWork at officeRemote work
$151.9k - $173.4k
...Risk Manager - Operational Risk Challenge & Advisory Can you build relationships as well as develop and implement innovative solutions? As a Manager Risk Specialist at Capital One you'll be responsible for working with business partners to identify and mitigate potential...Full timePart timeWork at officeLocal area- ...Purpose of Job The Enterprise Risk Manager is responsible for identifying, evaluating, and mitigating operational and financial risks across the organization, with a primary focus on energy trading and market risk activities. This role oversees trading agreement...Work experience placementWork at office
$230.4k - $263k
...Director, Technical Products & Platforms Risk Leader - Enterprise Services Risk Office The Enterprise Services Risk organization is expanding with a focus... ...professionals. We operate at the forefront of risk management, providing support for novel and developing...Full timePart timeWork at officeLocal area$151.9k - $173.4k
...Fraud Risk Manager - Business Cards and Payments, Hybrid Business Cards & Payments manages Capital One's Corporate and Small Business credit, charge cards, and emerging B2B payment functions. In this Fraud Risk Manager role, you will be responsible for leading a team...Full timePart timeLocal area- ...Risk Manager, Executive Protection This role plays a critical role in safeguarding Genworth's senior leaders, board members, and key stakeholders by delivering discreet, professional, and risk-based protective services. This position supports the company's Executive...Work experience placementLocal area
- ...Senior Capital Oversight Risk Manager The Senior Capital Oversight Risk Manager serves as a senior subject matter expert, providing independent oversight of Truist's capital management processes, including capital stress testing, regulatory interpretations and capital...
$70.6k - $141.2k
...Health Government Services is seeking a skilled Federal Program Manager to join our mission-driven organization. In this role, you will... ...program activities and ensuring successful delivery across Oracle’s risk management framework. The ideal candidate will have a solid...Temporary workFlexible hours$102.96k - $185.33k
...Risk Adjustment Strategic Manager Location: Virginia, Indiana, Georgia, Tennessee, Connecticut, New York, New Jersey, Maine, Kentucky This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility...Temporary workWork experience placementWork at officeLocal area2 days per week1 day per week$202.9k
...Carescout Services Senior Enterprise Risk Director At Genworth, we empower families to navigate the aging journey with confidence. We... ...Richmond, VA New York, NY Your Role: Ensuring strong risk management is critical to preserving the integrity of our business and enabling...Local area$138.1k - $157.7k
...Risk Manager - Quality Control Capital One's Card Risk organization is responsible for core areas that span Risk Management, Strategy, Operations, Technology, and Analytics. This organization leads, advises and innovates on top transformational initiatives across the...Full timePart timeCurrently hiringLocal area- ...Risk Management Director, RN, BSN Director of Risk Management needed for healthcare organization. Candidates must have strong experience and results as Dir. in General acute care setting. Director experience of at least 6+ years with strong results. Risk Management...Relocation package
- ...Senior Risk Technologist Provides senior leadership level risk oversight and insight in driving the successful implementation of... ...developments, and to translate those insights into forward-looking risk management practices, governance enhancements, and team-wide capability...Contract workWork at office
$110.5k - $202.7k
...all. The opportunity The objective of our Consulting risk services is to provide clients with a candid and reliable overview... ...Your key responsibilities You will be responsible for managing multiple client engagement teams at an executive level within the...Contract workSummer holidayWork at officeImmediate startFlexible hours- Old Dominion Electric Cooperative in Glen Allen, Virginia, is seeking an Enterprise Risk Manager to lead risk management initiatives in energy trading and financial operations. This role requires a minimum of 10 years in risk management or related fields, ensuring compliance...Work at office
$138.1k - $157.7k
...Risk Manager - Customer Identity Management Team (Hybrid) Do you like working in the spotlight? Are you ready to work on the front line of a top 10 Bank? Can you build relationships as well as develop and implement innovative solutions? As a Risk Manager at Capital...Full timePart timeLocal area$109.9k - $125.4k
...Principal Associate, Risk Manager - Issues & Events Management (Hybrid) As a Principal Risk Specialist within the Card Risk team, you will engage with a team of risk managers, product owners and business leads in delivering flawlessly executed event and issue management...Full timePart timeLocal area$206k - $235.1k
Director, Global Enterprise HR Risk Advisor As a Director in Capital One’s Human Resource Risk Office, you will apply your leadership and analytical skills to our highest profile Risk Management projects. You will lead teams of Risk Advisors and act as a thought leader...Full timePart timeWork at officeLocal area$138.1k - $157.7k
Risk Manager, Business Continuity and Resilience Risk Management Do you want to be part of an organization that is dedicated to helping Capital One identify, manage, and effectively mitigate risk - for our customers, our communities, and our associates? Capital One is...Full timePart timeLocal area- Old Dominion Electric Cooperative (ODEC) is seeking an Enterprise Risk Manager to identify, evaluate, and mitigate operational and financial risks in energy trading. This role involves overseeing trading agreement risks and ensuring compliance with policies while supporting...Work at office
$120.8k - $137.9k
Principal Risk Manager- Global Payments Network Risk Are you ready to lead from the front line of a top 10 bank? Do you thrive in a high-visibility environment where your strategic relationship-building translates directly into innovative risk solutions? As a Principal...Full timePart timeLocal area$177.7k - $202.8k
Card Risk Senior Manager - Platform Development Capital One is pushing the boundaries of fintech, and our Card Risk Team needs a Senior Risk... ...years of experience developing, evaluating or implementing cybersecurity, technology or risk assessment activities At least 4 years...Full timePart timeLocal area- ...Healthcare Financial/Actuarial Associate Manager As a Healthcare Financial/Actuarial Associate Manager you will contribute to a wide... ...Provides direction on benefit plan analysis, design, cost avoidance, risk and funding strategies Contributes to vendor financial...Temporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours
$161.5k - $184.3k
...Overview Senior Risk Manager (Global Payments Network) Job Description The Senior Manager, Risk Management will join the Data Governance and Pricing (DGAP) team within the Global Payment Networks (GPN) to manage numerous data adjacent risks. The risks include...Full timePart timeLocal area$164.8k - $188.1k
Data Analyst Manager - Model Risk Office At Capital One, data is at the center of everything we do. When we launched as a startup we disrupted the credit card industry by individually personalizing every credit card offer using statistical modeling and the relational database...Full timePart timeWork experience placementWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cybersecurity Risk Management. Be the first to apply!
- risk management associate Richmond, VA
- director credit risk Richmond, VA
- risk management specialist Richmond, VA
- enterprise risk manager Richmond, VA
- head of risk management Richmond, VA
- operational risk manager Richmond, VA
- risk management manager Richmond, VA
- director of risk management Richmond, VA
- risk underwriter Richmond, VA
- technology risk Richmond, VA

