Chief Cybersecurity Risk Officer
$300k - $400kHabitat For Humanity Of Durham
Language Fluency: English (Required)
Work Shift: 1st shift (United States of America)
Job Grade: 116
Job Description
The Chief Cybersecurity Risk Officer (CCRO) is a senior executive position responsible for providing comprehensive risk oversight of the organization's cybersecurity organization. Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the institution's strategic objectives.
This role will serve as the Risk Oversight Leader for all functions within Cybersecurity. This role will lead and implement the cyber risk oversight for Truist which includes: 1) Serve as the Chief Cybersecurity Risk Officer with independent oversight and challenge to the Chief Information Security Officer (CISO) for all risk types; 2) Establish and manage cyber risk oversight – inclusive of delivery of independent assessments and continuous monitoring; 3) Provide guidance to senior leaders across the company on critical cybersecurity issues for both internal and external stakeholders; 4) Use judgment to elevate significant issues and emerging risks; communicate cyber domain maturity and residual risk to senior management including up to the Board of Directors; 5) consistently and appropriately apply second line of defense corporate authority for managing Truist’s cyber risk.
Essential Duties and Responsibilities
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
- 1. Strategic Leadership - Develop and maintain the enterprise technology management framework, incorporating emerging risks related to cyber security. Establish risk appetite statements, key risk indicators, and thresholds for cyber security across the organization. Provide independent assessment and challenge of cyber security initiatives, ensuring alignment with risk appetite and regulatory expectations. Lead the evaluation of strategic cyber security decisions and their impact on the organization's risk profile.
- 2. Risk Leadership - Provide independent risk oversight (i.e., second line of defense/LOD2) for Truist Protection Services (TPS) through the effective identification, mitigation, monitoring and reporting of operational, technology and compliance related risks within Core Technology and Cyber. This role includes independently challenging LOD1 self-assessments and providing effective challenges of CCS to ensure applicable risk types remain within our stated risk appetite. Additionally, this role is responsible for integrating and aligning all cybersecurity risk with business unit risk, controls and assessments. Work in conjunction with other Risk Oversight Officers (RCSA, IRM, MRMD etc.) to ensure a common set of requirements in establishing a comprehensive risk management approach & transparent decision making and prioritization of technology activities.
- 3. Governance and Oversight - Serve as a non-voting member of the first line owned Technology, Data and Operations risk committee, a voting member of the CIRO led risk committee and actively participate in the Enterprise and Board Risk Committees (BRC). This includes (a) reviewing and effectively challenging technology and data risk policies, standards, and procedures, (b) overseeing the assessment and monitoring of critical technology vendors and third-party service providers, and (c) ensuring compliance with regulatory requirements and supervisory guidance related to cybersecurity risk.
- 4. Risk Assessments - Define, communicate and drive the Cyber Risk Frameworks and direct the assessment of information security and cyber risk. Provide independent assessment and oversight of the maturity of CCS and adequacy of cybersecurity controls in meeting agreed business outcomes for cybersecurity. Assessments should leverage agreed upon metrics produced by Business Units (LOD1), but challenge and validated as appropriate.
- 5. Risk Continuous Monitoring - Oversee the evaluation of the cybersecurity strategy and operations for potential risks and biases. Furthermore, monitor the cybersecurity project portfolios, developmental methodologies and progress on project milestones. Lead the review of significant cyber incidents and direct remediation efforts to remediate incident root causes. Using monitoring routines to identify emerging risk and/or consider accelerate risk reviews of technology policies/standards, business processes or control assessments.
- 6. Risk Reporting - Design the standard recurring reporting packages for Cyber Security to support ongoing reporting of identification, mitigation, monitoring of material risks. These reporting packages will be used for internal discussions and/or governance reporting.
- 7. Regulatory Engagement Oversight - Serve as the primary risk point of contact with regulators on cyber risk matters. This includes presenting regular risk assessments and updates to the Board and external stakeholders and collaborating with Truist Audit Services (TAS) / external auditors on cybersecurity reviews. Additionally, this role should provide effective challenge and validation procedures on all regulatory remediations where management actions are being reviewed and validated for closure.
- 8. Talent Management - Lead, manage and develop teammates directly and indirectly. Leverage industry insights to influence enterprise technology talent management through recommendations to Truist senior leadership to inform decisions on resource allocations (both competence and capacity). Where needed, encourage and facilitate Cybersecurity Risk education series, skills training, and industry participation in conference to elevate competence of the risk teammates and enable risk management to meet its objectives of maintaining a strong stature and influence with the company.
- 9. Risk Culture - Promote the culture of Risk Management across the organization by empowering risk teammates to embrace leadership direction, identify risk exposure in everyday operations and champion improving the enterprise programs for building a sustainable business model, meeting the objectives outlines by leadership and the Board of Directors.
Qualifications
Required Qualifications:
- 1. Bachelor’s degree in computer science, Information Systems, or data/technology related field; MBA preferred.
- 2. Fifteen+ (15+) years of progressive experience in cybersecurity relevant roles within a Category 2 or 3 Large Financial Institution (LFI) with a deep understanding of regulatory requirements for complex financial services organization (including both Federal Reserve and FDIC regulations). In depth understanding of how data is captured, transformed, and used and the ability to connect end-to- end processes independently.
- 3. Fifteen+ (15+) years of experience or equivalent proficiency in managing people with demonstrated high competency in recruiting, developing, and coaching/mentoring.
- 4. Fifteen+ (15+) years of experience in a financial institution with emphasis on risk management or equivalent work experience.
- 5. Extensive knowledge on information security, cyber risk, core technology infrastructure, cloud operations, and technology operations.
- 6. Experience in leveraging modern tools to measure effective of technology and cyber controls.
- 7. Experience with enterprise architecture, reference architectures and emerging technologies.
- 8. Knowledge of key technology rules/regulations and technology risk management practices (e.g. Federal Financial Institutions Examination Council (FFIEC), Control Objectives for Information and Related Technology (COBIT), NIST (National Institute of Standards and Technology), Information Technology Infrastructure Library (ITIL).
- 9. Excellent leadership skills including the ability to lead direct and indirect reports, including executive level leaders.
- 10. Excellent communication (verbal and written), presentation and facilitation skills; ability to influence and communicate with impact with C-suite executives and board members. This includes the ability to translate technical concepts for various audiences.
- 11. Excellence in building and leading high-performing teams.
Preferred Qualifications:
- 1. Bachelor’s degree in finance or business equivalent.
- 2. Professional designations such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (Information Systems Audit and Control Association) (CRISC), Certified Project Manager (CPM) Strategic business and financial planning experience.
- 3. Have an innovation mindset and strong understanding of industry recognized tooling to support enterprise data programs and strong control environments.
- 4. Experience with audit processes and techniques.
- 5. Exposure to and experience with adapting cybersecurity capabilities in a post Mythos threat environment.
The annual base salary for this position is $300,000 to $400,000.
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.
#J-18808-Ljbffr$300k - $400k
...Fluency: English (Required)Work Shift:1st shift (United States of America)Please review the following job description:The Chief Cybersecurity Risk Officer (CCRO) is a senior executive position responsible for providing comprehensive risk oversight of the organization's...SuggestedFull timePart timeWork experience placementShift workDay shift$105.4k - $207.8k
...could be the place for you. Traditional security and integrated risk programs have often been unsuccessful in unifying the need to... ...services • Experience responding to and recovering from cybersecurity incidents • Hands-on experience configuring, tuning, and operationalizing...SuggestedLocal areaVisa sponsorship$115k - $145k
...contract lifecycle management, supports vendor performance and risk oversight, and provides clear insight into technology spend,... ...contracts and MSAs to ensure compliance with current insurance, cybersecurity, data protection, SLAs, disaster recovery, termination, and...SuggestedFull timeContract workTemporary workFlexible hours$118.3k - $219.8k
...Manager, Security – Security Compliance & Risk ManagementCore ResponsibilitiesRisk ManagementOwn and operate the enterprise technology... ...timely identification, escalation, and resolution of cybersecurity risks and issues across the organizationServe as a trusted advisor...SuggestedLocal area$148.2k - $292.3k
...enterprise cost strategies for health plan and insurance clients Review and apply trend forecasting, predictive modeling, underwriting, and risk analysis methodologies to support client decision-making Advise clients on alternative plan designs, reimbursement models, and value...SuggestedLocal areaVisa sponsorship$100.4k - $197.9k
Position Summary Our Human Capital practice is at the forefront of transforming the nature of work. As converging forces reshape industries, our team uniquely addresses the complexities of work, workforce, and workplace dynamics. We leverage sector-specific insights...Local areaVisa sponsorship$180.2k - $355.1k
...enterprise cost strategies for health plan and insurance clients Review and apply trend forecasting, predictive modeling, underwriting, and risk analysis methodologies to support client decision-making Advise clients on alternative plan designs, reimbursement models, and value...Local areaVisa sponsorship- ...benefits, retirement, and private client insurance solutions to organizations and individuals seeking limitless possibilities. With offices across North America, we combine the personalized service model of a local consultant with the global resources of the world's...Permanent employmentWork at officeLocal areaFlexible hoursNight shift
- ...benefits, retirement, and private client insurance solutions to organizations and individuals seeking limitless possibilities. With offices across North America, we combine the personalized service model of a local consultant with the global resources of the world's...Permanent employmentWork at officeLocal areaFlexible hoursNight shift
$81.07k - $129.71k
...and anomalies. Executes control activities to support Enterprise Risk Management. Provides analytic support for corporate and... ..., and future focused. In a Hybrid-Flex role, you'll work in the office at least two days a week for collaboration and connection. In a...Work at officeLocal areaRemote workFlexible hours2 days per week- ...providing expert guidance, and supporting workforce needs with top-tier staffing services. Our expertise spans system administration, cybersecurity, networking, and IT operations. We empower our clients to achieve their technology goals with a client-focused approach that...Contract workRemote work
$80k - $167k
...opportunity to contribute to the company’s success. As a Credit Risk Review Advisor Senior within PNC's Independent Risk Management organization... ...to effectively communicate with stakeholders.PNC is an in-office company that fosters a supportive culture where employees can...Full timeTemporary workPart timeWork experience placementWork at office$87.5k - $202.8k
...opportunity to contribute to the company’s success. As a Credit Risk Review Advisor within PNC's Independent Risk Management organization... ...to effectively communicate with stakeholders.PNC is an in-office company that fosters a supportive culture where employees can thrive...Full timeTemporary workPart timeWork experience placementWork at office$100.4k - $197.9k
...models 1 year of experience developing client deliverables, including reports and presentations 1 year of experience using Microsoft Office products, including Word, Excel, and PowerPoint The wage range for this role takes into account the wide range of factors that are...Work at officeLocal areaVisa sponsorship$128k - $252.5k
...care finance 2+ years of experience in project management, presentations, and facilitation 2+ years of experience using Microsoft Office products, including Word, Excel, and PowerPoint The wage range for this role takes into account the wide range of factors that are...Work at officeLocal areaVisa sponsorship$65 - $66 per hour
IT Security Analyst Raleigh, North Carolina, United States $ 65.00 - 66.00 (US Dollar) About the Job IT Security Analyst IT Security Analyst needs 3+ years experience IT Security Analyst requires: IT security Cyber security Banking industry Finance...$101k - $203k
...RSM.Position OverviewAs a Manager in RSM’s expanding Process Risk and Controls Practice, you will play a key role in helping clients... ..., and leading practicesPartner with internal audit teams, chief risk officers, SOX program leaders, and other stakeholders to strengthen...Full timeWork experience placementInternshipLocal areaRemote workFlexible hours$102.7k - $164.6k
...Language (Other than English):**None**Travel Requirement:**0% - 25%**PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS****Position Type**Office-basedTeaches / trains others regularlyFrequentlyTravel regularly from the office to various work sites or from site-to-...Work at officeRemote workWork from homeShift work- ...that impact regulatory reports, ensuring controls are in place, validating reported numbers, and supporting ongoing data quality and risk management processes. The role is heavily data focused, emphasizing functional knowledge of regulatory data and reporting...Permanent employmentFull timePart timeH1bWork visaShift workDay shift
$111.2k - $190.3k
...delivers the technology that enables high quality external assurance engagements across the U.S. and the global network. The Manager of Risk & Compliance supports Assurance Digital by executing certification and compliance activities for products and platforms under...Full timeWork experience placementInternshipLocal area$157.98k - $252.77k
...Job Description Blue Cross NC is hiring a Director, Risk Management to lead the design, execution, and continuous improvement of the... ..., and future focused. In a Hybrid-Flex role, you’ll work in the office at least two days a week for collaboration and connection. In a...Work at officeLocal areaRemote workFlexible hours2 days per week- ...Job DetailsJob Location: Administrative Office - Canton, NC 28716Position Type: Full TimeJob Shift: DayJob Category: BankingJob Description... ...regulatory compliance, identify and mitigate financial crime risk, and provide assurance regarding the effectiveness of key...Contract workWork at officeShift work
- ...Regional Risk Management ActivitiesResponsible for providing senior level guidance, direction, and assistance on regional risk management... ...activities within the area of responsibility for the Regional Office (RO).Serves as technical advisor to the Director with primary...Work at office
- ...Job PositionThis position is located in the Risk Management Agency (RMA), Deputy Administrator for Insurance Services (DAIS), Raleigh, NC Risk Management Region which serves the states of CT, DE, ME, MD, MA, NH, NJ, NY, NC, PA, RI, VT, VA, and WV. This position is designated...
$157.5k - $205k
...stakeholder.What you’ll be responsible for:As Manager, GRM AI Transformation, you will help lead the reinvention of how Circle’s Global Risk Management (GRM) organization operates — moving it from today’s manually intensive processes to an AI-native operating model in...Flexible hoursShift work$85.77k - $153.09k
...Role:Grade Level (for internal use):11The Role: Manager, Insurance Risk Management The Team: The Risk Management team operates as a... ...requirement assessmentHybrid: This role requires work from the office for 2days a week or 9days a month.Right to Work Requirements:This...Full timeContract workSecond jobLive inWork at officeWorldwideFlexible hours$134k - $348.5k
Industry/SectorNot ApplicableSpecialismAssuranceManagement LevelDirectorJob Description & SummaryAt PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and solutions. They help organisations...Full timeTemporary workH1b$140k - $170k
...70,000.00 Annual SalaryJob Description Summary:The Construction Risk Manager will: Support operations and preconstruction teams in one... ...organizational skillsComputer-literacy; knowledge of Microsoft Office SuiteTakes initiative and finds solutions to potential problemsResearch...Full timeContract workTemporary workWork at officeFlexible hours- ...people in homes and keep them there. We’re looking for a Credit Risk Analyst in Raleigh, NC to join us in fulfilling our mission,... ...protected characteristics. Why Work at Enact Hybrid work schedule (in‑office days Tues/Wed/Thurs) Generous Time Off 40 Hours of Volunteer...Work at officeFlexible hours
- ...potential impact on the future business trajectory. Analyze customer, product, and funnel data to proactively identify trends, highlight risks and opportunities, and develop a well-informed revenue and margin forecast. Prepare forecasts and analysis on industry and general...Full timeTemporary workWork experience placementRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Cybersecurity Risk Officer. Be the first to apply!
- director of risk management Raleigh, NC
- director credit risk Raleigh, NC
- enterprise risk manager Raleigh, NC
- operational risk manager Raleigh, NC
- risk management specialist Raleigh, NC
- risk management manager Raleigh, NC
- head of risk management Raleigh, NC
- risk management associate Raleigh, NC
- technology risk Raleigh, NC
- at risk youth Raleigh, NC

