Chief Cybersecurity Risk Officer
$300k - $400kFayette Chamber of Commerce
Language Fluency: English (Required)
Work Shift: 1st shift (United States of America)
Job Grade: 116
Please review the following job description:
The Chief Cybersecurity Risk Officer (CCRO) is a senior executive position responsible for providing comprehensive risk oversight of the organization’s cybersecurity organization. Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the institution’s strategic objectives.
This role will serve as the Risk Oversight Leader for all functions within Cybersecurity. This role will lead and implement the cyber risk oversight for Truist which includes: 1) Serve as the Chief Cybersecurity Risk Officer with independent oversight and challenge to the Chief Information Security Officer (CISO) for all risk types; 2) Establish and manage cyber risk oversight – inclusive of delivery of independent assessments and continuous monitoring; 3) Provide guidance to senior leaders across the company on critical cybersecurity issues for both internal and external stakeholders; 4) Use judgement to elevate significant issues and emerging risks; communicate cyber domain maturity and residual risk to senior management including up to the Board of Directors; 5) consistently and appropriately apply second line of defense corporate authority for managing Truist’s cyber risk.
Essential Duties and Responsibilities
1. Strategic Leadership
Develop and maintain the enterprise technology management framework, incorporating emerging risks related to cyber security. Establish risk appetite statements, key risk indicators, and thresholds for cyber security across the organization. Provide independent assessment and challenge of cyber security initiatives, ensuring alignment with risk appetite and regulatory expectations. Lead the evaluation of strategic cyber security decisions and their impact on the organization’s risk profile.
2. Risk Leadership
Provide independent risk oversight (i.e., second line of defense/LOD2) for Truist Protection Services (TPS) through the effective identification, mitigation, monitoring and reporting of operational, technology and compliance related risks within Core Technology and Cyber. This role includes independently challenging LOD1 self-assessments and providing effective challenges of CCS to ensure applicable risk types remain within our stated risk appetite.
Additionally, this role is responsible for integrating and aligning all cybersecurity risk with business unit risk, controls and assessments. Work in conjunction with other Risk Oversight Officers (RCSA, IRM, MRMD etc.) to ensure a common set of requirements in establishing a comprehensive risk management approach & transparent decision making and prioritization of technology activities.
3. Governance and Oversight
Serve as a non-voting member of the first line owned Technology, Data and Operations risk committee, a voting member of the CIRO led risk committee and actively participate in the Enterprise and Board Risk Committees (BRC). This includes (a) reviewing and effectively challenging technology and data risk policies, standards, and procedures, (b) overseeing the assessment and monitoring of critical technology vendors and third-party service providers, and (c) ensuring compliance with regulatory requirements and supervisory guidance related to cybersecurity risk.
4. Risk Assessments
Define, communicate and drive the Cyber Risk Frameworks and direct the assessment of information security and cyber risk. Provide independent assessment and oversight of the maturity of CCS and adequacy of cybersecurity controls in meeting agreed business outcomes for cybersecurity. Assessments should leverage agreed upon metrics produced by Business Units (LOD1), but challenge and validated as appropriate.
5. Risk Continuous Monitoring
Oversee the evaluation of the cybersecurity strategy and operations for potential risks and biases. Furthermore, monitor the cybersecurity project portfolios, developmental methodologies and progress on project milestones. Lead the review of significant cyber incidents and direct remediation efforts to remediate incident root causes. Using monitoring routines to identify emerging risk and/or consider accelerate risk reviews of technology policies/standards, business processes or control assessments.
6. Risk Reporting
Design the standard recurring reporting packages for Cyber Security to support ongoing reporting of identification, mitigation, monitoring of material risks. These reporting packages will be used for internal discussions and/or governance reporting.
7. Regulatory Engagement Oversight
Serve as the primary risk point of contact with regulators on cyber risk matters. This includes presenting regular risk assessments and updates to the Board and external stakeholders and collaborating with Truist Audit Services (TAS) / external auditors on cybersecurity reviews. Additionally, this role should provide effective challenge and validation procedures on all regulatory remediations where management actions are being reviewed and validated for closure.
8. Talent Management
Lead, manage and develop teammates directly and indirectly. Leverage industry insights to influence enterprise technology talent management through recommendations to Truist senior leadership to inform decisions on resource allocations (both competence and capacity). Where needed, encourage and facilitate Cybersecurity Risk education series, skills training, and industry participation in conference to elevate competence of the risk teammates and enable risk management to meet its objectives of maintaining a strong stature and influence with the company.
9. Risk Culture
Promote the culture of Risk Management across the organization by empowering risk teammates to embrace leadership direction, identify risk exposure in everyday operations and champion improving the enterprise programs for building a sustainable business model, meeting the objectives outlines by leadership and the Board of Directors.
Qualifications
Required Qualifications
1. Bachelor’s degree in computer science, Information Systems, or data/technology related field; MBA preferred.
2. Fifteen+ (15+) years of progressive experience in cybersecurity relevant roles within a Category 2 or 3 Large Financial Institution (LFI) with a deep understanding of regulatory requirements for complex financial services organization (including both Federal Reserve and FDIC regulations). In depth understanding of how data is captured, transformed, and used and the ability to connect end-to-end processes independently.
3. Fifteen+ (15+) years of experience or equivalent proficiency in managing people with demonstrated high competency in recruiting, developing, and coaching/mentoring.
4. Fifteen+ (15+) years of experience in a financial institution with emphasis on risk management or equivalent work experience.
5. Extensive knowledge on information security, cyber risk, core technology infrastructure, cloud operations, and technology operations.
6. Experience in leveraging modern tools to measure effective of technology and cyber controls.
7. Experience with enterprise architecture, reference architectures and emerging technologies.
8. Knowledge of key technology rules/regulations and technology risk management practices (e.g. Federal Financial Institutions Examination Council (FFIEC), Control Objectives for Information and Related Technology (COBIT), NIST (National Institute of Standards and Technology), Information Technology Infrastructure Library (ITIL).
9. Excellent leadership skills including the ability to lead direct and indirect reports, including executive level leaders.
10. Excellent communication (verbal and written), presentation and facilitation skills; ability to influence and communicate with impact with C-suite executives and board members. This includes the ability to translate technical concepts for various audiences.
11. Excellence in building and leading high-performing teams
Preferred Qualifications
1. Bachelor’s degree in finance or business equivalent.
2. Professional designations such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (Information Systems Audit and Control Association) (CRISC), Certified Project Manager (CPM) Strategic business and financial planning expertise.
3. Have an innovation mindset and strong understanding of industry recognized tooling to support enterprise data programs and strong control environments.
4. Experience with audit processes and techniques
5. Exposure to and experience with adapting cybersecurity capabilities in a post Mythos threat environment.
The annual base salary for this position is $300,000 to $400,000.
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation
All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.
#J-18808-Ljbffr- ...Baker Tilly is seeking a Risk Advisory Services Principal to lead a fast-growing practice. You will provide strategic direction, manage client engagements and drive growth across healthcare, life sciences or technology sectors. You will mentor teams, oversee risk assessments...Suggested
- ...procedures. Advise and oversee audit huddle to disseminate audit information and procedures. Provide support for information and cybersecurity analytical reviews, troubleshooting and research. Work with InfoSec security tools and applications. Incorporates the design of...SuggestedLocal area
- ...Job Summary: We are looking for a skilled cybersecurity professional with relevant technical... ...development programs. While your path in the Office of Information Security will be unique... ...offices within the department.Conduct Risk Management analysis to identify areas of...SuggestedWork experience placementWork at officeLocal area
$94.4k - $129.8k
...projects and assessments as a security consultant or advisor on risk. Researches general and industry specific security trends.... ...assessment of supplier control environments. Working knowledge of cybersecurity governance, risk, and compliance practices, including the...SuggestedOngoing contractTemporary work- ...Summary Of Purpose: Summary Of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance to protect the organization's mission-critical operations in the nuclear power industry. The position, a combination...SuggestedWork experience placement
- ...protection. Maintain dashboards, alerts, and reports for proactive risk detection and escalation. Vulnerability & Risk Management... ...Qualifications Bachelor’s degree in Information Security, Cybersecurity, IT, or a related field (or equivalent experience). Hands-...
$120k - $135k
...world’s first InsurSec provider designed from the ground up to help businesses tackle cyber risk head on. By combining industry-leading insurance with world-class cybersecurity technology, At-Bay offers end-to-end prevention and protection for the digital age. With 98%...$150k - $185k
...world’s first InsurSec provider designed from the ground up to help businesses tackle cyber risk head on. By combining industry-leading insurance with world-class cybersecurity technology, At-Bay offers end-to-end prevention and protection for the digital age. With 98%...- HYBRID ROLE BASED OUT OF OUR ATLANTA OFFICE Job Purpose: Our Senior Cyber Defense & Risk Analyst is responsible for strengthening Veritiv’s security posture through both cybersecurity operations and governance, risk, and compliance. This position partners closely...Work experience placementWork at office
- ...our data and systems. You will implement security controls, conduct regular audits, and respond to incidents as part of a proactive risk management program. The role requires 2–3 years in information security, strong communication with both technical and non-technical...
- ...our Enterprise Sales Organization to focus on growing our cybersecurity and risk consulting practice. The Strategic Account Manager is responsible... ..., audit committee members, compliance leaders, privacy officers, and business unit executives to enable multi-threaded...Contract workWork at office
$220k - $250k
...Job Description Job Description Direct Counsel is seeking a Digital Risk Advisory & Cybersecurity Associate with 3–6 years of experience to join a nationally recognized privacy and cybersecurity practice. This is an exceptional opportunity for an attorney interested...$100k - $130k
...role is hybrid. You will be expected to report to one of our Aflac offices located in Columbus, GA for at least 60% of the work week. You... ...actuarial and financial models that effectively evaluate risk. Project Management - Advanced Can effectively lead projects, including...Work experience placementWork from homeFlexible hours$66.24k - $114.26k
...Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual...Temporary workWork experience placementWork at officeLocal area2 days per week1 day per week- ...AnalystThis individual contributor is primarily responsible for assisting in researching and determining the likelihood of financial risk to the organization, supporting actuarial documentation, product line evaluation, and actuarial modeling, and assisting in financial...
$66.24k - $99.36k
...Indianapolis, IN; Louisville, KY; St. Louis, MO; Mason, OH; Norfolk, VA; Richmond, VA; Waukesha, WIThis role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life...Work experience placementInternshipWork at officeLocal area2 days per week1 day per week$66.24k - $99.36k
...Indianapolis, IN; Louisville, KY; St. Louis, MO; Mason, OH; Norfolk, VA; Richmond, VA; Waukesha, WI This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life...Temporary workWork experience placementInternshipWork at officeLocal area2 days per week1 day per week$73.5k - $147k
...actuarial consulting analyst which can be located in East Coast Mercer offices.What can you expect?Managing client projects that focus on... ...concepts to a non-technical audienceMarsh is a global leader in risk, reinsurance and capital, people and investments, and management...Minimum wageWork experience placementWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week- ...At AIG, we are reimagining the way we help customers to manage risk. Join us as a Actuarial Analyst to play your part in that transformation... ..., which is why we ask our team members to be primarily in the office. This approach helps us work together effectively and create a...Contract workWork at office
$62k - $78k
...AIG, we are reimagining the way we help customers to manage risk. Join us as an Actuarial Analyst to take on key... ...Business Actuaries, Modelers, Underwriters, Business Leads, and Chief Underwriting Officers to implement updates, enhancements and efficiencies to pricing...- ...Analyst II Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity,... ...Obtains, verifies, analyzes and models data including risk reporting and forecasting. Calculates monthly claims liability...Temporary workWork at officeLocal area2 days per week1 day per week
- ...PricingThis individual contributor is primarily responsible for providing support for researching and determining the likelihood of financial risk to the organization, reviewing actuarial documentation for accuracy, supporting product line evaluation and actuarial modeling, and...Work experience placement
- ...Actuarial Analyst II Location This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity,... ...an Impact Obtains, verifies, analyzes and models data including risk reporting and forecasting. Calculates monthly claims liability...Temporary workWork at officeLocal area2 days per week1 day per week
$66.24k - $114.26k
...Position Title: Actuarial Analyst I Job Description: Actuarial Analyst I Location: This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life...Temporary workWork experience placementWork at officeLocal area2 days per week1 day per week- ...Translating threat intelligence into actionable detection and defense improvements Reporting, Metrics and dashboarding Vulnerability & risk management (20%) Leading threat & vulnerability management (TVM) activities Risk prioritization, remediation tracking, and...Local areaFlexible hours
- ...vulnerabilitiesTranslating threat intelligence into actionable detection and defense improvementsReporting, Metrics and dashboardingVulnerability & risk management (20%)Leading threat & vulnerability management (TVM) activitiesRisk prioritization, remediation tracking, and stakeholder...Local areaFlexible hours
$175k - $205k
...world’s first InsurSec provider designed from the ground up to help businesses tackle cyber risk head on. By combining industry-leading insurance with world-class cybersecurity technology, At-Bay offers end-to-end prevention and protection for the digital age. With 98%...- ...projects and materials according to Pinnacle's internal filing system Regular, predictable and punctual attendance in a Pinnacle office when not working off-site Supervisory Responsibilities This position does not have supervisory responsibilities....Full timeSummer workInternshipWork at office
- A recruitment firm is seeking a P&C Actuarial Analyst in Atlanta. The role involves performing product development, pricing, modeling, report writing, and data analysis for niche P&C products. Candidates should have 2+ CAS exams and 0–4 years of P&C actuarial experience...Full time
$120k - $150k
...Risk Manager / Senior Risk Analyst Location: Atlanta, Orlando or Tampa (Hybrid) — Remote flexibility available for the right candidate Division : Dealer General Warranty About CV Family & Dealer General Warranty The CV Family Organization is a privately held family of...Contract workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Cybersecurity Risk Officer. Be the first to apply!
- director of risk management Atlanta, GA
- director credit risk Atlanta, GA
- enterprise risk manager Atlanta, GA
- operational risk manager Atlanta, GA
- risk management specialist Atlanta, GA
- risk management manager Atlanta, GA
- head of risk management Atlanta, GA
- risk management associate Atlanta, GA
- senior risk manager Atlanta, GA
- operational risk analyst Atlanta, GA


