IT and InfoSec Operational Risk Officer

Northwest Opportunities
Columbus, OH Full Time
POSTED ON 4/8/2024

Job Summary

The IT and InfoSec Operational Risk Officer within the second line of defense Operational Risk organization is responsible for the independent oversight of front-line Information Technology (IT) and Information Security (IS) units to socialize risk concepts, frameworks and promote the organizations' risk culture, including education and training.  The IT and InfoSec Operational Risk Officer must adapt previous experience and industry leading practices to fit Northwest. The position also partners with functional and operational leadership in the development of risk mitigation plans, consistent with the Bank's enterprise risk management framework. The role will be an integral part of a risk management team that encourages creativity, leadership, and influence. The role is expected to have a significant impact and influence in bank-wide strategic decision-making, and to support our mission through risk-based and data-driven decision making.

 

Essential Functions

  • Provide companywide oversight and governance over information security and information technology risks
  • Help mature and execute an IT and IS risk management framework using industry leading practices (e.g., NIST CSF, COBIT, SCF) taking into consideration regulatory expectations
  • Independently assess risks and drive actions to address the root causes that persistently lead to significant residual operational risk by challenging both historical and proposed practices
  • Leverage the current ERM framework and partner with first-line IT and IS teams to further mature IT risk assessments, document controls, identify gaps, and create action plans for critical IT and IS processes, including validation and testing to ensure IT risk programs are implemented and executed appropriately
  • Help refine the risk register for IT, IS and operational risk competencies, as well as help create additional ones as appropriate
  • Provide oversight of IT/IS Risk and Control Self-Assessment (RCSA) activities, and monitoring routines (Third Party, Audit, Issue Management, Remediations, etc.)
  • Make recommendations for remediation of issues and continuous monitoring through the creation of metrics
  • Review processes and controls against leading practice and industry frameworks, identify gaps in design and execution, and communicate issues and make recommendations
  • Perform independent risk assessment of the first line, inclusive of emerging risks
  • Review and challenge of first-line risk acceptances
  • Identify trends, themes, tendencies that indicate emerging IT/IS risks by relying on mining trends in relevant metrics, loss data and external events and effectively communicate learnings to Business to drive necessary responses and action
  • Complete risk assessments of critical technology implementations (e.g., Cloud Computing, hybrid infrastructure models, and Active Directory)
  • Provide analysis and reporting of Northwest’s IT and IS risk profile, and consultative advice to Northwest’s Management Team
  • Influence appropriate risk management prioritization by the first line to enable the business to meet strategic objectives, while meeting IT and IS risk program expectations
  • Ensure compliance with Northwest’s policies and procedures, and Federal/State regulations
  • Navigate Microsoft Office Software, computer applications, and software specific to the department to maximize technology tools and gain efficiency
  • Work as part of a team
  • Work with on-site equipment

 

 

Education Experience preferred

  • Bachelor’s degree in Information Technology or related degree
  • 12 – 15 years of banking or regulatory experience
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Risk and Information Systems Control (CRISC)
  • Certified Information Systems Security Personnel

 

#LI-EK1

#LI-Hybrid

Salary.com Estimation for IT and InfoSec Operational Risk Officer in Columbus, OH
$166,863 to $216,988
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs with skills like those required for the IT and InfoSec Operational Risk Officer.

Click the checkbox next to the jobs that you are interested in.

  • Business Analytics Skill

    • Income Estimation: $105,885 - $158,261
    • Income Estimation: $106,933 - $144,672
  • Compliance Management Skill

    • Income Estimation: $92,814 - $151,106
    • Income Estimation: $101,931 - $132,526
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Northwest Opportunities

Northwest Opportunities
Hired Organization Address MARION, IN Full Time
Office Managers build, develop, and motivate their team to provide an excellent experience for our customers/clients and...
Northwest Opportunities
Hired Organization Address LOCKPORT, NY Full Time
Office Managers build, develop, and motivate their team to provide an excellent experience for our customers/clients and...
Northwest Opportunities
Hired Organization Address MISHAWAKA, IN Full Time
Northwest Tellers are important members of our retail network team because they often have the most interaction with our...
Northwest Opportunities
Hired Organization Address Bellevue, PA Full Time
Job Summary The Model Development Manager (MDM) is responsible for managing the Model Development & Analytics (MDA) Team...

Not the job you're looking for? Here are some other IT and InfoSec Operational Risk Officer jobs in the Columbus, OH area that may be a better fit.

IT and InfoSec Operational Risk Officer

Northwest Bank, Columbus, OH

Credit Risk Modelling SME

PRO IT, Columbus, OH