Principal Technology Risk Management - Data Security
Core
Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company to ensure risks are managed consistent with enterprise risk appetite and regulatory expectations.
Role type
Principal Technology Risk Management - Data Security (Second-Line Risk)
Builds
Independent risk oversight, governance reporting, and control validation for technology and data security domains.
Domain
Financial Services / Payments / Technology Risk & Information Security
Deliverable
dashboards & analysis
Required skills
Second-line oversight, risk assessment, control validation, governance reporting, root cause analysis, risk trend identification, stakeholder management, critical thinking, regulatory alignment
Preferred skills
Financial services experience, regulatory framework knowledge (ISO 27002, PCI DSS, NIST, FFIEC, SOC 2), audit support, project management
Technologies
N/A
Responsibilities
Provide independent review and challenge of first-line technology risk activities; Evaluate risk management practices against enterprise frameworks; Assess severity ratings and remediation plans for risk events; Identify risk trends and emerging themes; Prepare reporting materials for senior leaders and risk committees; Partner with first-line leaders to improve control expectations and testing scope.
Seniority
Principal, strategy & mentorship