Principal of Access Management Risk
Core
Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company to ensure risks are managed consistent with enterprise risk appetite and regulatory expectations.
Role type
Principal, Second-Line Technology Risk & Access Management
Builds
Independent risk oversight, governance reporting, and control validation for enterprise technology and information security domains.
Domain
Financial Services / Payments / Technology Risk & Information Security
Deliverable
dashboards & analysis
Required skills
Second-line oversight, risk assessment, control validation, regulatory compliance, risk trend analysis, stakeholder management, critical thinking, governance reporting, issue management
Preferred skills
Financial services experience, regulatory frameworks (ISO 27002, PCI DSS, NIST, FFIEC, SOC 2), audit support, risk/security certifications (CISA, CISM, CISSP, CRISC)
Technologies
N/A
Responsibilities
Provide independent review and challenge of first-line technology risk management activities; Evaluate design and execution of risk management practices against enterprise frameworks; Assess adequacy of severity ratings and root cause analyses for technology issues; Identify risk trends and emerging themes through data analysis; Prepare reporting and escalation materials for senior leaders and governance forums; Partner with first-line leaders to improve control expectations and testing scope; Recommend opportunities to strengthen risk awareness and governance routines.
Seniority
Principal, hands-on IC with strategic oversight