FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Director, Technology Risk Management
Finance of America. Lead execution of the Technology Risk Management framework aligned to NIST CSF, FFIEC, and SOX ITGC .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Technology Risk Management, with a focus on aligning frameworks to NIST CSF, FFIEC, and SOX ITGC. Proven ability to translate regulatory expectations into actionable controls while fostering collaboration and continuous improvement across technology and product teams.
Highest-signal resume keywords
Technology Risk ManagementCybersecurity Risk AssessmentCloud Risk ManagementRegulatory Compliance (NIST CSF, FFIEC, SOX ITGC)Team Leadership and Development
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk Appetite DefinitionKey Risk Indicator (KRI) MonitoringData Protection StrategiesAutomation in Risk ManagementControl Maturity Improvement
Soft Skills
Stakeholder ManagementJudgement and Decision-MakingCollaboration and TeamworkCommunication Skills
Tools & Technologies
Risk Management ToolsAudit Management Software
Certifications & Qualifications
CISACRISCCISSP
Industry Keywords
Financial ServicesRegulated EnvironmentsThird-Party RiskEmerging Technology Risk
Tech Stack
Tools & technologiesCloudCyber SecuritySDLC
About the role
Key responsibilities & impact- Lead execution of the Technology Risk Management framework aligned to NIST CSF, FFIEC, and SOX ITGC
- Translate regulatory expectations into pragmatic controls and practices across Technology and Product teams
- Define, operationalize, and monitor technology risk appetite, tolerances, and KRIs
- Oversee enterprise-wide identification and assessment of cloud, infrastructure, cybersecurity, data protection, AI, emerging technology, and third-party/vendor risks
- Deliver data-driven risk insights and reporting on risk posture, trends, and emerging risks to senior leadership
- Drive continuous improvement of control maturity and sustained SOX ITGC effectiveness
- Partner with Technology teams to design and implement scalable, automated controls
- Ensure execution of regulatory exams, internal audits, and remediation commitments
- Oversee issue management, including identification, prioritization, root cause analysis, and sustainable remediation
- Drive timely remediation of high-risk issues and reduction of aged items
- Lead adoption of automation and tooling for risk identification, monitoring, and reporting
- Evaluate and improve technology processes to reduce risk, increase resilience, and enhance operational efficiency
- Integrate risk management into SDLC, product development, and change management processes
- Establish governance and risk oversight for AI and emerging technologies
- Assess risks associated with new technology initiatives and provide guidance for safe adoption
- Partner with Technology and Business leaders to proactively manage risk
- Lead engagement with Internal Audit, External Audit, and second line of defense functions
- Build and develop a high-performing team
- Perform other duties as assigned
Requirements
What you’ll need- Minimum 10 years of experience in Technology Risk, Cybersecurity, IT Audit or related disciplines within financial services or regulated environments
- Proven experience operating in or alongside first line technology functions, with strong business partnership orientation
- Demonstrated success in evolving risk programs to strategic, insight-driven functions
- Deep understanding of cloud and infrastructure risk, cybersecurity and data protection, third-party/vendor risk, and AI/emerging technology risk
- Strong knowledge of FFIEC, NIST CSF, and SOX ITGC
- Ability to translate complex technical risks into clear, concise executive-level reporting
- Strong judgement, with the ability to balance risk management with business enablement
- Proven ability to lead and develop high-performing teams
- Strong stakeholder management skills, with experience engaging senior leadership and regulators
- Able to drive accountability, foster collaboration, and promote a culture of continuous improvement
- Bachelor's Degree
- Relevant certifications such as CISA, CRISC, or CISSP
Benefits
Comp & perks- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- Paid time-off benefits
- Flexible spending account
- 401(k) with employer match
- ESPP