Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Finance of America

Director, Technology Risk Management

Finance of America

. Lead execution of the Technology Risk Management framework aligned to NIST CSF, FFIEC, and SOX ITGC .

Posted 10/6/2026full-timeRemote • United StatesLead💰 $150,000 - $200,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Technology Risk Management, with a focus on aligning frameworks to NIST CSF, FFIEC, and SOX ITGC. Proven ability to translate regulatory expectations into actionable controls while fostering collaboration and continuous improvement across technology and product teams.

Highest-signal resume keywords
Technology Risk ManagementCybersecurity Risk AssessmentCloud Risk ManagementRegulatory Compliance (NIST CSF, FFIEC, SOX ITGC)Team Leadership and Development

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk Appetite DefinitionKey Risk Indicator (KRI) MonitoringData Protection StrategiesAutomation in Risk ManagementControl Maturity Improvement
Soft Skills
Stakeholder ManagementJudgement and Decision-MakingCollaboration and TeamworkCommunication Skills
Tools & Technologies
Risk Management ToolsAudit Management Software
Certifications & Qualifications
CISACRISCCISSP
Industry Keywords
Financial ServicesRegulated EnvironmentsThird-Party RiskEmerging Technology Risk

Tech Stack

Tools & technologies
CloudCyber SecuritySDLC

About the role

Key responsibilities & impact
  • Lead execution of the Technology Risk Management framework aligned to NIST CSF, FFIEC, and SOX ITGC
  • Translate regulatory expectations into pragmatic controls and practices across Technology and Product teams
  • Define, operationalize, and monitor technology risk appetite, tolerances, and KRIs
  • Oversee enterprise-wide identification and assessment of cloud, infrastructure, cybersecurity, data protection, AI, emerging technology, and third-party/vendor risks
  • Deliver data-driven risk insights and reporting on risk posture, trends, and emerging risks to senior leadership
  • Drive continuous improvement of control maturity and sustained SOX ITGC effectiveness
  • Partner with Technology teams to design and implement scalable, automated controls
  • Ensure execution of regulatory exams, internal audits, and remediation commitments
  • Oversee issue management, including identification, prioritization, root cause analysis, and sustainable remediation
  • Drive timely remediation of high-risk issues and reduction of aged items
  • Lead adoption of automation and tooling for risk identification, monitoring, and reporting
  • Evaluate and improve technology processes to reduce risk, increase resilience, and enhance operational efficiency
  • Integrate risk management into SDLC, product development, and change management processes
  • Establish governance and risk oversight for AI and emerging technologies
  • Assess risks associated with new technology initiatives and provide guidance for safe adoption
  • Partner with Technology and Business leaders to proactively manage risk
  • Lead engagement with Internal Audit, External Audit, and second line of defense functions
  • Build and develop a high-performing team
  • Perform other duties as assigned

Requirements

What you’ll need
  • Minimum 10 years of experience in Technology Risk, Cybersecurity, IT Audit or related disciplines within financial services or regulated environments
  • Proven experience operating in or alongside first line technology functions, with strong business partnership orientation
  • Demonstrated success in evolving risk programs to strategic, insight-driven functions
  • Deep understanding of cloud and infrastructure risk, cybersecurity and data protection, third-party/vendor risk, and AI/emerging technology risk
  • Strong knowledge of FFIEC, NIST CSF, and SOX ITGC
  • Ability to translate complex technical risks into clear, concise executive-level reporting
  • Strong judgement, with the ability to balance risk management with business enablement
  • Proven ability to lead and develop high-performing teams
  • Strong stakeholder management skills, with experience engaging senior leadership and regulators
  • Able to drive accountability, foster collaboration, and promote a culture of continuous improvement
  • Bachelor's Degree
  • Relevant certifications such as CISA, CRISC, or CISSP

Benefits

Comp & perks
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Paid time-off benefits
  • Flexible spending account
  • 401(k) with employer match
  • ESPP