VP, Technology Risk Management


Los Angeles Metro Area
Permanent
USD88000 - USD160000
Risk Management
PR/552855_1757458269
VP, Technology Risk Management

Position Overview

This role is responsible for leading second-line oversight of enterprise-wide Information Technology Risk Management (ITRM). The position encompasses governance and strategic alignment of IT and cybersecurity functions, oversight of IT operations, change and configuration management, and the broader governance, risk, and compliance (GRC) landscape. The individual will collaborate closely with first-line technology risk teams to provide independent challenge and guidance on control design, implementation, and risk mitigation strategies across major IT and cybersecurity initiatives.

The role also includes evaluating the effectiveness of IT and IS controls through substantive testing and contributing to the continuous improvement of risk management practices and frameworks.

Key Responsibilities

Serve as a second-line advisor and challenger to first-line IT and cybersecurity teams on risk and control matters.

Oversee the implementation and maintenance of IT risk management practices across operational, security, and change management domains.

Support the enterprise adoption and integration of GRC platforms, promoting consistent usage and reporting across stakeholders.

Provide subject matter expertise on IT risk management, tailoring guidance to specific business platforms and operational contexts.

Contribute to the development of enterprise IT risk appetite statements and ensure alignment with business objectives.

Produce regular reports on IT risk posture, control effectiveness, and emerging risk themes for senior leadership and governance bodies.

Review and assess IT and cybersecurity control frameworks, documentation, and compliance reporting.

Analyze audit findings, regulatory feedback, and client assessments to identify systemic risk issues and recommend solutions.

Establish monitoring mechanisms to ensure adherence to IT risk policies, standards, and frameworks.

Conduct independent testing of IT general controls and application controls to validate design and operational effectiveness.

Advise on remediation strategies for control gaps and non-compliance areas.

Provide ongoing governance and strategic direction for IT risk management across the organization.

Engage with cross-functional leaders in areas such as disaster recovery, infrastructure, data governance, vendor risk, and change management to inform risk oversight.

Build and maintain strong relationships with business units to support risk-informed decision-making for new initiatives and projects.

Maintain and update second-line owned IT and cybersecurity policies and standards through periodic reviews.

Qualifications

Education:

Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field preferred.

Professional certifications such as CISA, CRISC, or equivalent are highly desirable.

Experience:

Minimum of 5 years in IT risk management, cybersecurity audit, or related roles within regulated industries.

At least 3 years of experience in IT control testing or audit functions.

Strong understanding of IT GRC frameworks and control environments.

Familiarity with regulatory expectations and industry standards, particularly those relevant to financial institutions (e.g., FFIEC, FDIC, CFPB).

FAQs

Congratulations, we understand that taking the time to apply is a big step. When you apply, your details go directly to the consultant who is sourcing talent. Due to demand, we may not get back to all applicants that have applied. However, we always keep your resume and details on file so when we see similar roles or see skillsets that drive growth in organizations, we will always reach out to discuss opportunities.

Yes. Even if this role isn’t a perfect match, applying allows us to understand your expertise and ambitions, ensuring you're on our radar for the right opportunity when it arises.

We also work in several ways, firstly we advertise our roles available on our site, however, often due to confidentiality we may not post all. We also work with clients who are more focused on skills and understanding what is required to future-proof their business. 

That's why we recommend registering your resume so you can be considered for roles that have yet to be created. 

Yes, we help with resume and interview preparation. From customized support on how to optimize your resume to interview preparation and compensation negotiations, we advocate for you throughout your next career move.

Handpicked roles for you