Oh oh! Awesome! Info! {$ msg.text $} ({$ msg.count $})

Director – Risk Data

  • On-site
  • On-site

The Director, IT Line 1 Risk will play a senior leadership role in strengthening the technology risk and control environment by establishing a centralized, authoritative risk and control database that connects issues, controls, remediation activity, operational risk signals, and control implementation details. This role requires a strong combination of technology risk expertise, data and database understanding, control design and testing experience, and the ability to translate daily operational data into timely, decision-ready risk insight for multiple levels of management.
The ideal candidate will have a strong understanding of SDLC, infrastructure, and cybersecurity risks and controls, along with hands-on experience in control automation, continuous control monitoring, risk analytics, and live dashboard development. Experience with large language models, AI agents, and intelligent automation is highly desirable as the organization advances toward more predictive, automated, and data-driven risk management.Key Responsibilities

  • Lead the design, development, and operationalization of a centralized IT risk and control database that serves as the authoritative source for IT issues, risks, controls, control implementation status, remediation activity, and supporting operational data.
  • Define the data model, taxonomy, metadata, lineage, and governance requirements needed to connect risks, controls, issues, incidents, metrics, assessments, audit findings, and remediation actions in a consistent and traceable manner.
  • Identify, ingest, and map risk signals from operational systems such as IT service management, change management, vulnerability management, incident management, project delivery, asset inventory, and control testing platforms.
  • Partner with technology, data architecture, cybersecurity, infrastructure, application development, operations, and risk stakeholders to ensure the risk database is scalable, sustainable, auditable, and aligned to enterprise risk and control frameworks.
  • Establish control implementation tracking capabilities, including control ownership, control design, operating effectiveness, evidence requirements, automation opportunities, and implementation milestones.
  • Drive the automation of control monitoring, control testing, risk assessments, evidence collection, issue tracking, and management reporting to reduce manual effort and improve timeliness, consistency, and accuracy.
  • Develop live dashboards and management reporting views tailored for technology teams, capability owners, senior IT leadership, risk committees, audit, regulatory stakeholders, and executive management.
  • Define and monitor key risk indicators, key control indicators, thresholds, trends, and early warning signals to support proactive risk identification, escalation, and decision-making.
  • Provide credible Line 1 risk challenge and advisory support across SDLC, infrastructure, cybersecurity, operational resilience, change management, access management, vulnerability management, data protection, and incident response controls.
  • Support RCSA, issue management, audit response, regulatory readiness, and remediation governance by ensuring risks, controls, issues, and evidence are clearly documented, linked, and defensible.
  • Evaluate opportunities to apply LLMs, AI agents, analytics, and intelligent automation to improve risk prioritization, control mapping, evidence review, issue classification, dashboard commentary, and predictive risk insight.
  • Represent IT Line 1 Risk in governance forums and communicate complex technology risk, control, and data issues in a clear, concise, and actionable manner for technical and non-technical audiences.

Required Qualifications

  • 10+ years of experience in technology risk, IT controls, cybersecurity risk, infrastructure risk, application risk, technology audit, or a related discipline within a complex technology or financial services environment.
  • Strong understanding of technology risk and control concepts across SDLC, infrastructure, cybersecurity, cloud, operational resilience, change management, access management, vulnerability management, incident management, and data protection.
  • Demonstrated experience designing, implementing, assessing, or overseeing technology controls and control remediation in audit, regulatory, or highly governed environments.
  • Strong database and data management understanding, including data modeling, relational data structures, metadata, data quality, lineage, integration, reporting layers, and governance practices.
  • Experience building or partnering on risk, control, issue, or operational data repositories that aggregate information from multiple technology and risk systems.
  • Experience with control automation, continuous control monitoring, control testing, evidence automation, and reporting automation.
  • Ability to define, interpret, and communicate KRIs, KCIs, KPIs, thresholds, trends, and out-of-tolerance conditions to support effective risk management decisions.
  • Experience creating live dashboards and executive reporting using tools such as Power BI, Tableau, ServiceNow reporting, Archer reporting, or similar analytics and visualization platforms.
  • Strong analytical, problem-solving, and data interpretation skills with the ability to convert operational data into actionable risk insight.
  • Excellent stakeholder management, communication, and influencing skills, with the ability to work across technology, risk, audit, cybersecurity, data, and senior management teams.
  • Strong governance mindset, documentation discipline, and ability to maintain audit-ready and regulator-ready evidence, traceability, and rationale.

Preferred Qualifications

  • Experience in financial services, clearing, settlement, payments, banking, insurance, or another highly regulated industry.
  • Familiarity with enterprise GRC platforms such as Archer, ServiceNow GRC/IRM, or similar risk and control management platforms.
  • Experience with AI, machine learning, large language models, AI agents, or intelligent automation applied to risk management, controls testing, evidence review, data classification, or management reporting.
  • Knowledge of cloud risk, DevSecOps, policy-as-code, CI/CD controls, secure SDLC, and automated control gates within the technology delivery lifecycle.
  • Familiarity with regulatory expectations and industry frameworks related to technology risk, cybersecurity, operational resilience, and controls management.
  • Experience leading cross-functional transformation initiatives involving data architecture, automation, risk governance, and executive reporting.

Critical Capabilities for Success

  • Technology Risk Depth: Understands how failures across SDLC, infrastructure, cybersecurity, and operations translate into business, regulatory, and operational risk.
  • Data and Database Orientation: Can define the structure, relationships, and governance needed to create a trusted risk and control data foundation.
  • Controls and Automation Expertise: Knows how to design, test, monitor, and automate controls across technology processes and platforms.
  • Dashboard and Reporting Acumen: Can translate complex risk data into live, intuitive dashboards and management-ready insights.
  • Execution Leadership: Can stand up a new capability, manage ambiguity, drive cross-functional alignment, and deliver measurable outcomes.
  • Innovation Mindset: Understands how AI, LLMs, and agents can be responsibly applied to improve risk intelligence, control monitoring, and operational efficiency.

Measures of Success

  • Authoritative IT risk and control database established with defined taxonomy, ownership, data lineage, and governance.
  • Risks, controls, issues, incidents, remediation actions, metrics, and evidence are consistently mapped and traceable.
  • Operational risk signals are ingested from key source systems and converted into meaningful KRIs, KCIs, trends, and alerts.
  • Live dashboards are available for multiple management levels and provide timely, accurate, and decision-ready risk insight.
  • Control automation and continuous monitoring reduce manual effort and improve the quality, timeliness, and defensibility of risk reporting.
  • Risk assessments, issue management, audit responses, and regulatory reporting are better supported through consistent data, evidence, and control traceability.
  • AI and automation opportunities are identified and responsibly implemented to enhance predictive risk intelligence and operational efficiency.

Skills & Requirements

Skills and Requirements – add details here

About the company

-

Aarthy Govindhraj | Contact Person

I'm interested