Information Technology Risk 1LoD Lead

Posted today

natixis corporate investment bankingNew York (NY)

SENIORITY

Manager

SALARY

$185,000 - $210,000

Apply

About the role

We are seeking a highly skilled, experienced, and strategic Technology Risk (LoD1) and Software Asset Management (SAM) Lead role in safeguarding the Natixis CIB Americas IT landscape and ensuring compliance with complex industry regulations. In this executive-level role, you will serve as the primary interface for the Line of Defense 1.1 Group (comprising the Groupe BPCE and Natixis CIB Head Office in Paris) and Line of Defense 2 (including the CISO, Operational Risk, and Compliance teams) regarding IT risk taxonomies, framework alignment, and risk remediation. You will be vital to ensuring the robust security and compliance of Natixis CIB Americas IT, managing high-value software assets effectively, and mitigating risks associated with information technology operations. The successful candidate will possess a deep understanding of IT risk frameworks, software licensing agreements, and industry best practices. You will lead the implementation of the Group IT Risk Management (ITRM) Framework, tailoring it to meet specific business and regional needs, while driving initiatives to assess, monitor, and enhance IT controls across the Americas platform.
Key Responsibilities: Strategy and Risk GovernanceIT Risk Strategy: Strengthen and execute the IT risk management strategy in strict alignment with Head Office (Groupe BPCE and Natixis CIB), organizational goals, and evolving regulatory expectations. Lead Software Asset Management: Oversee the Americas SAM program, including process optimization, governance frameworks, and strategic contribution to the associated corporate policies managed at LoD2.Conduct Comprehensive Assessments: Participate in, and periodically lead, risk assessments, vulnerability assessments, and audits to identify potential IT risks, propose robust mitigation plans, and recommend appropriate controls. Prioritize Systemic Risks: Oversee and assist in the identification, analysis, and prioritization of risks associated with critical IT systems, proprietary software applications, and third-party vendors.
Process Optimization and Technical Execution: Establish Runbooks and Procedures: Develop, document, and maintain rigorous IT risk management procedures and associated operational runbooks in accordance with industry regulations and global bank standards. Enforce SAM Lifecycle Management: Oversee the complete lifecycle of software assets from acquisition to retirement, ensuring compliance with complex licensing agreements, mitigating financial exposure, and optimizing usage in alignment with Head Office processes. Perform System Integrity Checks: Conduct daily health and completeness checks for all software assets within the IT Asset Management (ITAM) platform. Manage System Enhancements: Drive feature enhancements for the ITAM tool, collaborating closely with IT teams to prioritize, test, and implement functional improvements, particularly within the SAM space.
Collaboration, Reporting, and Compliance: Facilitate Asset Recertification: Coordinate the ITAM Annual Recertification process in partnership with IT asset owners to ensure the ongoing integrity, compliance, and accuracy of software inventories. Partner with Key Stakeholders: Liaise with business, risk, and IT stakeholders to facilitate IT controls reviews, ensuring all regulatory and internal controls are met, documented, and reported. Deliver Senior-Level Reporting: Prepare and present risk and control reports, including Data Risk Strategy (DRS) and operational risk reports, for executive and senior management. Manage Risk Acceptances: Evaluate, document, and submit risk acceptances for the Chief Information Officer (CIO) Office, ensuring detailed justification for any temporary exceptions. Enhance Operational Security: Coordinate the implementation and knowledge-transfer processes for Multi-Factor Authentication (MFA) across relevant applications to continuously strengthen the perimeter. Remediate EOL Exposures: Perform random sampling and quality assurance on the End-of-Life (EOL) remediation tracking systems to ensure effective hazard mitigation.
Training, Culture, and Continuous Improvement: Foster an Accountability Culture: Develop and deliver targeted training programs to educate teams on IT risk management, regulatory expectations, and software licensing compliance, fostering a pervasive culture of risk awareness. Monitor Emerging Trends: Stay at the forefront of industry trends, emerging technologies, regulatory shifts, and best practices in risk management and software licensing.
Required Qualifications
Education and Experience: Ideally, a Bachelor’s degree in Information Technology, Computer Science, Business Administration, or a related field (a Master’s degree or equivalent graduate degree is highly preferred).A minimum of 10 years of comprehensive experience in Information Technology, featuring hands-on expertise in IT risk management and software asset management, complemented by progressive leadership or team-management experience. Strong experience working within highly regulated financial environments, specifically with frameworks and compliance requirements mandated by the FFIEC, the Federal Reserve, and other key banking regulators.
Technical Skills and Certifications: Extensive knowledge of recognized IT risk frameworks (e.g., NIST, ISO 27001, and FFIEC) and complex software licensing models (including cloud, hybrid, and on-premises environments).Active professional certifications such as Certified in Risk and Information Systems Control (CRISC), Certified Data Privacy Solutions Engineer (CDPSE), Certified Software Asset Manager (CSAM), or closely equivalent industry credentials. Proven familiarity with cloud technologies, particularly Software as a Service (SaaS) models, subscription management, and associated financial optimization. Familiarity with architecture governance and enterprise architecture frameworks.
Soft Skills and Leadership Attributes: Demonstrated ability to work independently, prioritize complex tasks under pressure, and consistently meet strict deadlines in a dynamic corporate setting. Exceptional communication and interpersonal skills, with a proven track record of engaging, influencing, and collaborating with diverse stakeholders across regional offices and global headquarters. Strong analytical, problem-solving, and decision-making capabilities, with a talent for translating complex technical risks into clear, actionable business strategies. Solid experience in program management, vendor management, third-party governance, process improvement, and financial expense review. The salary range for this position will be between $185,000 - $210,000. Natixis is required by law to include a reasonable estimate of the compensation range for this role. Actual base salary will vary and will be based on several factors including, but not limited to, relevant experience, education, skills set, applicable licensure and certifications, and other business and organizational needs. Base salary is only one component of our total rewards package. Natixis also offers a generous benefits package, and you may be eligible for a discretionary incentive award depending on company and individual performance.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this