Head of Cyber and IT Risk Management (SVP)

Posted 2 days ago

madisondavisNew York (NY)

SENIORITY

Manager

Apply

About the role

A leading financial-services organization is seeking a Senior Vice President to lead its Cyber and IT Risk Management function. This executive will provide independent risk oversight and credible challenge across technology and cybersecurity, helping the organization identify, assess, communicate, monitor, and mitigate material risks across a complex technology environment. The position requires a combination of technical credibility, enterprise-risk expertise, executive communication, and results-oriented leadership. The successful candidate will lead a blended team while partnering with technology, cybersecurity, operational risk, enterprise risk, Internal Audit, and senior executives.
Responsibilities: Lead the enterprise Cyber and IT Risk Management function Establish the strategy, operating model, and priorities for technology-risk oversight Assess inherent and residual technology and cybersecurity risks Evaluate the design and operating effectiveness of mitigating controls Provide constructive, evidence-based challenge to technology and cybersecurity leaders Lead technology and cyber risk assessments Establish risk-based testing, monitoring, and analytics Identify risk concentrations, emerging risks, and control weaknesses Translate complex technical issues into clear business and enterprise-risk terms Communicate material risks and remediation priorities to senior executives and governance forums Evaluate cybersecurity processes, vulnerabilities, incidents, architecture, and controls Challenge risk acceptance and remediation decisions when residual risk remains excessive Drive complex and long-running remediation initiatives through closure Track whether risk initiatives produce measurable risk reduction Partner across technology, cybersecurity, enterprise risk, operational risk, and Internal Audit Lead and develop a distributed team of employees, contractors, and offshore resources Improve accountability and effectiveness across the risk-management function
Role Requirements: Significant leadership experience in cyber risk, IT risk, technology risk, operational risk, or a closely related discipline Strong understanding of enterprise and operational risk management Technical experience or foundation in cybersecurity, engineering, infrastructure, development, architecture, or a similar field Ability to assess complex technology environments and identify material risks Experience evaluating control design, operating effectiveness, mitigating controls, and residual risk Broad knowledge of cybersecurity practices and control domains Experience leading risk assessments, testing, monitoring, analytics, and remediation Ability to provide credible challenge to senior executives Demonstrated success driving risk initiatives and remediation through completion Strong executive-level communication and presentation skills Experience within financial services or another highly regulated enterprise Knowledge of NIST CSF, FFIEC, or comparable cyber and financial-services risk frameworks Experience leading employee, contractor, and distributed resources Ability to work onsite in the Dallas–Fort Worth area approximately three days per week Ability to travel periodically to California
Nice to Have: Banking experienceCISA, CISSP, CRISC, CDPSE, or comparable certification Experience across first, second, and third lines of defense Executive risk or governance-committee presentation experience Offshore-team leadership Public-cloud security-risk experience Risk-analytics and risk-based control-testing transformation

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this