Talent.com
SunTrust Investment Services, Inc.
Chief Cybersecurity Risk OfficerSunTrust Investment Services, Inc. • Richmond, VA, United States
No longer accepting applications
Chief Cybersecurity Risk Officer

Chief Cybersecurity Risk Officer

SunTrust Investment Services, Inc. • Richmond, VA, United States
20 days ago
Job type
  • Full-time
  • Part-time
  • Temporary
Job description

Chief Cybersecurity Risk Officer

The Chief Cybersecurity Risk Officer (CCRO) is a senior executive position responsible for providing comprehensive risk oversight of the organization's cybersecurity organization. Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the institution's strategic objectives. This role will serve as the Risk Oversight Leader for all functions within Cybersecurity. This role will lead and implement the cyber risk oversight for Truist which includes: Serve as the Chief Cybersecurity Risk Officer with independent oversight and challenge to the Chief Information Security Officer (CISO) for all risk types; Establish and manage cyber risk oversight inclusive of delivery of independent assessments and continuous monitoring; Provide guidance to senior leaders across the company on critical cybersecurity issues for both internal and external stakeholders; Use judgment to escalate significant issues and emerging risks; communicate cyber domain maturity and residual risk to senior management including up to the Board of Directors; consistently and appropriately apply second line of defense corporate authority for managing Truist's cyber risk.

Essential Duties and Responsibilities

Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.

1. Strategic Leadership - Develop and maintain the enterprise technology management framework, incorporating emerging risks related to cyber security. Establish risk appetite statements, key risk indicators, and thresholds for cyber security across the organization. Provide independent assessment and challenge of cyber security initiatives, ensuring alignment with risk appetite and regulatory expectations. Lead the evaluation of strategic cyber security decisions and their impact on the organization's risk profile.

2. Risk Leadership - Provide independent risk oversight (i.e., second line of defense/LOD2) for Truist Protection Services (TPS) through the effective identification, mitigation, monitoring and reporting of operational, technology and compliance related risks within Core Technology and Cyber. This role includes independently challenging LOD1 self-assessments and providing effective challenges of CCS to ensure applicable risk types remain within our stated risk appetite.

Additionally, this role is responsible for integrating and aligning all cybersecurity risk with business unit risk, controls and assessments. Work in conjunction with other Risk Oversight Officers (RCSA, IRM, MRMD etc.) to ensure a common set of requirements in establishing a comprehensive risk management approach & transparent decision making and prioritization of technology activities.

3. Governance and Oversight - Serve as a non-voting member of the first line owned Technology, Data and Operations risk committee, a voting member of the CIRO led risk committee and actively participate in the Enterprise and Board Risk Committees (BRC) This includes (a) reviewing and effectively challenging technology and data risk policies, standards, and procedures, (b) overseeing the assessment and monitoring of critical technology vendors and third-party service providers, and (c) ensuring compliance with regulatory requirements and supervisory guidance related to cybersecurity risk.

4. Risk Assessments - Define, communicate and drive the Cyber Risk Frameworks and direct the assessment of information security and cyber risk. Provide independent assessment and oversight of the maturity of CCS and adequacy of cybersecurity controls in meeting agreed business outcomes for cybersecurity. Assessments should leverage agreed upon metrics produced by Business Units (LOD1), but challenge and validated as appropriate.

5. Risk Continuous Monitoring - Oversee the evaluation of the cybersecurity strategy and operations for potential risks and biases. Furthermore, monitor the cybersecurity project portfolios, developmental methodologies and progress on project milestones. Lead the review of significant cyber incidents and direct remediation efforts to remediate incident root causes. Using monitoring routines to identify emerging risk and/or consider accelerate risk reviews of technology policies/standards, business processes or control assessments.

6. Risk Reporting - Design the standard recurring reporting packages for Cyber Security to support ongoing reporting of identification, mitigation, monitoring of material risks. These reporting packages will be used for internal discussions and/or governance reporting.

7. Regulatory Engagement Oversight - Serve as the primary risk point of contact with regulators on cyber risk matters. This includes presenting regular risk assessments and updates to the Board and external stakeholders and collaborating with Truist Audit Services (TAS) / external auditors on cybersecurity reviews. Additionally, this role should provide effective challenge and validation procedures on all regulatory remediations where management actions are being reviewed and validated for closure.

8. Talent Management - Lead, manage and develop teammates directly and indirectly. Leverage industry insights to influence enterprise technology talent management through recommendations to Truist senior leadership to inform decisions on resource allocations (both competence and capacity). Where needed, encourage and facilitate Cybersecurity Risk education series, skills training, and industry participation in conference to elevate competence of the risk teammates and enable risk management to meet its objectives of maintaining a strong stature and influence with the company.

9. Risk Culture - Promote the culture of Risk Management across the organization by empowering risk teammates to embrace leadership direction, identify risk exposure in everyday operations and champion improving the enterprise programs for building a sustainable business model, meeting the objectives outlines by leadership and the Board of Directors.

Qualifications

Required Qualifications:

The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

1. Bachelor's degree in computer science, Information Systems, or data/technology related field; MBA preferred.

2. Fifteen+ (15+) years of progressive experience in cybersecurity relevant roles within a Category 2 or 3 Large Financial Institution (LFI) with a deep understanding of regulatory requirements for complex financial services organization (including both Federal Reserve and FDIC regulations). In depth understanding of how data is captured, transformed, and used and the ability to connect end-to-end processes independently.

3. Fifteen+ (15+) years of experience or equivalent proficiency in managing people with demonstrated high competency in recruiting, developing, and coaching/mentoring.

4. Fifteen+ (15+) years of experience in a financial institution with emphasis on risk management or equivalent work experience.

5. Extensive knowledge on information security, cyber risk, core technology infrastructure, cloud operations, and technology operations.

6. Experience in leveraging modern tools to measure effective of technology and cyber controls.

7. Experience with enterprise architecture, reference architectures and emerging technologies.

8. Knowledge of key technology rules/regulations and technology risk management practices (e.g. Federal Financial Institutions Examination Council (FFIEC), Control Objectives for Information and Related Technology (COBIT), NIST (National Institute of Standards and Technology), Information Technology Infrastructure Library (ITIL).

9. Excellent leadership skills including the ability to lead direct and indirect reports, including executive level leaders.

10. Excellent communication (verbal and written), presentation and facilitation skills; ability to influence and communicate with impact with C-suite executives and board members. This includes the ability to translate technical concepts for various audiences.

11. Excellence in building and leading high-performing teams

Preferred Qualifications:

1. Bachelor's degree in finance or business equivalent.

2. Professional designations such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (Information Systems Audit and Control Association) (CRISC), Certified Project Manager (CPM) Strategic business and financial planning experience.

3. Have an innovation mindset and strong understanding of industry recognized tooling to support enterprise data programs and strong control environments.

4. Experience with audit processes and techniques

5. Exposure to and experience with adapting cybersecurity capabilities in a post Mythos threat environment.

The annual base salary for this position is $300,000 to $400,000.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist's generous benefit plans, please visit our Benefits site . Depending on the position and division, this job may also be eligible for Truist's defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age

Create a job alert for this search

Chief Cybersecurity Risk Officer • Richmond, VA, United States

Similar jobs

Shift Leader

Pizza HutColonial Heights, VA, United States
Full-time

E ELLERSLIE AVE, Colonial Heights, VA.Flynn Hut joined the Pizza Hut system in 2021.In 2023, we expanded internationally acquiring Pizza Hut's master franchisee in Australia with 260+ units.Today w... Show more

 • Promoted

Shift Leader (P1-1361620-0)

Panda Restaurant GroupChester, VA, United States
Full-time

Our Panda Shift Leader associates are important leaders of our team and are responsible for bringing Panda's mission alive in our restaurants by supporting management in creating food with passion,... Show more

 • Promoted

Cyber Digital Trust & Online Safety Manager

DeloitteRichmond, VA, United States
Full-time

The job title is not provided in the raw HTML.Deloitte is committed to providing reasonable accommodations for people with disabilities.If you require a reasonable accommodation to participate in t... Show more

 • Promoted

Cybersecurity Program Manager Controls Testing

Rapid StrategyRichmond, VA, United States
Full-time

The Cybersecurity Program Manager will oversee and coordinate the execution of a cybersecurity program focused on both controls testing and penetration testing for a government client.This role req... Show more

 • Promoted

Cybersecurity Engineer (Remote)

GSK SolutionsRichmond, VA, United States
Remote
Full-time

Job Title:Cybersecurity Engineer (Remote) Location:Richmond, VA Duration:3 months Interview Process:Web Cam Interview Only Note:ON SITE:Monthly meetings and on site as requested by mgr Visa sponsor... Show more

 • Promoted

Senior IT Compliance Analyst - IT & OT - GMP

Novo NordiskPetersburg, VA, United States
Full-time

Senior IT Compliance Analyst - IT & OT - GMP.Facility: Digital & IT Location: Petersburg, VA, US.For more than 100 years, Novo Nordisk has been tackling the unmet medical needs of people living wit... Show more

 • Promoted

Director Therapy Operations

Encompass Health Rehabilitation Hospital of RichmondFort Lee, VA, US
Full-time +1

As the Director of Therapy Operations at Encompass Health, you'll shape the future of patient care and contribute to the health of your.As a strategic leader, you'll oversee the organization, devel... Show more

 • Promoted

IT PMO Liaison (HYBRID)

Serigor Inc.Richmond, VA, United States
Full-time

The Client IT PMO Liaison will be responsible for successfully planning, organizing, and motivating diverse project teams throughout all phases of Waterfall, Agile, and Hybrid projects.The Senior P... Show more

 • Promoted

Chief Operating Officer

DeAngelo Contracting Services, LLCRichmond, VA, United States
Full-time

DCS Asset Maintenance is a family owned and operated business with treating all employees like family at the core of our values.Our employees provide innovative, safe, and high-quality infrastructu... Show more

 • Promoted

Surface Warfare Officer

US NavyBowling Green, VA, US
Full-time

Surface Warfare Officers lead at sea by managing ship operations, combat systems, navigation, and warfare tactics to ensure mission readiness across the Fleet on destroyers, cruisers, amphibious sh... Show more

 • Promoted

Sr. Project Manager / Project Manager (Contract Contingent)

ProSidian ConsultingFort Gregg Adams, VA, United States
Full-time

Project Manager / Project Manager (Contract Contingent).ProSidian is a Management and Operations Consulting Services Firm focusing on providing value to clients through tailored solutions based on ... Show more

 • Promoted

Lead Training Developer

Hive GroupFort Gregg Adams, VA, United States
Full-time

Hive Group, a HUBZone-certified SDVOSB and multiple award-winning organization, delivers innovative solutions for complex, mission-critical federal programs.We are seeking a highly skilled and stra... Show more

 • Promoted

Risk Coordinator

Talium AdvisorsRichmond, VA, United States
Full-time

The Risk Coordinator will develop a monthly schedule (at least 6 to 12 assessments) for each calendar month.The Risk Coordinator will track and report on status weekly.Coordinate with supplier mana... Show more

 • Promoted

IT SOX Risk Principal Associate, SOX Advisory Team

Capital oneRichmond, VA, United States
Full-time +1

IT SOX Risk Principal Associate, SOX Advisory TeamIf you're looking for a fast paced, dynamic and innovative firm founded on a culture of diversity and inclusion that can provide you with a challen... Show more

 • Promoted

Project Manager

StaffingFort Gregg Adams, VA, United States
Full-time

We need more of a typical PM, experienced for the Oracle / KPMG / Client large project being pursued.Location or access closer to DeCA (FT Lee/Richmond area) would be preferred.The Professional Ser... Show more

 • Promoted

IT PMO Liaison

Beyond SOFRichmond, VA, United States
Full-time

Candidate MUST possess PMP certification through PMI or VITA's PM certification.No other certification qualifies.Candidate must also be able to work onsite 2-3 days/week.The VDOT IT PMO Liaison wil... Show more

 • Promoted

Senior Associate - Network Participant Risk Oversight Testing & Monitoring

Capital oneRichmond, VA, United States
Full-time +1

Senior Associate - Network Participant Risk Oversight Testing & MonitoringAs a Senior Risk Associate at Capital One, you will be joining the newly created Network Participant Risk Management (N... Show more

 • Promoted

Manager-Finance Risk Analytics (HYBRID--Richmond, VA or REMOTE: VA/PA/MD/DC/NC/SC/GA only) Finance

Atlantic Union BankRichmond, VA, United States
Remote
Full-time

Manager-Finance Risk Analytics (HYBRID--Richmond, VA or REMOTE: VA/PA/MD/DC/NC/SC/GA only).Position Description This position reports to the Director of Technical Accounting and Finance Risk Analyt... Show more

 • Promoted

Operations System Analyst - Electronic Warfare

SimVentions, Inc - Glassdoor 4.6Rappahannock Academy, VA, United States
Temporary

Virginia’s Best Places to Work year after year! .We are looking for an Operations System Analyst to join our team! This individual will preform integration and testing on Navy EW systems.They will ... Show more

 • Promoted

Project Engineering Associate

M.C. DeanRuther Glen, VA, United States
Full-time

Engineering Project Associate Internal Capital Projects.We design, build, operate, and maintain cyber-physical solutions for the nation's most mission-critical facilities, secure environments, com... Show more