Sr. Director, Technology and Digital Risk Management

Santander Holdings USA Inc
Saugus, Massachusetts, United States
$189K-$300K a year
Full-time
We are sorry. The job offer you are looking for is no longer available.

Sr. Director, Technology and Digital Risk ManagementDallas, United States of AmericaJob Description : The Sr. Director, Technology and Digital Risk Management at Santander US and Santander Bank NA is responsible for all independent risk management and assurance activities over the assigned business area’s technology footprint covering Information Security, Cyber resilience, Cyber fraud and Data Security (incl.

Retention and Disposal) as part of the second line of defense Technology and Information Risk organization.The incumbent develops and maintains an effective Information Security Risk Management program that enables the assigned business area to comprehensively identify, assess, mitigate, manage, monitor and report technology risk, including performing technical risk reviews of identified domains.

This role is established in the second line of defense and requires collaboration across CISO, Data Office, IT, Operational Risk, Internal Audit and other relevant functional stakeholders within the organization in the management of Cybersecurity risks.

An excellent understanding of the evolving regulatory landscape in the US and EU are vital for success in this role.The day-to-day focus may vary depending on the requirements of the overall second line of defense program priorities directed by the Head of Technology Risk and may include : planned or ad-hoc technical risk reviews, review of Technology or Business initiatives, Review and challenge activities, Risk reporting, development of technical risk framework and methodologies.

The team to support the oversight of cybersecurity risks will comprise of individuals positioned as a center of excellence aligned against the core coverage areas noted above.

Direct reports include leads assigned to core coverage areas.Key Responsibilities : Establish themselves as the second line of defense subject matter expert for key stakeholders in the management of cybersecurity and technology risks across all operating entitiesPrepare information to enable governance committees / working groups in the management oversight of cybersecurity and technology risksParticipate in relevant governance committees and working groups as a delegate of the Head of Technology, including the Operational Risk Committee, Technology Executive Working Group, Information Security & Data Management Committee, Architectural Review Board, AI Evaluation ForumInitiate timely escalations to the Head of Technology and to the leadership teamIdentify and assess cybersecurity risks and counsel business units managers, CISO and / or IT GRC stakeholders on risk management issues to ensure awareness and accountability for cybersecurity risksOversee ongoing oversight of the firm’s information risk footprint through ongoing monitoring, formal review and challenge activities, targeted risk reviews, technology policy and standard assurance, and other activities e.

g., transformation review and challenge.Develop and implement a technical risk management governance, framework to enable the strategic business direction of the organizationEnsure the updating of existing policies and framework or develop new ones that steer the safe and sound adoption of technologies across the organizationParticipate in the independent and ongoing risk oversight of key technology components of the firm’s digital transformation initiatives.

Additionally, coordinate oversight of key emerging technology risksImplement and sustain independent risk oversight coverage of the cloud operating platform and vendor software development activities.

Work across the lines of defense to recommend strategies that effectively treat risks within the risk appetiteMonitor external trends and evaluate potential impacts to business strategy;

provide documented analytical insights of the risk horizon, while ensuring a sound operational and compliance control environment through establishment of a system of effective and sustainable internal controlsParticipate in evaluation of new products / Business changes / projects and assess related information risks and impact to the cybersecurity and technology risk profileParticipate in the evaluation and management of cybersecurity risks related to third-party suppliers involved in technology and business projectsAdvises on remediation of regulatory findings, correction of any inconsistencies and monitors resolution.

Manage, oversee and contribute to targeted risk reviews designed to evaluate information risks and their effective and sustainable mitigationPerform review and challenge of first line of defense risk management processes, data and outcomes (e.

g. risk assessments, control evaluations, risk metrics, mitigation plans, risk acceptances etc.) and communicate risk opinions at various levels of managementAnalyze risk data from various sources (e.

g. external events, control deficiencies, risk register etc.) to identify and measure levels of risk, concentration, trends and patternsParticipate in the review and challenge of scenario for crisis management exercises, especially where there is a cyber componentSupport process for constructive engagement across the Lines of Defense regarding differences or conflicts in risk appetite, risk metric determination or evaluation, issue severity or other areas of disputeManage delivery timelines and develop materials to ensure second line of defense independent opinion appropriately represented during committee meetings, external exams and internal audits.

Ensure all activities and deliverables achieve their timeliness, quality and accuracy service levels.Collaborate with other second line of defense functions such as Operational Risk, Model Risk, Compliance etc.

on common priorities and strategic initiativesProvides second line of defense leadership and subject matter expertise during response to major technology or cyber incidents including cyber-security related privacy events and coordinate second line of defense engagement and response of incident / crisis managerRecruits, develops, and manages talent to create within the organization a culture of leadership, performance, and accountability.

Qualifications : To perform this job successfully, an individual must be able to perform each essential duty satisfactorily.

The requirements listed below are representative of the knowledge, skill, and / or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education : Required : Bachelor's Degree in a technical discipline or equivalent work experience : Computer Science, Information Technology, Information Systems, Information SecurityPreferred : Master's Degree in related technical disciplinesRequired : Professional Certifications in CybersecurityReferred : Professional Certifications in Cloud Security (AWS, Azure)Work Experience : 15+ years overall professional experience in cybersecurity risk management roles in a matrix organizationPractitioner and management experience in one or more areas of Cybersecurity RisksExperience in Cybersecurity risk consulting in the financial services sector, Cyber security audit, Chief Information Security Officer / Deputy or in a similar second line of defense role is highly preferredExperience within a highly regulated environment such as the financial services industry and knowledge of the current and evolving regulatory landscape is necessaryExperience leading high performance teamsSkills and Abilities : Strong understanding of technology infrastructure, information security, and enterprise resilienceExperience with developing and implementing Information Risk Management ProgramsDemonstrated leadership skills and ability to coordinate oversight activities across different teamsKnowledge of current and evolving regulatory requirements and industry best practices in technology and cybersecurity risk managementStrong Leadership ExperienceTechnical skills (incl.

Tools) : Resilient Security ArchitectureIdentity and Access ManagementNetwork / Firewall ManagementVulnerability and Patch ManagementCloud Security ArchitectureSecure Application Development / ContainerizationEncryption / TokenizationData Loss PreventionSecurity Logging and MonitoringIncident Detection and Response ManagementOffensive SecurityCompetencies and Abilities : Demonstrated expertise and track record in technology risk management segment, and ability to perform at an advanced level of competence.

Advanced knowledge of technical risk management best practices and how to implement them.Ability to engage effectively with both senior management and operational teamsA keen sense of risk anticipation with attention to details and an ingrained ability to connect the dots and challenge status quoAn execution and solution focused risk mindset with an ability to push the needle forward even with ambiguous or incomplete informationAbility to direct, train and guide peers, subordinates and management.

A team player who can coordinate and drive consensus among different teams and stakeholders having varying view pointsAbility to build relationships, influencing and negotiations across diverse stakeholders across the lines of defense, handle conflict resolution with other groups to ensure appropriate risk management decisions are made.

Ability to adjust to new developments / changing circumstances.Ability to effectively communicate and build relationships with multiple levels of the organizational structure, including senior level management.

Ability to collaborate with multidisciplinary teams.Ability to multi-task and adapt / adjust to multiple demands and competing priorities.

Ability to maintain and report on confidential information in an appropriate manner.Ability to convey a sense of urgency and drive issues / projects to closure.

Ability to effectively interact with the executive management and vendors.Ability to demonstrate sound judgement and critical thinkingExcellent written and oral communication skills.

Excellent analytical, organizational and project management skills.Strong leadership, supervisory engagement skills.Strong risk, process, and control validation and / or assessment skills.

Diversity & EEO Statements : At Santander, we value and respect differences in our workforce and strive to increase the diversity of our teams.

We actively encourage everyone to apply.Santander is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, genetics, disability, age, veteran status or any other characteristic protected by law.

Employer Rights : This job description does not list all of the job duties of the job. You may be asked by your supervisors or managers to perform other duties.

You may be evaluated in part based upon your performance of the tasks listed in this job description. The employer has the right to revise this job description at any time.

This job description is not a contract for employment and either you or the employer may terminate at any time for any reason.

Primary Location : Dallas, TX, DallasOther Locations : Texas-Dallas,New Jersey-Florham Park,New York-New York,Massachusetts-BostonOrganization : Santander Consumer USA Inc.

The base pay range for this position is posted below and represents the annualized salary range. For hourly positions (non-exempt), the annual range is based on a 40-hour work week.

The exact compensation may vary based on skills, experience, training, licensure and certifications and location.Salary : $189,000 - $300,000 / year

1 day ago
Related jobs
Promoted
Takeda
Boston, Massachusetts

Set the vision, direction, and strategy for area(s) of responsibility and actively contribute to and align with the overall CDM, Global Integrated Clinical Trial Data Services, and Global Development Organization (GDO) strategies and operating models. Lead the development of robust strategies for DM...

Promoted
Karkidi
Boston, Massachusetts

BCG delivers solutions through leading-edge management consulting, technology and design, and corporate and digital ventures. We are Technology and Digital Advantage (TDA), where tech and digital get real. Digital Marketing & Personalization: Optimising digital marketing programs across all digi...

X4 Pharmaceuticals
Boston, Massachusetts

The Medical Director, Pharmacovigilance & Risk Management will serve as the medical expert for the pharmacovigilance team in the management of safety signals, risk management activities, and benefit-risk analysis and will contribute to the development of pharmacovigilance strategies for monitoring t...

HRI Hospital
Brookline, Massachusetts

The individual in this position is responsible for staff training and education on the hospital’s performance initiatives and measures including outcomes measurement and reporting, as well as patient and employee safety. A strong knowledge of JOINT COMMISSION, CMS standards, and any other applicable...

Iron Mountain
Remote, MA, US
Remote

The Senior Director owns the process of identifying, measuring and managing insurable risks, developing reports and plans, and analyzing risk/insurance problems and defining and/or overseeing the implementation of the risk solutions that help optimize operations. We provide expert, sustainable solut...

Boston University
Boston, Massachusetts

Our IS&T Educational Technology Platform Administration team is looking for an Assistant Director who will be responsible for leading and managing the team of platform administrators in the support of Learning Management Systems, Assessment Systems, Instructional Video Services, and Grading Support ...

Raytheon Technologies
Cambridge, Massachusetts

Bachelor’s degree in electrical engineering and 10+ years of experience in electronic circuit design and analysis; a Master’s degree in electrical engineering and 7+ years of experience in electronic circuit design and analysis. This is especially evident in our Physical Systems and Sciences group, ...

PwC US Group LLP
Boston, Massachusetts
Remote

Our Sales and Marketing Generalist - Practice Support team focuses on designing, developing, and implementing communication programmes and media events to promote and sell PwC’s brand and services as well as contribute to and evaluate our pricing strategies in the marketplace. You’ll focus on design...

Capital One
Boston, Massachusetts

The Director, Product Management is a unique and high profile role that is responsible for discovering, delivering and optimizing products and capabilities that fundamentally transform how our Finance Associates work and enable us to deliver valuable insights using modernized technologies and core d...

Takeda
Boston, Massachusetts

As part of the Patient Safety and Pharmacovigilance team, within the Risk Management and Education function, you will report to the Senior Director, Signal Management and represent the pharmacovigilance department as subject matter expert in cross-functional teams or committees and external environm...