Talent.com
serp_jobs.error_messages.no_longer_accepting
Director, Cyber and Digital Risk Management

Director, Cyber and Digital Risk Management

Santander Holdings USA IncDallas, TX, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Director, Cyber and Digital Risk Management

Country : United States of America

Your Journey Starts Here :

Santander is a global leader and innovator in the financial services industry. We believe that our employees are our greatest asset. Our focus is on fostering an enriching journey that empowers you to explore diverse career opportunities while nurturing your personal growth. We are committed to creating an environment where continuous learning and development are prioritized, enabling you to thrive both professionally and personally. Here, you will find ample opportunities to connect and collaborate with talented colleagues from around the world, sharing insights and driving innovation together. Join us at Santander, where you are supported by a culture of engagement and a commitment to your success.

An exciting journey awaits, if you are interested in exploring the possibilities We Want to Talk to You!

The Difference You Make :

The Director, Cyber and Digital Risk Management m onitors activities to minimize the company's exposure to information security risks. Activities may include 2nd line of defense independent assurance over technical cyber risk analysis, risk identification and remediation. The incumbent shall support the preservation of digital trust and ensure that the oversight is adequate to minimize compliance and regulatory risk by resolving issues and ensuring adherence to industry good practice frameworks, company and legal standards. The Director is responsible for ensuring that the company's activities adhere to the necessary rules and regulations, and that the company complies with legal / regulatory statutes and jurisdictions, as they relate to the management of cyber and digital risks.

The Director, Cyber and Digital Risk Management at Santander US and Santander Bank NA is responsible for independent risk management and assurance activities over the assigned business area’s technology footprint covering Information Security, Cyber Resilience, Cyber Fraud and Data Security (incl. Retention and Disposal) as part of the second line of defense Technology Risk Management organization.

The incumbent develops and maintains an effective Information Security Risk oversight program that enables the assigned business area to comprehensively identify, assess, mitigate, manage, monitor and report technology risk, including performing technical risk reviews of identified domains.

This role is established in the second line of defense and requires collaboration across CISO, Data Office, IT, Operational Risk, Internal Audit and other relevant functional stakeholders within the organization in the management of Cybersecurity risks. An excellent understanding of the evolving regulatory landscape in the US and EU are vital for success in this role.

The day-to-day focus may vary depending on the requirements of the overall second line of defense program priorities directed by the Head of Technology Risk and may include : planned or ad-hoc technical risk review and challenge, review of Technology or Business initiatives, Ongoing risk monitoring activities, Risk reporting, development of technical risk framework and methodologies.

The team to support the oversight of cybersecurity risks will comprise of individuals aligned against the core coverage areas noted above. This is an individual contributor role but will require people and stakeholder management skills to operate effectively in a 2nd line of defense role in a matrix organization.

Key Responsibilities :

  • Establish themselves as the second line of defense subject matter expert for key stakeholders in the management of cybersecurity and technology risks across all operating entities
  • Prepare information to enable governance committees / working groups in the management oversight of cybersecurity and technology risks
  • Participate in relevant governance committees and working groups as a delegate of the Head of Technology, including the Operational Risk Committee, Technology Executive Working Group, Information Security & Data Management Committee, Architectural Review Board, AI Enablement Working Group
  • Initiate timely escalations to the Sr. Director, Cyber & Digital Risk and to the leadership team
  • Identify and assess cybersecurity risks and counsel business units managers, CISO and / or IT GRC stakeholders on risk management issues to ensure awareness and accountability for cybersecurity risks
  • Oversee ongoing oversight of the firm’s information risk footprint through ongoing monitoring, formal review and challenge activities, targeted risk reviews, technology policy and standard assurance, and other activities e.g., transformation review and challenge.
  • Contribute to the updating of existing policies and framework or develop new ones that steer the safe and sound adoption of technologies across the organization
  • Participate in the independent and ongoing risk oversight of key technology components of the firm’s digital transformation initiatives.
  • Implement and sustain independent risk oversight coverage of the cloud operating platform and vendor software development activities.
  • Work across the lines of defense to recommend strategies that effectively treat risks within the risk appetite
  • Monitor external trends and evaluate potential impacts to business strategy; provide documented analytical insights of the risk horizon, while ensuring a sound operational and compliance control environment through establishment of a system of effective and sustainable internal controls
  • Participate in evaluation of new products / Business changes / projects and assess related information risks and impact to the cybersecurity and technology risk profile
  • Participate in the evaluation and management of cybersecurity risks related to third-party suppliers involved in technology and business projects
  • Advises on remediation of regulatory findings, correction of any inconsistencies and monitors resolution.
  • Manage, oversee and contribute to targeted risk reviews designed to evaluate information risks and their effective and sustainable mitigation
  • Perform review and challenge of first line of defense risk management processes, data and outcomes (e.g. risk assessments, control evaluations, risk metrics, mitigation plans, risk acceptances etc.) and communicate risk opinions at various levels of management
  • Analyze risk data from various sources (e.g. external events, control deficiencies, risk register etc.) to identify and measure levels of risk, concentration, trends and patterns
  • Participate in the review and challenge of scenario for crisis management exercises, especially where there is a cyber component
  • Support process for constructive engagement across the Lines of Defense regarding differences or conflicts in risk appetite, risk metric determination or evaluation, issue severity or other areas of dispute
  • Own individual delivery timelines and develop materials to ensure second line of defense independent opinion appropriately represented during committee meetings, external exams and internal audits.
  • Ensure all activities and deliverables achieve their timeliness, quality and accuracy service levels.
  • Collaborate with other second line of defense functions such as Operational Risk, Model Risk, Compliance etc. on common priorities and strategic initiatives
  • Provides second line of defense leadership and subject matter expertise during response to major technology or cyber incidents including cyber-security related privacy events and coordinate second line of defense engagement and response of incident / crisis managers

What You Bring :

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and / or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education :

  • Bachelor's Degree in a technical discipline or equivalent work experience : Computer Science, Information Technology, Information Systems, Information Security. Req
  • Master's Degree in related technical disciplines. Pref
  • Professional Certifications in Cybersecurity. Req.
  • Professional Certifications in Cloud Security (AWS, Azure). Pref
  • Work Experience :

  • Practitioner and management experience in one or more areas of Cybersecurity Risks
  • Overall professional experience of 15+ years or more in cybersecurity risk management roles in a matrix organization
  • Experience in Cybersecurity risk consulting in the financial services sector, Cyber security audit, Chief Information Security Officer / Deputy or in a similar second line of defense role is highly preferred
  • Experience within a highly regulated environment such as the financial services industry and knowledge of the current and evolving regulatory landscape is necessary
  • Experience leading high performance teams
  • Skills and Abilities :

  • Strong understanding of technology infrastructure, information security, and enterprise resilience
  • Experience with developing and implementing technology & cyber risk oversight programs, preferably in a 2nd or 3rd line of defense
  • Demonstrated leadership skills and ability to coordinate oversight activities across different teams
  • Knowledge of current and evolving regulatory requirements and industry best practices in technology and cybersecurity risk management
  • Strong Leadership Experience
  • Technical skills (incl. Tools) :

  • Resilient Security Architecture
  • Identity and Access Management
  • Network / Firewall Management
  • Vulnerability and Patch Management
  • Cloud Security Architecture
  • Secure Application Development / Containerization
  • Encryption / Tokenization
  • Data Loss Prevention
  • Security Logging and Monitoring
  • Incident Detection and Response Management
  • Offensive Security
  • Competencies and Abilities :

  • Demonstrated expertise and track record in technology risk management segment, and ability to perform at an advanced level of competence.
  • Advanced knowledge of cyber risk management best practices and how to implement them.
  • Ability to engage effectively with both senior management and operational teams
  • A keen sense of risk anticipation with attention to details and an ingrained ability to connect the dots and challenge status quo
  • An execution and solution focused risk mindset with an ability to push the needle forward even with ambiguous or incomplete information
  • Ability to direct, train and guide peers, subordinates and management.
  • A team player who can coordinate and drive consensus among different teams and stakeholders having varying viewpoints
  • Ability to build relationships, influencing and negotiating across diverse stakeholders across the lines of defense, handle conflict resolution with other groups to ensure appropriate risk management decisions are made.
  • Ability to adjust to new developments / changing circumstances.
  • Ability to effectively communicate and build relationships with multiple levels of the organizational structure, including senior level management.
  • Ability to collaborate with multidisciplinary teams.
  • Ability to multi-task and adapt / adjust to multiple demands and competing priorities.
  • Ability to maintain and report on confidential information in an appropriate manner.
  • Ability to convey a sense of urgency and drive issues / projects to closure.
  • Ability to effectively interact with the executive management and vendors.
  • Ability to demonstrate sound judgement and critical thinking
  • Excellent written and oral communication skills.
  • Excellent analytical, organizational and project management skills.
  • Strong leadership, supervisory engagement skills.
  • Strong risk, process, and control validation and / or assessment skills
  • Certifications :

  • Professional Certifications in Cybersecurity. Req.
  • Professional Certifications in Cloud Security (AWS, Azure). Pref
  • It Would Be Nice For You To Have :

    Established work history or equivalent demonstrated through a combination of work experience, training, military service, or education.

    What Else You Need To Know :

    The base pay range for this position is posted below and represents the annualized salary range. For hourly positions (non-exempt), the annual range is based on a 40-hour work week. The exact compensation may vary based on skills, experience, training, licensure and certifications and location.

    Base Pay Range

    Minimum : $123,750.00 USD

    Maximum : $225,000.00 USD

    Link to Santander Benefits :

    Santander Benefits - 2025 Santander OnGoing / NH eGuide (foleon.com)

    Risk Culture :

    We embrace a strong risk culture and all of our professionals at all levels are expected to take a proactive and responsible approach toward risk management.

    EEO Statement :

    At Santander, we value and respect differences in our workforce. We actively encourage everyone to apply. Santander is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, genetics, disability, age, veteran status or any other characteristic protected by law.

    Working Conditions :

    Frequent minimal physical effort such as sitting, standing and walking is required for this role. Depending on location, occasional moving and lifting light equipment and / or furniture may be required .

    Employer Rights :

    This job description does not list all of the job duties of the job. You may be asked by your supervisors or managers to perform other duties. You may be evaluated in part based upon your performance of the tasks listed in this job description. The employer has the right to revise this job description at any time. This job description is not a contract for employment and either you or the employer may terminate your employment at any time for any reason.

    What To Do Next :

    If this sounds like a role you are interested in, then please apply.

    We are committed to providing an inclusive and accessible application process for all candidates. If you require any assistance or accommodation due to a disability or any other reason, please contact us at TAOps@santander.us to discuss your needs.

    Primary Location : Coconut Grove, FL, Miami Coconut Grove Corp

    Other Locations : Florida-Coconut Grove,Texas-Dallas

    Organization : Santander Holdings USA, Inc.

    serp_jobs.job_alerts.create_a_job

    Director Risk Management • Dallas, TX, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Director of Retirement Solutions

    Director of Retirement Solutions

    VirtualVocationsIrving, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director, Retirement Platform Enablement (Remote).Key Responsibilities Define, document, and standardize platform practices, including policies and procedures Engage w...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Project Manager

    Senior Cybersecurity Project Manager

    VirtualVocationsGrand Prairie, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cybersecurity Project Manager, responsible for managing technical cybersecurity projects. Key Responsibilities Manage projects with internal and external dependen...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Technology Risk Management Principal

    Technology Risk Management Principal

    Fannie MaePlano, US
    serp_jobs.job_card.full_time
    Playing an essential role in the U.Fannie Mae is foundational to housing finance.Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable ren...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Director of Discovery App

    Director of Discovery App

    VirtualVocationsPlano, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director, Discovery App to lead a career readiness program aimed at increasing participation and enhancing user experience for students and partners.Key Responsibilities ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Third Party Risk Manager

    Third Party Risk Manager

    American National Bank of TexasTerrell, TX, United States
    serp_jobs.job_card.full_time
    The Bank's third-party vendors throughout the relationship life cycle ensuring the bank maintains an effective Third-Party Risk Management Program (TPRM) in compliance with all applicable laws, rul...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Principal Security Risk Management Consultant

    Principal Security Risk Management Consultant

    VerizonIrving, TX, United States
    serp_jobs.job_card.full_time +1
    A place to share your ideas freely - even if they're daring or different.Where the true you can learn, grow, and thrive.At Verizon, we power and empower how people live, work and play by connecting...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Director of Security Engineering

    Senior Director of Security Engineering

    VirtualVocationsIrving, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Director of Security Engineering.Key Responsibilities Define and implement the long-term vision and strategy for the security engineering function Build and lea...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Cybersecurity Lead / Architect

    Cybersecurity Lead / Architect

    HCLTechFrisco, TX, US
    serp_jobs.job_card.full_time
    Cybersecurity Lead / Architect Candidate Persona - Ability to do architecture and consulting engagement for large and complex customer environment. Self-motivated individual and creative thinker who...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Director of Cybersecurity Operations & Engineering

    Director of Cybersecurity Operations & Engineering

    ATIDallas, TX, United States
    serp_jobs.job_card.full_time
    From the edges of space to the bottoms of ocean, our materials are proven to perform and so is our team.We're hiring high performers as proven as our products. At ATI Materials, we are innovators...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Alliance Director

    Alliance Director

    VirtualVocationsPlano, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for an Alliance Director - API Security.Key Responsibilities Define and execute the strategic partnership roadmap aligned with business goals Own and grow relationships with...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Project Manager

    Cybersecurity Project Manager

    VirtualVocationsGrand Prairie, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Project Manager to join their cybersecurity project team.Key Responsibilities Implement Project Management best practices to reduce risks and improve serv...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Vice President of Cybersecurity

    Vice President of Cybersecurity

    VirtualVocationsPlano, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Vice President of Cybersecurity to lead the development and execution of an enterprise-wide cybersecurity strategy. Key Responsibilities Develop and implement a comprehe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior SOC Manager

    Senior SOC Manager

    VirtualVocationsGarland, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Operations Center (SOC) Manager.Key Responsibilities Oversee daily SOC activities for timely detection and response to security incidents Manage, mento...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Director - Catastrophe Managment Analytics

    Senior Director - Catastrophe Managment Analytics

    AonFarmers Branch, TX, United States
    serp_jobs.job_card.full_time +1
    Aon is looking for a Senior Director - Catastrophe Modeling - Boston, NYC, Bloomington, Atlanta, Dallas or Chicago.Senior Director of Catastrophe Risk Management. As part of the Catastrophe Manageme...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Deputy Digital Organizing Director

    Deputy Digital Organizing Director

    VirtualVocationsGrand Prairie, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Deputy Digital Organizing Director.Key Responsibilities Implement multi-channel digital organizing and mobilization strategies to enhance volunteer engagement Manage a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Senior Director of Technology Management

    Senior Director of Technology Management

    VirtualVocationsGrand Prairie, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Director of Technology Program Management to lead its technical project and program management team. Key Responsibilities Lead the R&D PMO, managing a diverse por...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Director, Organization Effectiveness & Change Leadership

    Director, Organization Effectiveness & Change Leadership

    MCKESSONIrving, TX, United States
    serp_jobs.job_card.full_time
    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessibl...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Manager, Information Security

    Senior Manager, Information Security

    VirtualVocationsIrving, Texas, United States
    serp_jobs.job_card.full_time
    Manager, Information Security Risk Management.Key Responsibilities Lead the supplier governance program and oversee supplier due diligence processes Partner with stakeholders for supplier sourci...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Director of Technology Consulting

    Senior Director of Technology Consulting

    VirtualVocationsArlington, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Director, Technology Consulting.Key Responsibilities Participate in account planning for strategic accounts to leverage technology solutions for revenue growth ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Director of SoC IP RTL

    Director of SoC IP RTL

    VirtualVocationsCarrollton, Texas, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director, System-on-Chip IP RTL.Key Responsibilities Lead RTL design teams in developing IP and SoCs from concept to productization Develop microarchitecture specifica...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days