Location: Hybrid – Queens, NY

Work arrangement: Hybrid

Work type: Full-time

Compensation: $150000 – $200000 annual

A US credit union is seeking a Director, Technology Risk and Business Continuity to oversee IT, Information Security, and Business Continuity/Disaster Recovery (BCP/DR) risks across the organization. This role partners with technology and business leaders within the three lines of defense framework to provide independent oversight and advisory support, ensuring technology risks are effectively managed and aligned with the organization's risk appetite, regulatory expectations, and strategic objectives. The position serves as the primary liaison between Enterprise Risk Management and technology leadership to promote transparency, resilience, and informed risk-based decision making.

Location: Hybrid — Hybrid – Queens, NY

ACCOUNTABILITIES:

Technology and Emerging Risk Oversight

Regardless of seniority or role, uphold the credit union's mission, core values, and guiding principles by providing an exceptional service experience to colleagues and members alike through consistent demonstration of service excellence behaviors. Provide independent second-line oversight of Information Technology, Information Security/Cyber, AI, technology resilience, and infrastructure risks, ensuring effective governance across the organization. Assess and challenge first-line risk assessments, control effectiveness, and mitigation strategies related to core systems, cloud adoption, data management, AI, automation, and third-party technology risks.

AI Risk and Governance

Provide independent oversight of AI governance, including AI use cases, model lifecycle controls, decision-support frameworks, and risks such as bias, explainability, data integrity, and misuse. Partner with technology and business leaders to ensure AI initiatives align with regulatory requirements, governance standards, ethical principles, and effective management of financial, operational, and reputational risks.

Information Security Risk Governance

Partner with Information Security leadership to provide independent oversight of cyber risk management, including security incidents, identity and access management, data protection, threat and vulnerability management, and alignment with regulatory and industry standards.

Business Continuity & Disaster Recovery Oversight

Provide independent oversight of the organization's Business Continuity and Disaster Recovery (BCP/DR) frameworks, including scenario design, testing effectiveness, recovery objectives (RTO/RPO), and operational resilience. Partner with first-line technology leadership to review and challenge BCP/DR strategies, testing results, remediation efforts, and readiness for technology failures, third-party disruptions, and other resilience scenarios.

Risk Identification, Monitoring, and Reporting

Develop and maintain the technology and operational resilience risk framework, including key risk indicators (KRIs), thresholds, and enterprise-wide risk integration. Monitor and escalate material IT, cyber, and resilience risks to executive leadership and the Risk Management Committee through effective reporting and governance.

Governance and Cross-Functional Coordination

Serve as the primary Enterprise Risk Management liaison to IT leadership, business lines, and operational teams, fostering effective collaboration and risk governance. Provide independent second-line oversight by challenging first-line risk ownership and supporting key governance forums, including technology, product, and incident management committees.

Issue Management and Continuous Improvement

Partner with first-line stakeholders to identify technology-related issues, validate root causes and remediation plans, and monitor corrective actions through resolution. Support the Issue Management Program by ensuring technology risks are documented, tracked, and resolved in compliance with regulatory requirements and the organization's Code of Ethics and Business Conduct.

QUALIFICATIONS:

Bachelor's degree in Risk Management, Information Systems, or related field

10+ years of experience in a financial services environment with exposure to regulated environments, including a minimum of 4 or more years in a second line or commensurate risk function

Experience in technology, cyber, and operational resilience risk management, including regulatory compliance, risk identification, monitoring, issue management, risk reporting, and cross-functional collaboration with business partners

Demonstrated ability to provide independent challenge to senior stakeholders, translate technical risks into business and financial impacts

Strong knowledge of enterprise risk management, financial services regulations (e.g., NCUA, FFIEC, OCC), the three lines of defense model, and technology, cyber, and emerging AI risk frameworks (e.g., NIST, ISO, COBIT)

Proficient in Microsoft Office, particularly Excel, with sound risk judgment, analytical skills, and the ability to provide independent, objective oversight

Strategic thinker with strong digital, cyber, and AI risk awareness, capable of balancing governance, partnership, and practical business solutions

Exceptional executive communication and influencing skills, with the ability to build relationships and drive outcomes without direct authority, including presenting to senior leadership and the Board

PREFERRED QUALIFICATIONS:

Technology Risk Management experience

Excellent communication skills

Compensation: $150000 – $200000 annual

Work Arrangement: Full Time
State: Hybrid - Queens, NY

Apply for this position

Banks + Cloud Native

Credit Unions (Top CU Cores)

Maximum allowed file size is 100 MB. Allowed Type(s): .pdf, .doc, .docx