A US credit union is seeking a Director, Technology Risk and Business Continuity to oversee IT, Information Security, and Business Continuity/Disaster Recovery (BCP/DR) risks across the organization.
Location: Hybrid — Hybrid – Queens, NY
The Director will partner with technology and business leaders within the three lines of defense framework to provide independent oversight and advisory support, ensuring technology risks are effectively managed and aligned with the organization’s risk appetite, regulatory expectations, and strategic objectives. This role serves as the primary liaison between Enterprise Risk Management and technology leadership to promote transparency, resilience, and informed risk based decision making.
ACCOUNTABILITIES:
Technology and Emerging Risk Oversight
Regardless of seniority or role, uphold a US credit union’s mission, core values, and guiding principles by providing an exceptional service experience to colleagues and members alike through consistent demonstration of service excellence behaviors. Provide independent second line oversight of Information Technology, Information Security/Cyber, AI, technology resilience, and infrastructure risks, ensuring effective governance across the organization. Assess and challenge first line risk assessments, control effectiveness, and mitigation strategies related to core systems, cloud adoption, data management, AI, automation, and third party technology risks.
AI Risk and Governance
Provide independent oversight of AI governance, including AI use cases, model lifecycle controls, decision support frameworks, and risks such as bias, explainability, data integrity, and misuse. Partner with technology and business leaders to ensure AI initiatives align with regulatory requirements, governance standards, ethical principles, and effective management of financial, operational, and reputational risks.
Information Security Risk Governance
Partner with Information Security leadership to provide independent oversight of cyber risk management, including security incidents, identity and access management, data protection, threat and vulnerability management, and alignment with regulatory and industry standards.
Business Continuity and Disaster Recovery Oversight
Provide independent oversight of the organization’s Business Continuity and Disaster Recovery (BCP/DR) frameworks, including scenario design, testing effectiveness, recovery objectives (RTO/RPO), and operational resilience. Partner with first line technology leadership to review and challenge BCP/DR strategies, testing results, remediation efforts, and readiness for technology failures, third party disruptions, and other resilience scenarios.
Risk Identification, Monitoring, and Reporting
Develop and maintain the technology and operational resilience risk framework, including key risk indicators (KRIs), thresholds, and enterprise wide risk integration. Monitor and escalate material IT, cyber, and resilience risks to executive leadership and the Risk Committee.
Compensation: $150000 – $200000 annual