Manager I, Technical Risk

Vienna, VA, United States

Navy Federal Credit Union

Navy Federal Credit Union is an armed forces bank serving the Navy, Army, Marine Corps, Air Force, Space Force, Coast Guard, veterans, DoD & their families. Join now!

View all jobs at Navy Federal Credit Union

Apply now Apply later

Responsible for overseeing the identification, evaluation, and mitigation of technical risks across the organization's IT systems and infrastructure. Oversees operational Issues management with a strong focus on partnership and collaboration on Information Security and Third-party risk management program. Plays a critical part in ensuring that technology-related risks are adequately managed, compliant with regulatory requirements, and aligned with the organization's overall risk management strategy. Manages professionals and is accountable for the performance and results of a team. Decisions are guided by policies, resources, and business plan. Develop, manage, and guide execution of operational initiatives to achieve tactical objectives.

  • Identify and assess technical risks associated with systems, applications, networks, and infrastructure
  • Serve as Security subject matter expert to support, coach, and mentor junior level team members
  • Function as a liaison and advisor, on behalf of the Digital business unit, to the Security business unit (Security). Partner and develop strong relationships with key stakeholders and foster collaboration and engagement, ensuring program alignment
  • Manage Issues and set clear objectives, define scope, ensure alignment with stakeholders, execute a plan of action, and review and address findings in a timely manner
  • Work with IT teams to analyze emerging technologies and their associated risks
  • Develop a strong understanding of the technical and administrative controls needed to secure digital applications and the underlying technologies used to build them
  • Oversees compliance with corporate standards; assists in defining new standards and refines existing standards related to Security, Issues Management and Third-Party risk programs
  • Develop and implement risk mitigation strategies to reduce the impact of technical risks on the organization
  • Design and deploy controls, processes, and procedures to manage identified risks
  • Ensure that technical systems adhere to industry best practices and regulatory standards (e.g., ISO, NIST, GDPR)
  • Develop and maintain technical risk management policies, procedures, and frameworks
  • Ensure compliance with internal policies and external regulations (e.g., data privacy, cybersecurity laws)
  • Collaborate with legal, compliance, and internal audit teams to ensure alignment on technical risk issues
  • Lead and coordinate the response to technical incidents and breaches, including root cause analysis and remediation efforts
  • Collaborate by actively working across business lines to document procedural and technical interdependency document workflows
  • Work with cybersecurity teams to address vulnerabilities and improve overall security posture for Digital
  • Collaborate with cross-functional teams including IT, operations, compliance, and business units to communicate risks, provide guidance on mitigation strategies and document areas for improvement
  • Present technical risk reports to senior management and board members, highlighting key risk areas and proposed actions
  • Support and contribute to the Digital Risk and Control Self-Assessment, Third Party Risk Management, and Issues Management programs   
  • Oversee risk assessments of Third party and vendor management program
  • Establish processes for continuous monitoring of key technical risks
  • Produce regular risk reports, dashboards, and metrics to provide visibility into the organization’s technical risk landscape
  • Stay up-to-date with the latest industry trends, regulations, and best practices to continuously improve the risk management function
  • Evaluate and manage risks associated with third-party vendors and service providers
  • Conduct risk assessments and reviews of external partners, ensuring compliance with contractual and regulatory requirements
  • Provide regular reporting and analytics to senior management and stakeholders
  • Lead and mentor a team of technical risk analysts or engineers
  • Provide ongoing training and development opportunities to ensure the team is up to date on the latest risk management practices and technologies
  • Experience conducting risk assessments, vulnerability assessments, and penetration testing to identify areas of risk exposure
  • Experience ensuring technical systems adhere to industry best practices and regulatory standards (e.g., NIST, ISO) 
  • Strong knowledge of information security concepts, and best practices with proven experience with cybersecurity and risk management frameworks such as NIST 800-53, CIS, and ISO 27001
  • People management experience
  • Significant Third-party and vendor risk management experience
  • Significant issues management and remediation experience
  • Significant cybersecurity & IT governance experience
  • Excellent verbal and written communication skills, with the ability to translate technical risks into business language for non-technical stakeholders
  • Expert analytical/quantitative, reconciliation, and deductive reasoning skills
  • Effective skill in building strategic and tactical-focused plans and alliances with stakeholders and leaders
  • Advanced communication and presentation skills; ability to persuade and influence; communicate complex information in an easily understandable manner
  • Bachelor’s degree in Computer Science, Information Technology, Engineering, or related technical field, or the equivalent combination of training, education and experience

Desired Qualifications

  • Master’s Degree in related field or equivalent combination of training, education and experience
  • Certified Information Systems Security Professional (CISSP)
  • Certified Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)

Hours: Monday - Friday, 8:00AM - 4:30PM 

Location: 820 Follin Lane, Vienna, VA 22180

Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.

Our approach to careers is simple yet powerful: Make our mission your passion.

  • Best Companies for Latinos to Work for 2024
  • Computerworld® Best Places to Work in IT
  • Forbes® 2025 America’s Best Large Employers
  • Forbes® 2024 America's Best Employers for New Grads
  • Forbes® 2024 America's Best Employers for Tech Workers
  • Fortune Best Workplaces for Millennials™ 2024   
  • Fortune Best Workplaces for Women ™ 2024
  • Fortune 100 Best Companies to Work For® 2024
  • Military Times 2024 Best for Vets Employers
  • Newsweek Most Loved Workplaces
  • 2024 PEOPLE® Companies That Care
  • RippleMatch Recruiting Choice Award
  • Yello and WayUp Top 100 Internship Programs

From Fortune. ©2024 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.

Equal Employment Opportunity: Navy Federal values and celebrates diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected Veteran.

Hybrid Workplace: Navy Federal Credit Union is a hybrid workplace, and details will be discussed during your interview process.

Disclaimers: Navy Federal reserves the right to fill this role at a higher/lower grade level based on business need. An assessment may be required to compete for this position. Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team’s discretion based on qualified applicant volume. Navy Federal Credit Union assesses market data to establish salary ranges that enable us to remain competitive. You are paid within the salary range, based on your experience, location and market position.

Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Analytics CISM CISSP Compliance Computer Science CRISC GDPR Governance ISO 27001 Monitoring NIST NIST 800-53 Pentesting Privacy Risk assessment Risk management Strategy Vendor management Vulnerabilities

Perks/benefits: Career development Competitive pay

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.