Establish themselves as the second line of defense subject matter expert on technology risk management
Identify and assess technology risks ensure awareness and accountability for their management
Design and execute independent testing and assurance of technical domains
Participate in the independent and ongoing risk oversight of key technology components of the firm’s business and strategy initiatives
Participate in evaluation of new products / Business changes / projects and assess related technology risks and impact to the technology risk profile
Participate in the evaluation and management of risks related to third-party suppliers involved in technology projects
Perform review and challenge of first line of defense risk management processes, data and outcomes (e.g. risk assessments, control evaluations, risk metrics, mitigation plans, risk acceptances etc.)
Analyze IT risk data from various sources to identify and measure levels of risk, concentration, trends and patterns, drive automation, risk analytics & aggregation and risk visualization
Support process for constructive engagement across the Lines of Defense regarding risk appetite, risk metric determination or evaluation, issue management and action plans
Advise on remediation of regulatory findings, correction of any inconsistencies and monitor resolution
Prepare information to enable governance committees / working groups in the management oversight of technology risks
Initiate timely escalations to the Technology Risk leadership team
Work across the lines of defense to recommend strategies that effectively treat risks within the risk appetite
Requirements
Bachelor's Degree in a technical discipline or equivalent work experience: Computer Science, Information Technology, Information Systems, Information Security
Master's Degree in related technical disciplines. Pref
Professional Certifications in one or more domains of technical expertise. Req.
Overall professional experience of 10+ years or more in technology risk audit & assurance or a technology risk management role
Practitioner experience in Technology or Cybersecurity risk management with an ability to lead technical risk assessments
Good understanding of regulatory requirements e.g. FFIEC, FDIC, OCC
Familiarity with industry frameworks and practices e.g. COBIT, ITIL, ISO, NIST 800-53, CSA-CCM v4, Fed Ramp, CIS Benchmarks
Experience within a highly regulated environment such as the financial services industry
IT Service Management domains e.g. IT Change Management, IT Capacity Management, IT Incident Management, IT Release Management
Software Development Lifecycle (SDLC)
IT Asset Management and Shadow IT (End User Computing)
Networks and Communication Systems
Virtualized infrastructure
Payments technology e.g. SWIFT, Fedline etc.
Advanced proficiency in MS Excel and PowerPoint
High levels of proficiency with data visualization and reporting tools such as PowerBI and/or Tableau
Working knowledge of the Python ecosystem, including best practices (Pref)
Strong communication and presentation skills
Strong analytical, organizational and project management skills
Benefits
Link to Santander Benefits: Santander Benefits - 2025 Santander OnGoing/NH eGuide (foleon.com)
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
technology risk managementrisk assessmentscontrol evaluationsrisk metricsrisk analyticsrisk visualizationPythondata analysisIT Service ManagementSoftware Development Lifecycle
Soft skills
communication skillspresentation skillsanalytical skillsorganizational skillsproject management skills