Salary
💰 $140,000 - $175,000 per year
About the role
- RCSA QA Execution: Execute and oversee QA reviews across all business line owned RCSAs, evaluating the quality of RCSA submissions across non-financial risk types
- Risk Documentation Review: Review risk statements, impact/likelihood ratings, control narratives, and residual risk assessments for completeness, clarity, and alignment with enterprise standards and risk taxonomy
- Quality and Consistency: Identify gaps, weaknesses, or inconsistencies in RCSA documentation and provide practical, risk-based recommendations to strengthen risk assessments
- Elevate RCSA Quality: Provide constructive feedback and escalate systemic gaps and emerging themes
- Promote Risk Culture and Awareness: Serve as a subject matter expert to promote best practices in identifying and assessing non-financial risks (e.g., operational resilience, data privacy, regulatory compliance, information security, and vendor risk)
- Reporting and Thematic Analysis: Contribute to QA dashboards and reporting for business and risk leadership
- Partner with Key Stakeholders: Collaborate with first-line process/control owners, second-line risk partners, and compliance teams to ensure alignment with enterprise risk standards and regulatory expectations
- Regulatory and Audit Readiness: Ensure RCSA documentation and QA evidence meet internal audit and regulatory standards (e.g., OCC Heightened Standards, FFIEC, SOX, and data governance frameworks)
- Support Training and Capability Building: Deliver guidance to first-line staff to enhance understanding of risk identification, control design, and risk rating rationale
- Project Management: Lead or participate in other risk-related projects or initiatives as assigned
Requirements
- Bachelor’s degree in risk management, Business, Legal, Information Technology, or related field
- Advanced degree preferred
- Minimum of 8 years of experience in risk management, operational risk, or internal audit within the banking or financial services industry
- At least 5 years in a leadership role within the banking sector
- Experience leading QA or audit reviews or building QA frameworks for operational risk and control programs
- Deep experience with RCSA programs and control frameworks across non-financial risks
- Knowledge of OCC Heightened Standards and Regulatory Category IV banking requirements preferred
- Strong analytical, problem-solving, and decision-making skills
- Excellent verbal and written communication abilities
- Strategic thinker with attention to detail and operational acumen
- Strong commitment to quality and continuous improvement
- Collaborative, with strong influence and stakeholder engagement skills
- Skilled in GRC tools (e.g., Archer, Workiva, ServiceNow, or similar data tools.)
- Preferred Certifications: Certified Risk Professional (CRP), Certified Internal Auditor (CIA), Certified in Risk Management Assurance (CRMA), Certified in Control Self-Assessment (CCSA), Certified Information Systems Auditor (CISA), Certified Data Privacy Solutions Engineer (CDPSE), Certified Regulatory Compliance Manager (CRCM)
- Lean Six Sigma, PMP or control design certifications a plus