ForgeApply · Job listing
Principal of Access Management Risk
Earlywarning
See all 83 open roles at Earlywarning →
Tailor your resume for this Earlywarning job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Earlywarning's site. Free trial, no card required.
About this role
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Purpose
Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managed consistent with enterprise risk appetite, regulatory expectations, and sound industry practice. May support one or more focus areas based on business need, including Enterprise Technology Risk, Data Security Risk, Access Management Risk, Offensive Security Risk, Vulnerability Management Risk, AI Security Risk, and Asset and Inventory Management Risk.
Essential Functions
• Provide independent review, oversight, and credible challenge of first-line technology risk management activities, controls, and decisions.
• Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards.
• Provide independent challenge and oversight of risk identification and assessment activities.
• Review and challenge risk and control self-assessments, issues management, remediation plans, control validation outcomes, and key risk indicators.
• Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events.
• Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness.
• Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees.
• Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements.
• Provide ongoing risk advisory support while maintaining second-line independence and accountability for effective challenge .
• Recommend opportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity.
• Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
Focus: Enterprise Technology and Information Security Risk
• Provide independent challenge and oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains.
• Provide independent challenge and oversight of information security risk management practices across threat management, network, endpoint, cloud, architecture, data, access, AI, or application security domains.
• Assess alignment of technology risk and control activities to enterprise policies, risk frameworks, and applicable industry standards.
• Evaluate whether risk assessments, control inventories, issues management, and key risk indicators are executed consistently and effectively across the technology organization.
• C hallenge risk identification activities related to significant technology changes, new products or capabilities, and cross-functional initiatives.
• Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed.
Minimum Qualifications
• Education and/or experience typically obtained through completion of a Bachelor’s degree or equivalent.
• Typically has 12 years of experience or demonstrated portfolio consistent with experience required of the role in technology risk, information security, operational risk, or related disciplines within a regulated or otherwise complex operating environment.
• Strong understanding of risk management practices, control frameworks, and second-line oversight within a three lines of defense model .
• Demonstrated experience providing independent review, challenge, or governance of first-line technology, security, data, or operational risk activities.
• Strong ability to assess control design and effectiveness, synthesize risk data, identify themes, and translate technical issues into business risk.
• Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross-functional partners.
• Strong critical thinking, judgment, and problem-solving skills, with the ability to provide practical, risk-based recommendations in a complex environment.
• Ability to operate independently, manage competing priorities, and maintain effective working relationships while preserving second-line objectivity.
• Background and drug screen.
Preferred Qualifications
• Advanced degree or additional related education and/or experience preferred.
• Experience in financial services, payments, fintech, or another highly regulated industry.
• Familiarity with relevant regulatory e
Salary insight
The midpoint of this range ($207k) is right around the median disclosed salary for San Francisco roles listed on ForgeApply ($200k across 8,660 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Earlywarning role before you apply.
Tailor my resume for this jobSimilar jobs
- System Access Risk Manager — Ingram Micro · Irvine, CA
- Technology Risk - Risk Management - Principal — Fanniemae · Reston, VA | Plano, TX
- Manager, Privileged Access Management — Raymond James · Saint Petersburg, Florida - United States | Memphis, Tennessee - United States | Southfield, Michigan - United States
- Security Risk Manager — Asana · San Francisco
- Staff Security Risk & Compliance Program Manager - Access Management — Confluent · Remote
- Data Management Risk Officer — BMO · Chicago, IL
- Patient Access Manager — Ensemble Health Partners · Lorain, OH | Mercy - Lorain Hospital
- Patient Access Manager — Ensemble Health Partners · Miami, FL
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)