Director of Risk and Compliance

Core BankOmaha, NebraskaOn-siteFull-timeStaff, 8–12 yearsListed 2 hours ago

Apply now

About this role

Company Overview

Core Bank is a high-performing, tech-forward community bank serving Omaha and Kansas City. Guided by our vision to be high-performing, solutions-based, and tech-forward, we combine trusted relationships with modern tools to deliver smarter, faster, and more personalized banking. Our culture—what we call our Recipe for Awesome —makes Core Bank more than a place to work or bank; its a place where people grow, solutions thrive, and together we build better. If you want to help us build something remarkable, then we'd love to get to know you. To learn more about what makes us - us, explore www.corebankcareers.com .

Position Summary

Core Bank is focused on delivering exceptional banking experiences while enabling innovation through commercial banking, embedded finance, and fintech partnerships. The Director of Risk & Compliance plays a critical leadership role in supporting that vision by ensuring the Bank maintains a scalable, business-focused, and forward-looking risk management framework.

Reporting directly to the Chief Risk Officer (CRO), the Director of Risk & Compliance serves as the CRO's second-in-command and the day-to-day enterprise risk operating leader. This leader is accountable for the day-to-day leadership, execution, integration, and continuous advancement of the Bank's enterprise risk capabilities across Enterprise Risk Management (ERM), Compliance Management, Financial Crimes Compliance, Third-Party Risk Management, Operational Risk, Technology and Cybersecurity, Business Continuity, Data, AI, and other emerging risk domains. By translating the CRO's direction into action, the Director helps the Bank pursue growth opportunities safely and responsibly and within the Board-approved risk appetite to drive consistent growth.

The Director of Risk & Compliance represents Enterprise Risk Management as a strategic enabler and trusted partner to the lines of business, executive leadership, the Board, and regulators. This leader combines independent challenge with practical judgment, helping the Bank identify responsible pathways to growth rather than positioning Risk as a barrier. The ideal candidate brings expertise across traditional banking risk disciplines and an informed understanding of fintech ecosystems, Banking-as-a-Service (BaaS), embedded banking models, data and AI governance, and emerging risks. Through credible, timely decisions and scalable risk solutions, the Director strengthens trust in the second line, supports innovation within established risk appetite, and advances the Bank's purpose, vision, and values.

The Director will also lead the evolution of the Bank's risk capabilities and oversight model toward a next-generation, forward-looking risk management framework. This includes expanding the use of leading and emerging risk indicators, scenario analysis, external intelligence, trend analysis, risk sensing, data and analytics, and other techniques that allow the Bank to identify weak signals and emerging threats before they deteriorate into events that could challenge the Bank's risk appetite, strategic objectives, or trusted regulatory standing.

The ideal candidate is an experienced enterprise risk leader and highly effective operator who can move seamlessly between strategy and execution; understands how a bank creates value; has the credibility to challenge senior leaders; has the judgment to make decisions without unnecessary escalation; and can build scalable, modern risk capabilities that support responsible growth.

Supervisory Responsibilities

- Provide leadership, coaching, development and performance management for Risk personnel.

- Foster a high-performance culture focused on accountability, collaboration, innovation, responsiveness, and continuous improvement.

- Build the confidence and decision-making capabilities of Risk team members so that decisions are made promptly and appropriately at the lowest effective level. Coach Risk personnel through complex judgments and decisions rather than allowing uncertainty or fear of making the wrong decision to become a reason for unnecessary escalation.

- Establish clear decision rights and escalation thresholds and coach team members through complex risk judgments, reserving only matters with material strategic, financial, regulatory, or risk-appetite implications are elevated to the CRO.

- Reinforce a culture in which Risk professionals are expected to make recommendations and decisions, not simply identify problems or escalate questions.

Duties and Responsibilities

Enterprise Risk Management Leadership

- Lead the day-to-day execution of the Enterprise Risk Management strategic plan, framework and ERM plan activities to ensure enterprise risk management programs remain examination and audit-ready on a continuous basis.

- Translate the CROs strategic priorities and direction into actionable plans, accountabilities, decisions, and measurable outcomes.

- Serve as the CRO's primary delegate and go-to enterprise risk leader in management committees, governance forums, and material business decisions, as appropriate. Exercise delegated authority, provide timely risk-based recommendations, resolve issues at the appropriate level, and escalate matters to the CRO when they exceed established decision rights, risk tolerances, or the Board-approved risk appetite.

- Evaluate strategic initiatives, new products, services, business lines, technologies, partnerships, and material changes to the Bank's operating model for alignment with strategic objectives, risk appetite, and safety and soundness.

- Partner closely with business and functional leaders to understand strategic objectives, identify risks and opportunities, and develop practical pathways to achieve desired outcomes within the Board-approved risk appetite.

- Build strong, trusted relationships with business leaders while maintaining independent second-line challenge to promote practical, scalable risk management practices that are embedded into business operations and decision-making.

- Maintain and continuously mature enterprise-wide risk assessment methodologies, risk inventories, risk appetite measures, key risk indicators, and governance processes. Expand the program's use of leading and emerging risk indicators, scenario analysis, external intelligence, and forward-looking trend analysis to identify signals before they develop into events that could affect strategic outcomes, the Board-approved risk appetite, or impact regulator trust.

- Prepare executive- and Board-level risk reporting that translates leading, emerging, and lagging indicators into clear insights, plausible scenarios, and recommended actions. Develop and adapt reporting that shows how changes in the risk profile may affect strategic objectives, the Board-approved risk appetite, shareholder value, consistent returns, and regulator trust.

- Translate emerging and leading indicators into clear implications, scenarios, decisions, and recommended management actions.

- Coordinate enterprise issue management, remediation tracking, and risk governance activities across all business lines and functions.

- Identify opportunities to simplify, streamline, automate, or redesign risk processes so that they scale with the Bank's growth.

- Continually assess whether the Bank's risk framework, governance, talent, data, technology, and capabilities enable and support the Bank's evolving strategy and risk profile.

- Define and maintain enterprise risk decision rights, escalation criteria, and governance protocols that enable timely decisions by qualified risk and business leaders while ensuring material matters receive appropriate C-suite, or Board attention.

Technology Risk, Cybersecurity & Emerging Technology Risk Oversight

- Partner with technology and business leaders to ensure innovation occurs safely and within established risk tolerances.

- Serve as the Bank's independent second-line risk leader for cybersecurity, operational resiliency, business continuity, disaster recovery, data governance, and technology risk management.

- Provide independent second-line oversight and credible challenge of Information Technology, Information Security, Cybersecurity, Privacy, Data, AI and related risk domains and programs.

- Independently assess whether technology and cyber risk management capabilities appropriately support the Bank's strategic objectives, growth plans, operational resilience, and risk appetite.

- Oversee governance, and risk and control assessments for artificial intelligence, machine learning, automation, banking technologies, models, data, cloud services, third-party technologies, and other emerging technologies.

- Monitor evolving regulatory guidance, supervisory expectations, industry practices, and emerging threats related to AI, fintech, cybersecurity, cloud computing, digital banking, and other technology-enabled financial services.

- Identify emerging technology risks early and ensure appropriate governance is established before risks become material.

Third-Party Risk Management

- Own the Bank's Third-Party Risk Management (TPRM) Program and overall governance framework.

- Provide enterprise oversight of material third-party relationships including fintech partners, embedded banking arrangements, technology service providers, and other outsourced activities.

- Ensure appropriate due diligence, risk assessment, onboarding, monitoring, issue management, operational resilience, and offboarding practices are maintained.

- Evaluate and monitor concentration, operational, information/cybersecurity, compliance, financial, and strategic risks associated with material third parties.

- Partner with business leaders to establish risk-based, scalable approaches that allow strategic partnerships to grow safely.

- Identify emerging risks within the Bank's partner ecosystem and ensure appropriate action is taken before risks materially impact the banks strategies and plans.

Financial Crimes Compliance and Compliance Program Management Oversight

- Oversee the Bank's Financial Crimes and Compliance Management Programs, teams and overall governance frameworks.

- Ensure effective independent second-line oversight of applicable federal and state laws and regulations, as applicable; including but not limited to CRA, UDAAP, HMDA, Section 1071, complaint management, Fair Lending, marketing compliance, privacy, and other areas as applicable to the Banks activities.

- Monitor evolving regulatory requirements and ensure timely and appropriate regulatory change implementation of policy, process, controls and governance capabilities.

- Ensure Compliance and Financial Crimes programs evolve with the Bank's products, partnerships, technologies, customers, and business model.

- Promote a proactive compliance culture that identifies regulatory risk early and works collaboratively with the business to develop sustainable solutions.

Operational Risk Management

- Own the Bank's Operational Risk Management Framework and related governance processes.

- Ensure operational risk frameworks evolve with organizational growth, technology adoption, third-party dependencies, new products, and changes to the Bank's operating model.

- Oversee operational risk and control assessments, loss event management, root cause analysis, control effectiveness reviews, and issue management activities.

- Coordinate and oversee business continuity and disaster recovery practices and capabilities for ongoing operational resilience.

- Identify systemic and cross-functional operational risks that may not be visible through individual business-line risk assessments.

CRO Support, Executive Leadership & Decision Escalation

- Serve as the CRO's trusted thought partner on enterprise risk decisions, strategic initiatives, and emerging risks. Equip the CRO with recommendations and decision-ready analysis, not simply questions or issues requiring further analysis.

- Proactively identify matters that require CRO attention and resolve matters within delegated authority without unnecessary escalation.

- Help protect the CRO's capacity for strategic planning, C-Suite and Board partnership and governance, regulatory relationships, and enterprise strategy by making appropriate day-to-day risk decisions.

- Provide the CRO with early warning of material changes in the Bank's risk profile, emerging threats, significant control weaknesses, regulatory concerns, and issues that could affect strategic outcomes.

- Serve as a stabilizing and integrating force across the company, ensuring consistent interpretation and application of the CRO's risk philosophy and expectations.

- Step into the CRO's role in appropriate forums and situations when delegated, ensuring continuity of leadership and decision-making.

Audit and Regulatory Relationships

- Support Audit and Assurance activities that are performed independently under direction of the CRO.

- Coordinate regulatory examinations and internal and external audit activities for applicable risk areas.

- Coordinate and support corrective action planning, issue remediation, and sustainable resolution of examination and audit findings.

- Build and maintain trusted relationships with regulators and auditors through transparency and consistent execution.

- Reinforce the Bank's reputation with regulators as an institution that understands its risks, acts proactively, makes sound decisions, and operates within its approved risk appetite.

Regular attendance is required.

Other activities, duties, or responsibilities may be assigned as needed.

Leadership Profile

Business First

Understands that effective risk management exists to help the Bank achieve strategic objectives safely and soundly. Consistently seeks solutions that enable responsible growth. Views risk management as a source of insight, competitive advantage, and disciplined decision-making—not simply control or oversight - helps the business find responsible pathways forward.

Trusted Deputy and Decisive Leader

Serves as a trusted thought partner to the CRO and a credible decision-maker for the enterprise. Applies sound judgment, welcomes constructive challenge, makes timely decisions within delegated authority, develops the decision confidence of the risk team, and escalates only matters that warrant CRO, C-Suite or Board attention.

Future Ready

Understands how technology, AI, fintech, embedded finance, cybersecurity, data, third-party dependencies, regulatory change, and evolving business models are reshaping risk. Builds next-generation capabilities that identify emerging risks before they become material.

Risk Operator and Optimizer

Possesses hands-on experience building, operating, and transforming risk programs from traditional, lagging oversight into forward-looking capabilities that use leading and emerging indicators to anticipate risk, support timely decisions, and enable responsible innovation.

Qualifications

Education and Experience

- Bachelor's degree in Business, Finance, Accounting, Risk Management, Information Technology, Cybersecurity, or a related field, or equivalent professional experience.

- Minimum 12 years of progressive leadership experience in banking, financial services, technology, risk management, compliance, audit, or related disciplines.

- Demonstrated expertise across multiple risk domains, including:

Enterprise Risk Management

- Operational Risk

- Technology Risk

- Information Security & Cybersecurity Risk

- Third-Party Risk Management

- Regulatory Compliance

- Financial Crimes Compliance

- Experience interacting directly with regulators, auditors, executive leadership teams, and Boards of Directors.

- Experience building, transforming, or maturing enterprise risk programs in regulated financial institutions, including implementing leading and emerging risk indicators, scenario analysis, decision frameworks, and executive and Board reporting that support strategic outcomes and preserve safety and soundness.

- Experience supporting fintech partnerships, embedded banking programs, sponsor banking, digital banking initiatives, or technology-enabled financial services environments.

Required Skills/Abilities/Knowledge

- Alignment with the Bank's Purpose, Vision, and Values.

- Deep understanding of Enterprise Risk Management and risk governance principles.

- Strong working knowledge of banking regulations and guidance, including FFIEC standards, BSA/AML requirements, regulatory compliance regulations, and third-party risk guidance.

- Understanding of AI governance, emerging technology risk, cloud services, automation, model oversight, and data governance concepts.

- Knowledge of fintech ecosystems, sponsor banking, Banking-as-a-Service (BaaS), embedded banking, digital banking platforms, and partnership risk management.

- Strong analytical and data interpretation skills, with the ability to leverage reporting and technology tools to support risk-based decision-making.

- Exceptional written, verbal, and executive presentation skills.

- Demonstrated ability to influence outcomes across organizations without direct authority.

- Strategic thinker who can balance detailed risk analysis with broader organizational objectives.

- Agile leader who thrives in evolving environments and can effectively adapt to changing business and regulatory expectations.

- Proven ability to build collaborative relationships across business functions, regulators, auditors, fintech partners, and executive leadership teams.

- Business-first mindset with the judgment, courage, and credibility to make timely risk decisions, recommend practical solutions, challenge constructively, and distinguish matters that can be resolved through delegated authority from those requiring escalation to the CRO, executive leadership, or the Board.

Core Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.