Chief Data Risk Officer

Truist BankCharlotte, Atlanta, Richmond, Georgia, North Carolina, VirginiaOn-siteFull-timeListed 2 hours ago

Apply now

About this role

The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:
Regular

Language Fluency:  English (Required)

Work Shift:
1st shift (United States of America)
#

Please review the following job description:

The Chief Data Risk Officer is a senior executive position responsible for building and leading the independent oversight and effective challenge function for Enterprise Data and Artificial Intelligence (AI) management. Oversight activities will cover data management practices spanning across Enterprise Data Office (EDA), Artificial Intelligence, Enterprise Data Operations & Delivery, and Line of Business & Corporate Functions Data offices. Reporting to the Chief Information Risk Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across all data domains, while supporting the institution's strategic objectives.

This role will lead and implement Risk oversight for Enterprise Data and AI for Truist, which includes: 1) Establish and manage the enterprise data risk strategy via the creation and deployment of the Truist Data Risk Policies, AI Oversight Policies, Data Framework and Assessment; 2) Serve as the Chief Data and AI Risk Officer with independent oversight and challenge to the Chief Data office and Enterprise AI and Data (AID) team for all risk types where / when present in Enterprise Technology; 3) Provide guidance to senior leaders across the company on critical technology issues for both internal and external stakeholders; 4) Use judgment to escalate significant issues and emerging risks; communicate data domain maturity and residual risk to the Board of Directors; 5) consistently and appropriately apply second line of defense corporate authority for managing Truist’s data and AI risk.

Essential Duties and Responsibilities

Following is a summary of the essential functions for this job.  Other duties may be performed, both major and minor, which are not mentioned below.  Specific activities may change from time to time.

1. Strategic Leadership - Develop and maintain the enterprise-wide data risk management framework, incorporating emerging risks related to data and AI.  Establish risk appetite statements, key risk indicators, and thresholds for data risk across the organization.  Provide independent assessment and challenge of technology initiatives, ensuring alignment with risk appetite and regulatory expectations. Lead the evaluation of strategic technology decisions and their impact on the organization's data risk profile.

2. CDO Risk Leadership - Provide independent risk oversight (i.e., second line of defense/LOD2) for Truist Enterprise AI and Data through the effective identification, mitigation, monitoring and reporting of operational, technology, data, and compliance related risks within Enterprise Data.  This role includes independently challenging LOD1 self-assessments and proving effective challenges of Enterprise Data function to ensure execution across all applicable risk types remain within our stated risk appetite. Additionally, this role is responsible for integrating and aligning all cybersecurity risk with business unit risk, controls and assessments. Work in conjunction with other Risk Oversight Officers (RCSA, IRM, MRMD etc.) to ensure a common set of requirements in establishing a comprehensive risk management approach & transparent decision making and prioritization of technology activities.

3. Governance and Oversight - Serve as a non-voting member of the first line-owned Technology, Data and Operations risk committee, a voting member of the CIRO led risk committee and actively participate in the Enterprise and Board Risk Committees (BRC)). This includes (a) reviewing and effectively challenging data and AI risk policies, standards, and procedures, (b) overseeing the assessment and monitoring of critical technology vendors and third-party service providers, and (c) ensuring compliance with regulatory requirements and supervisory guidance related to technology and data risk.

4. Risk Assessments - Define, communicate, and drive the Enterprise Data and AI Risk Framework and direct the assessment of data management, data privacy, data protection, data resiliency and AI. Provide independent assessment and oversight of the maturity of technology and adequacy of technology controls in meeting agreed to business outcomes for performance, stability, security and service availability. Assessments should leverage agreed upon metrics produced by Business Units (LOD1), but challenge and validated as appropriate.

5. Risk Continuous Monitoring - Oversee the evaluation of technology strategy and operations (including artificial intelligence (AI) and machine learning) for potential risks and biases. Furthermore, monitor technology projects portfolios, developmental methodologies, and progress on project milestones. Review of significant technology incidents, related to data, and direct remediation efforts.  Using monitoring routines to identify emerging risk and/or consider accelerate risk reviews of data policies/standards, business processes or control assessments.

6. Risk Reporting - Design the standard recurring reporting packages for Enterprise Data to support ongoing reporting of identification, mitigation, monitoring of material risks.  These reporting packages will be used for internal discussions and/or governance reporting.

7. Regulatory Engagement Oversight - Serve as the primary risk point of contact with regulators on data and AI risk matters. This includes presenting regular risk assessments and updates to external stakeholders and collaborating with Truist Audit Services (TAS) / external auditors on data audits.  Additionally, this role should provide effective challenge and validation procedures on all data regulatory remediations where management actions are being reviewed and validated for closure.

8. Talent Management - Lead, manage and develop teammates directly and indirectly.  Leverage industry insights to influence enterprise technology talent management through recommendations to Truist senior leadership to inform decisions on resource allocations (both competence and capacity). Where needed, encourage, and facilitate Technology Risk education series, skills training, and industry participation in conference to elevate competence of the risk teammates and enable risk management to meet its objectives of maintaining a strong stature and influence with the company.

9. Risk Culture - Promote the culture of Risk Management across the organization by empowering risk teammates to embrace leadership direction, identify risk exposure in everyday operations and champion improving the enterprise programs for building a sustainable business model, meeting the objectives outlines by leadership and the Board of Directors.

Qualifications

Required Qualifications:

The requirements listed below are representative of the knowledge, skill and/or ability required.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

1. Advanced degree in Data, Data Science, Data Analytics, Computer Science, Information Systems, or data/technology related field.

2. Fifteen+ (15+) years of progressive managerial experience in managing Data Operation, Data Management & Risk Management risk management within a Category 2 or 3 Large Financial Institution (LFI), with a deep understanding of regulatory requirements for complex financial services organization (including Federal Reserve and FDIC regulations).

3. In depth understanding of how data is captured, transformed, and used and the ability to connect end-to-end processes independently.  Additionally, experience in leveraging modern tools to measure effective of data controls.

4. Fifteen+ (15+) years of experience or equivalent proficiency in managing people with demonstrated high competency in recruiting, developing, and coaching/mentoring.

5. Fifteen+ (15+) years of experience in a financial institution with emphasis on risk management or equivalent work experience.

6. Strong understanding of data governance, privacy requirements, and AI risk management.

7. Experience with enterprise architecture and emerging technologies.

8. Knowledge of key technology rules/regulations and technology risk management practices (e.g. Federal Financial Institutions Examination Council (FFIEC), Control Objectives for Information and Related Technology (COBIT), NIST (National Institute of Standards and Technology), Information Technology Infrastructure Library (ITIL)).

9. Excellent leadership skills including the ability to lead direct and indirect reports, including executive level leaders.

10. Excellent communication (verbal and written), presentation and facilitation skills; ability to influence and communicate with C-suite executives and board members. This includes the ability to translate technical concepts for various audiences.

11. Excellence in building and leading high-performing teams.

Preferred Qualifications:

1. Bachelor’s degree in finance or business equivalent.

2. Professional designations such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (Information Systems Audit and Control Association) (CRISC), Certified Project Manager (CPM) Strategic business and financial planning experience.

3. Have an innovation mindset and strong understanding of industry recognized tooling to support enterprise data programs and strong control environments.

4. Experience with audit processes and techniques.

The annual base salary for this position is $320,000 to $400,000.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site . Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law     E-Verify IER Right to Work