Skip to main content
F

Director, Technology Risk & Operational Resilience

First Command Financial Services
6 days ago
Remote friendly (Fort Worth, TX, United States)
United States
Indeed

How will your role impact First Command? The Director, Technology Risk & Operational Resilience is a senior leader within Enterprise Risk Management responsible for leading the Company’s technology risk, third-party risk management, and business resiliency teams and providing independent oversight and effective challenge of related first-line risk management activities. Reporting to the SVP, Chief Risk Officer, the Director establishes governance and risk oversight frameworks, monitors exposure against approved risk appetite and tolerances, evaluates interconnected and emerging risks, and provides decision-oriented insights to executive leadership and the Board. The Director oversees enterprise risk practices related to technology, critical third parties, operational resilience, business continuity, crisis preparedness, and disaster recovery. The role partners with Technology, Information Security, Operations, Procurement, Legal, Compliance, Internal Audit, and business leadership to promote clear risk ownership, timely escalation, effective remediation, and resilience of critical business services. What will the employee do in this role? Technology Risk Oversight Lead the second-line technology risk function and the enterprise third-party risk management and business resiliency teams, while providing independent oversight and effective challenge of first-line technology, cybersecurity, business continuity, crisis management, and disaster recovery capabilities. Challenge first-line risk assessments, control activities, remediation plans, and risk acceptance decisions. Provide independent risk oversight and effective challenge of material technology exposures, including cybersecurity, cloud services, data and technology dependencies, artificial intelligence, technology transformation, and end-of-life or unsupported platforms. Provide an independent risk perspective on significant technology investments, architecture decisions, system implementations, cloud migrations, acquisitions, and material changes to critical services. Evaluate technology risk exposures against approved risk appetite statements and tolerance thresholds. Monitor emerging technology risks and industry trends and advise executive leadership on potential impacts to the organization. Oversee technology risk metrics, key risk indicators (KRIs), and executive reporting. Third-Party Risk Oversight Lead the enterprise TPRM governance and oversight function, including risk-tiering standards, due diligence requirements, ongoing monitoring, issue escalation, reporting, and effective challenge of third-party risk decisions. Define roles and accountability among business relationship owners, Procurement, Information Security, Legal, Compliance, and the TPRM function throughout the third-party lifecycle. Provide independent challenge and oversight of vendor risk assessments, due diligence activities, ongoing monitoring, and remediation efforts. Oversee risks associated with critical third-party service providers, strategic partners, cloud service providers, and outsourced business operations. Monitor concentration risk, fourth-party risk, and critical supplier dependency risks. Assess third-party risk management practices against regulatory expectations, industry standards, and organizational risk appetite. Escalate material third-party risks and control weaknesses to executive leadership and governance committees. Operational Resilience & Business Resiliency Establish and oversee the enterprise operational resilience framework, including critical business services, key dependencies, disruption tolerances, and severe-but-plausible scenarios. Lead the business resiliency and crisis preparedness program, including business impact analyses, continuity planning, exercises, and enterprise event readiness. Provide independent oversight and effective challenge of Technology-owned disaster recovery strategies, recovery capabilities, testing results, and remediation plans. …

View the full posting and apply