Principal of Access Management Risk
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.Overall Purpose Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managed consistent with enterprise risk appetite, regulatory expectations, and sound industry practice. May support one or more focus areas based on business need, including Enterprise Technology Risk, Data Security Risk, Access Management Risk, Offensive Security Risk, Vulnerability Management Risk, AI Security Risk, and Asset and Inventory Management Risk. Essential Functions Provide independent review, oversight, and credible challenge of first-line technology risk management activities, controls, and decisions. Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards. Provide independent challenge and oversight of risk identification and assessment activities. Review and challenge risk and control self-assessments, issues management, remediation plans, control validation outcomes, and key risk indicators. Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events. Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness. Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees. Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements. Provide ongoing risk advisory support while maintaining&nb...