Senior IT Risk Officer - Cybersecurity
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Data Security
Role Overview
The IT Risk Officer, Sr — Cybersecurity serves as the primary first-line risk professional for Old National Bank’s cybersecurity and information security operational domains. This senior-level role is the IT Risk Office’s subject matter expert and 1
LOD owner for five (5) Tier 1 Assessable Units encompassing Security Operations, Identity and Access Management, Data Protection, Vulnerability Management, and Threat Intelligence.
Lead comprehensive Risk and Control Self-Assessments (RCSAs) for all five assigned cybersecurity AUs, conduct targeted risk assessments, evaluate control design and operating effectiveness, and identify control gaps and risk exposures.
Why It Might Be a FitThe IT Risk Officer, Sr — Cybersecurity must be equally fluent in the language of security practitioners and the language of risk committees, translating technical control performance into risk-rated assessments that drive leadership decisions.
Requirements- Minimum 6–8 years in cybersecurity, IT risk management, or information security governance, with at least 3 years in a financial services environment
- Deep understanding of NIST CSF 2.0; FFIEC Cybersecurity Assessment Tool; PCI DSS v4.0; CIS Critical Security Controls; and OCC Heightened Standards as they apply to information security
- Fluency with GRC platforms (Archer, Service Now IRM, or equivalent); SIEM tooling (Splunk, Microsoft Sentinel); IAM platforms (SailPoint ISC, Entra/Active Directory); cloud security frameworks (AWS Security Hub, AWS Config, CIS AWS Benchmark); and vulnerability management tools (Tenable, Qualys, or equivalent)
- Ability to assess complex cybersecurity environments, quantify risk exposure, and prioritize remediation efforts based on business impact, regulatory urgency, and exploitability
- Exceptional written and verbal communication, ability to translate highly technical cybersecurity findings into business-risk language for executive and board audiences
- Competitive compensation with salary and incentive program
- Medical, dental, and vision insurance
- 401K
- Continuing education opportunities
- Employee assistance program
- Impact Network Groups
- Paid holidays
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).