Sr. Manager, IT Risk
Listed on 2026-08-05
-
IT/Tech
Cybersecurity, IT Consultant, IT Project Manager, IT Business Analyst
Ent Credit Union and Wings Credit Union joined forces in January 2026. This merger means more opportunities, expanded resources, and a shared commitment to delivering exceptional member service. Together, we become more – empowering members, communities, and teams through a bold, unified future. Both organizations bring a strong legacy of member satisfaction, operational excellence, financial stability, and community impact. Recognized locally and nationally as best-in-class financial institutions and employers of choice, each is known for its commitment to financial well-being and philanthropic leadership.
Join us during this transformative time and be part of shaping the future of banking! To learn more about the merger, .
Job Description Sr. Manager, IT Risk supports the Dir-Business and Technology Risk by leading a team in the development, implementation, and maintenance of an enterprise-wide Technology Risk Management program, aligning with the Information Security Policy (ISP) and organizational objectives. This role establishes robust First Line frameworks, manages technology risk assessments, and performs focused controls testing to support risk assessments, providing thought leadership and consultative advice to ensure effective integration of risk practices across all business units.
Collaborating closely with IT, Enterprise Security, and business leaders, the senior manager enhances risk control initiatives and fosters a risk-aware culture. Through these comprehensive efforts, the Sr. Manager, IT Risk not only enhances regulatory compliance and audit preparedness but also strengthens the credit union’s defenses against technology-related risks.
Essential Functions
Technology Risk Program Management:
Lead the inventory and understanding of existing key technology processes, risks, and internal controls within Ent’s GRC platform (Archer), ensuring alignment with organizational environments and standards.
Conduct and document process walkthroughs to define technology processes and identify key control activities, ensuring management self-assesses its key inherent technology risks and control activities effectively.
Act as a consultant to the business units for the implementation of technology changes, ensuring risk considerations are integrated and compliance standards are met. Oversee the evaluation of risk implications for new technology implementations and changes, ensuring robust compliance monitoring and reporting aligned with the Information Security Policy (ISP). Draft and present Risk and Control Matrices (RACMs) for key technology risks and mitigating controls to business line management for review and approval.
Design and perform focused controls testing to support required technology risk assessments Coordinate with business line management to review, update, and approve RACMs, including memorializing and retaining evidence of approval.Technology Risk Monitoring and Strategy Implementation:
Design and maintain comprehensive risk dashboards/reports for senior management, the Enterprise Risk Management Committee (ERMC), and the Board of Directors, highlighting key technology risks, mitigation efforts, and trends.
Develop and refine technology risk mitigation strategies, advising IT and business units to ensure practical and sustainable risk controls.
Provide strategic advice on policy development and compliance, helping to shape policies that mitigate risks effectively and align with organizational goals.
Assist business lines in drafting program documentation (e. g. , procedures, reporting, training) that reflects approved technology risks and controls, enhancing partnerships between risk management and operational teams.
Leverage prior knowledge, testing, and experience gained from roles and results of engagements previously performed by Internal Audit and other assurance and advisory service providers to refine technology risk processes.
Staff Development and Team Leadership:
Develop and implement training programs to enhance team capabilities in technology risk management, ensuring alignment with industry-recognized standards and certifications.
Provide ongoing feedback and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).