Technology Risk Management
Listed on 2026-06-05
-
IT/Tech
Cybersecurity, Information Security
Join Natixis as a Technology Risk Manager within our Technology Risk Management (TRM) team, operating in the Second Line of Defense (2
LOD). This strategic role is crucial for ensuring robust risk management over IT Operations, Development, and Governance. You will play a key part in overseeing governance and compliance activities for the Technology Risk function, including policy maintenance, 2
LOD control testing, and preparing reports for relevant governance committees. As a key point of contact, you will support the Chief Information Security Officer (CISO) in the day‑day operations of the Technology Risk function.
- Enhance Technology Risk policies and related documentation for the U.S. platform.
- Review local policies to ensure appropriate quality, ownership, coverage, and implementation.
- Support the development of Policy and Procedure documentation to address gaps in the existing policy framework.
- Conduct Technology Risk Assessments and drive mitigation actions.
- Perform periodic Technology Risk control testing to ensure appropriate oversight of the First Line of Defense (1
LOD). - Update and maintain results within the firm’s Governance, Risk, and Compliance (GRC) tool.
- Track and follow up on Audit and Regulatory recommendations and findings.
- Provide essential administrative support for TRM monthly governance committees and other senior management meetings and presentations, as necessary.
- Coordinate documentation gathering for internal and external audits, as well as regulatory examinations.
- Conduct data analysis and mining required for Head Office and local Key Risk Indicator (KRI) and Key Performance Indicator (KPI) reporting.
- Develop and support Information and Cyber Security training programs for employees, including weekly Information Security awareness sessions for new joiners.
- Assist in the development and support of platform‑wide phishing campaigns and targeted spear‑phishing initiatives.
- Bachelor’s degree in Business, Computer Science, Information Security, or a related field.
- 5+ years of experience in Technology Risk or Information Security.
- Previous experience in related areas, such as Information Security and IT Risk & Control functions, is required.
- Prior exposure to industry frameworks (e.g., NIST, COBIT, FFIEC) and regulations (e.g., NY DFS
500, EBA/GL/2019/04, NFA). - Strong technical problem‑solving and data analytical skills.
- Proven experience writing clear and accurate content for internal publications, such as training materials, bulletins, and memos.
- Effective teamwork, communication, collaboration, and relationship‑building skills.
- Ability to operate across IT functions (U.S., Head Office, and other geographies).
- Strong sense of ownership and drive.
- Excellent organizational, time management, and prioritization skills.
- Certification (or working towards) in CISSP, CISA, CISM, CRISC, or CIA is a plus.
- Strong communication and interpersonal skills, with the ability to engage with employees at all levels, including other geographical platforms.
- Detail‑oriented manager with a strong working knowledge of program, portfolio, and project management techniques, processes, and methodologies.
- Ability to work independently while collaborating effectively in teams.
- High degree of integrity and a strong work ethic.
- Commitment to timely follow‑through on commitments.
- Capability to navigate and work across departments while understanding and anticipating their constraints.
- Experience in a multicultural environment is preferred.
- Proficiency in MS Excel, PowerPoint, and Word is required; familiarity with RSA Archer is a plus.
Natixis is an equal opportunity employer, committed to a workplace free of discrimination. Natixis will not tolerate any form of discrimination based on age, color, mental or physical handicap or disability, pregnancy, marital status, sexual orientation, national origin, alienage, ancestry or citizenship status, race, religion, sex (including sex stereotyping, gender identity, gender expression or transgender status), veteran status, creed, genetic information or carrier…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).