Principal - AI Technology Risk
Listed on 2026-06-20
-
IT/Tech
Cybersecurity, Information Security
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting‑edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Top technical subject matter expert providing technical and risk management expertise in improving and expanding the observability and reporting on the Security Posture of the Company. This position supports the enterprise‑wide Information Security program as a trusted technical advisor by empowering team members to make risk‑aware decisions in accordance with Early Warning’s compliance, regulatory and departmental policy and procedures. Provides the primary measure of confidence that the security features, practices, procedures, and architecture of the security program accurately mediate and enforce the security policy.
EssentialFunctions
- Create and manage the operating model for identifying and resolving security risks and posture drift.
- Lead initiatives and strategies in support of the Security Posture Management program.
- Own ensuring that business goals and risks are adequately addressed; collaborate and consult with enterprise cross‑functional teams to maintain continuous awareness of the enterprise’s Security Posture and identify improvement opportunities.
- Establish effective working relationships across the enterprise to foster a strong risk culture by supporting stakeholders in owning and managing their risks and controls.
- Ensure controls are successfully designed and implemented to meet compliance requirements and business objectives.
- Manage relationships cross‑functionally to integrate alignment with organizational strategies while addressing risk management needs.
- Review new processes from a control’s perspective and consult with process owners to design and implement new controls.
- Improve risk and control environment by providing subject matter technical expertise on enhancing the design and effectiveness of Security’s control program while aligning with compliance and technical needs.
- Develop, execute, and present the risk reporting framework, ensuring risk mitigation activities are performed timely.
- Select appropriate metrics (KRI/KPI) to monitor adequacy and effectiveness of the control environment.
- Monitor remediation efforts to closure, including review of supporting evidence.
- Develop and enhance documentation and reporting standards to support oversight of the enterprise’s Security Posture and ensure consistent execution and coverage across the enterprise through a stakeholder‑approved policy‑driven governance program.
- Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
- Bachelor’s degree in computer science, information technology, cyber security, or related field.
- 15+ years of progressive related IT or information security work experience, including experience with firewalls, IDS, vulnerability management, anti‑virus, data loss prevention, two‑factor authentication, and VPN.
- 3+ years of experience with security, regulatory, and privacy controls environment, and security governance, regulatory landscape, risk assessment, and risk management principles and techniques.
- Advanced level experience with network security design and protection, application development, application security issues, operating system security, hardening standards and protection mechanisms.
- Strong technical knowledge in security tools, application security design and architecture; secure network design and architecture, server security, and workstation security.
- Ability to articulate the practical and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).