×
Register Here to Apply for Jobs or Post Jobs. X

SVP & Director of IT Governance - Cyber Security

Job in Ross Township, Allegheny County, Pennsylvania, USA
Listing for: WesBanco Bank Inc.
Full Time position
Listed on 2026-08-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 150000 - 210000 USD Yearly USD 150000.00 210000.00 YEAR
Job Description & How to Apply Below

SUMMARY:

Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit, and executive leadership to ensure the technology risk posture aligns to regulatory expectations, enterprise risk appetite, and industry frameworks. Requires deep expertise in banking technology regulations, enterprise risk frameworks, and control design, balanced with the executive presence to communicate complex risk themes to technical and non-technical audiences, including Board-level committees.

ESSENTIAL DUTIES AND RESPONSIBILITIES:
  • To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
  • Owns andmaturesthe enterprise IT GRC program, including policies, standards, procedures, and control frameworks aligned to NIST CSF 2.0, CIS Controls v8, FFIEC CAT/Architecture, and applicable regulatory guidance (OCC, FDIC, Federal Reserve).
  • Establishes andmaintainsthe technology policy hierarchy (policy standard procedure control) with defined ownership and periodic review cadence.
  • Serves as program owner for the technology governance council structure (e.g., IT Steering, Technology Risk), including agenda-setting, reporting, and action item tracking.
  • Operationalizes AI governance standards (NIST AI RMF, ISO/IEC 42001), including AI inventory, risk tiering, lifecycle controls, and oversight of vendor AI use cases.
  • Directs the enterprise technology risk assessment program (annual and event-driven) across infrastructure, applications, data, cloud, and third-party environments; ensuremethodologyaligns to ERM/RCSA and risk appetite.
  • Maintains and evolves the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exception workflows.
  • Leads risk assessment and advisory activities for emerging technologies (AI/ML, cloud, RPA), translating technical exposures into business impact and decision options.
  • Develops and reports technology risk metrics and KRIs for senior leadership and Board committees; drive a data-driven risk culture.
  • Serves as the primary IT GRC point of contact for regulatory examinations (OCC, FDIC, Federal Reserve) and internal/external audit engagements related to technology, cybersecurity, and operational risk.
  • Monitors and interprets evolving regulatory requirements and supervisory guidance (FFIEC, SR letters, OCC bulletins, GLBA Safeguards, privacy laws) and translate them into actionable obligations and control updates.
  • Manages technology audit and exam finding remediation: track issue aging,validate evidence, and ensure sustainable control improvements with clear ownership and timelines.
  • Partners cross-functionally to support intersecting risk programs (e.g., model risk governance/SR 11-7 alignment, BSA/AML technology controls, and data governance) as applicable.
  • Leads the technology and cybersecurity components of Third-Party Risk Management (TPRM), including onboarding due diligence, periodic reviews, and ongoing monitoring for critical/high-risk vendors.
  • Defines vendor risk tiering criteria and control requirements for SaaS, cloud, and AI providers; ensure contract provisions address security, privacy, SLAs, and right-to-audit.
  • Coordinates with Procurement and Legal to ensure contractual risk provisions (e.g., DPA, data handling, incident notification) are implemented and enforced.
  • Design and implement a continuous controls monitoring(CCM) approach leveragingGRC toolingto automate evidence collection, control attestations, and targeted testing.
  • Overseescontrolself-assessments (CSA) across IT domains (identity and access management, change management, vulnerability management, data protection) andvalidateremediation effectiveness.
  • Partners with Cybersecurity on security control maturity assessments (CIS Controls, NIST SP 800-53) and annual FFIEC CAT completion.
  • Leads or co-leads the annual SOC 1/SOC 2 review process for material service providers and support SOX ITGC scoping, testing coordination, and remediation tracking (as applicable).
  • Builds, leads, and mentors a team of GRC analysts/specialists; establish performance expectations, succession coverage, and professional development pathways.
  • Drives GRC tool strategy and platform optimization (e.g., Service Now GRC, Archer, or equivalent) to enable scalable risk and compliance workflows.
  • Develops and manages the IT GRC program budget, including tooling, vendor contracts, and staffing plans.
  • Champions a risk-aware culture through executive communications, training, and proactive engagement with Technology and business teams.
OTHER REQUIREMENTS:
  • Banking is a highly regulated industry and you will be expected to acquire and maintain a proficiency in the Bank's…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary