USAA Logo

USAA

SSDLC IT/IS Risk Management & Governance Executive - Charlotte

Posted 3 Days Ago
Be an Early Applicant
In-Office or Remote
2 Locations
170K-306K Annually
Expert/Leader
In-Office or Remote
2 Locations
170K-306K Annually
Expert/Leader
The IT/Info Security Risk Management & Governance Executive manages IT/IS risks, leads teams, and ensures compliance with regulatory standards, while advising on risk strategy and governance.
The summary above was generated by AI

Why USAA?

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.

Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.

The Opportunity

USAA is seeking an IT/Info Security Risk Management & Governance Executive who needs to have "hands-on" expertise in SSDLC - Second Line of Defense. This role sits within the Chief Risk Office for Technology.

We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: Charlotte, NC, San Antonio, TX, Tampa, FL with a preference for Charlotte.

*** Relocation assistance is available to Charlotte for this position ***

The successful candidate will serve as a key advisor responsible for recognizing and reporting Information Technology (IT) and Information Security (IS) strategic and aggregate risks across the business while advancing the Enterprise Risk Management function for aggregation, quantification, and qualification of risks. Sets direction for risk management programs within IT/IS and leads all aspects of the delivery of those programs across the line of business.

Provide risk management and governance leadership, operational direction and operational oversight of Information Security, Business Continuity, Data Center Security, AI and Corporate Investigations domains and establish a best-in-class Risk Management framework for the Enterprise Security Group (ESG) to ensure comprehensive oversight and management of risks across the full risk taxonomy. Ensures risks align within appetite tolerances and strategic goals, product plans, forecasts, and adjusts to variances.

Responsible for the aggregation and reporting of risks to senior leadership and effectively assessing and influencing business decisions and direction. Contributes to the long-term strategy of how risk systems should be adapted and integrated to maximize the ability to manage risk in an environment shaped by regulatory change and disruptive, emerging technologies. Ensures effective and appropriate policies, procedures, and controls are in place supporting all risk processes, systems, strategies, and implementations.

Additional responsibilities include but are not limited to:

  • Establishes trust and rapport with senior business leaders across the enterprise to sustain oversight of the second line risk role. Actively engages line of business leaders to ensure all risks are appropriately addressed consistent with policy and the Risk Appetite.

  • Partners with senior risk executives in managing overall risk appetite to include the identification and definition of key methods, metrics, and limits. Influences and sets strategy for advancement of the risk management framework.

  • Partners across Risk Management, Finance, and the business while effectively challenging variances to plan and strategies to mitigate. Provides advice to other key business partners and drive key decisions assessing risk and reward through effective challenge.

  • Liaises with Compliance and CLO on legal & regulatory considerations that impact business operations and product offerings in accordance with federal and state regulations. Influences sound governance structure for oversight of risks and business operations and interacts & engages with all product & channel leaders on complex, multi-product processes and procedures while factoring in all legal & regulatory requirements.

  • Assists in interactions and briefs on domain of responsibility with regulators from the OCC, FED, FDIC, and CFPB as well as prepare Board and Senior Management level reports related to IT/IS risk.

  • Builds and oversees a team of employees (~5 direct reports / 20-30 team size to start) for assigned functional area through ongoing execution of recruiting, development, retention, coaching and support, performance management, and managerial activities.

Minimum Education:

  • Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.

Minimum Experience:

  • 10+ years of risk management, regulatory or operations experience in a functional area such as insurance, banking, or financial services with 5+ years of this experience focused on Information Security, Business Continuity, Physical Security or Corporate Investigations.

  • 4+ years of people leadership experience in building, managing and/or developing high-performing teams.

  • Industry certification(s) in Information Security (e.g., CISSP, CISM) or Business Continuity (e.g., ABCP, CBCP) or Risk Management (e.g., CRISC) or Physical Security (e.g., CPP).

  • Demonstrated experience working with and applying Risk, Security or Audit frameworks (FFIEC, COBIT, COSO, ISO 27001/2, NIST 800-53, SSAE16).

  • Knowledge of applicable laws, rules, and regulations applicable to financial institutions.

  • Experience making data-driven decisions.

  • Experience working with external agencies and regulators.

  • Broad knowledge of information technology systems and general system development principles.

What sets you apart:

  • 7+ years of risk management and regulatory experience in a functional area such as insurance, banking, or financial services (Large size organizations 20k+)

  • 10+ years experience focused on Information Security, Data, Risk Management, evaluating the design and development of software.

  • Experience with artificial intelligence (AI) and machine learning principles, including responsible AI use case evaluations and deployment.  

  • 10+ years "hands-on" experience integrating security throughout the Secure Software Development Lifecycle (SSDLC), including component analysis, static and dynamic scanning (SAST/DAST), penetration testing, and comprehensive application security testing across build, deploy, and maintenance phases.

  • Proven ability to develop high-impact materials and deliver concise, insight-driven presentations to executive leadership, translating complex concepts into actionable recommendations that influence strategic decision-making.

Compensation range: The salary range for this position is: $169,880.00 - $305,780.00.

USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).

Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position.

 

Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.

 

The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.

Long Term Incentive Plan: Cash payment for Executive level roles only, representing a cash payment which is both time and performance based.

 

Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.

 

For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.

Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.

 

USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Top Skills

Abcp
AI
Cbcp
Cism
Cissp
Cobit
Coso
Crisc
Ffiec
Iso 27001/2
Machine Learning Principles
Nist 800-53
Ssae16
Ssdlc

Similar Jobs

10 Hours Ago
Remote or Hybrid
México
Expert/Leader
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Regional Sales Manager will develop and execute sales strategies for public sector clients, establish relationships with key decision makers, and collaborate internally to drive revenue growth in cybersecurity solutions.
Top Skills: CloudCybersecuritySaaSSalesforce
10 Hours Ago
Easy Apply
Remote
31 Locations
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead the Core Planning team at GitLab to enhance enterprise planning through AI integrations, improve workflow efficiency, and connect planning to business outcomes.
Top Skills: DevOpsDevsecopsSaaS
Yesterday
Easy Apply
Remote or Hybrid
México
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
In this role, you will act as a trusted technical advisor, driving customer success by optimizing technical health, managing accounts, and ensuring measurable business value through Samsara's solutions.
Top Skills: APIsGainsightGongJIRAPythonSalesforceTableauZendesk

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account