Demo

Technology Risk Director- CyberSecurity

Citizens Financial Group
Johnston, RI Full Time
POSTED ON 4/28/2026
AVAILABLE BEFORE 6/28/2026

Description

As a First Line of Defense Cybersecurity Risk Director within the Enterprise Technology Security (ETS) Risk organization, you will provide strategic leadership in protecting the organization against evolving cyber threats while enabling business innovation. This role is accountable for the design, execution, and continuous maturity of the cybersecurity risk management framework, ensuring cyber risks are proactively identified, assessed, mitigated, monitored, and transparently reported. You will serve as a trusted advisor to senior leadership, translating complex cybersecurity and technology risks into clear business impacts and risk-based decisions aligned to enterprise risk appetite. The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and business leaders to ensure cybersecurity risk strategies are fully integrated with business objectives, regulatory expectations, and enterprise resilience goals. You will also lead and develop a high performing team of cybersecurity risk professionals, fostering a culture of strong risk discipline, constructive challenge, and continuous improvement across the organization.

Key Responsibilities

Leadership & Strategy

  • Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise.
  • Define and evolve the cybersecurity risk management strategy and operating model, ensuring alignment with enterprise risk appetite, regulatory requirements, and business priorities.
  • Translate cyber and technology risks into business relevant impacts, enabling senior management to make informed, risk-based decisions.

Cybersecurity Risk Management & Oversight

  • Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and monitoring of cyber and technology risks.
  • Define and maintain key risk indicators (KRIs), controls, and control testing strategies to measure cybersecurity risk exposure and control effectiveness.
  • Provide oversight of Risk and Control Self Assessments (RCSAs), Targeted Risk Reviews, business initiative risk assessments, and issue management, ensuring timely remediation and sustainable risk reduction.
  • Maintain visibility into detailed cyber risk assessments, advising business and technology leaders on prioritized mitigation strategies and risk tradeoffs.

Business Partnership & Advisory

  • Act as a strategic risk advisor to business lines and technology leaders, providing day to day guidance on regulatory compliance, risk mitigation, and industry best practices.
  • Advise on new products, processes, technologies, and strategic initiatives, ensuring appropriate risk identification, control design, and governance approvals are in place.
  • Guide business partners through enterprise governance forums and approval processes, ensuring cyber risks are understood, documented, and appropriately managed.

Regulatory, Audit & External Engagement

  • Serve as the primary risk lead for regulatory exams and audits related to cybersecurity and technology risk for assigned products or functions.
  • Partner with Internal Audit, and second line stakeholders, leading exam preparation, responses, and ongoing issue remediation.
  • Ensure compliance with applicable laws, regulations, and supervisory guidance, including FFIEC, GLBA, SOX, and other relevant standards.

Collaboration & Stakeholder Management

  • Build and maintain strong, trusted relationships with business partners, technology leaders, security teams, project stakeholders, and subject matter experts.
  • Collaborate across lines of defense to provide effective challenge while enabling responsible innovation and delivery.
  • Promote a culture of cybersecurity awareness and operational resilience across the organization.

Qualifications - Experience & Skills

  • 10 years of experience in Cybersecurity and/or Information Technology, with deep exposure to enterprise environments.
  • 10 years of risk management experience within financial services, preferably in cybersecurity, technology risk, or operational risk.
  • Strong experience with cloud technologies (IaaS, PaaS, SaaS), DevSecOps, web applications, operating systems, databases, and networking.
  • Broad knowledge of cybersecurity domains including:
    • Network and infrastructure security
    • Vulnerability and configuration management
    • Identity and Access Management including Customer Identity
    • API and application security
    • Data protection and cryptography
    • Operational resilience
    • Incident, problem, and change management
  • Experience operating in a highly regulated environment under significant supervisory scrutiny.
  • Solid understanding of internal controls, risk assessments, and governance processes.
  • Working knowledge of FFIEC guidance, GLBA, SOX, and related regulatory frameworks.
  • Familiarity with leading industry frameworks, including Cybersecurity Risk Institute, NIST Cybersecurity Framework, Cloud Security Alliance, NIST 800 53, and ISO 27001.
  • Demonstrated ability to synthesize complex risk data, prioritize mitigation actions, and influence outcomes.
  • Exceptional communication and executive presence skills, with the ability to engage all levels of the organization.
  • Proven leadership, coaching, and talent development experience.
  • Strong project and program management capabilities across multiple stakeholders.

Education & Certifications (Preferred)

  • Bachelor’s Degree required; Master’s Degree preferred.
  • Professional certifications strongly preferred, including:
    • Certified Information Systems Security Professional (CISSP)
    • Certified Cloud Security Professional (CCSP)
    • Cloud security specialty certification in AWS and Azure
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)
    • Certified in Risk and Information Systems Control (CRISC)

Hours & Work Schedule

  • Hours per Week: 40
  • Work Schedule: Monday-Friday
  • Hybrid: 4 days onsite, 1 day remote

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.

Benefits

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more.


Awards We've Received

Glassdoor Best Place to Work in Consulting, Finance & Insurance
Human Rights Campaign Corporate Equality Index 100 Award
Newsweek America's Most Charitable Company
The Banker's
US Bank of the Year
Dave Thomas Foundation’s Best Adoption-Friendly Workplace
Disability:IN Best Places to Work for Disability Inclusion

Salary.com Estimation for Technology Risk Director- CyberSecurity in Johnston, RI
$235,783 to $304,315
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Technology Risk Director- CyberSecurity?

Sign up to receive alerts about other jobs on the Technology Risk Director- CyberSecurity career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$228,678 - $310,400
Income Estimation: 
$282,790 - $435,557
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Citizens Financial Group

  • Citizens Financial Group Lewes, DE
  • Job ID 46464 Full/Part Time Full Time Shift 1ST Posting Start Date 04/28/2026 Posting End Date 06/06/2026 Description Starting Salary: $21 / hour and up As... more
  • Just Posted

  • Citizens Financial Group Clinton, CT
  • Job ID 46097 Full/Part Time Full Time Shift 1ST Posting Start Date 04/14/2026 Posting End Date 06/06/2026 Description Starting Salary: $25 / hour and up Ci... more
  • Just Posted

  • Citizens Financial Group Chagrin Falls, OH
  • Job ID 46484 Full/Part Time Part Time Shift 1ST Posting Start Date 04/28/2026 Posting End Date 06/06/2026 Description Starting Salary: $21 / hour and up As... more
  • Just Posted

  • Citizens Financial Group Claremont, NH
  • Job ID 45685 Full/Part Time Full Time Shift 1ST Posting Start Date 03/25/2026 Posting End Date 05/02/2026 Description Starting Salary: $25 / hour and up Ci... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Technology Risk Director- CyberSecurity jobs in the Johnston, RI area that may be a better fit.

  • Citizens Bank Johnston, RI
  • Job Description The Enterprise Technology & Security (ETS) Risk Director directs a team of risk professionals, developing comprehensive risk management str... more
  • 1 Day Ago

  • Citizens Johnston, RI
  • Description The Enterprise Technology & Security (ETS) Risk Director directs a team of risk professionals, developing comprehensive risk management strateg... more
  • 15 Days Ago

AI Assistant is available now!

Feel free to start your new journey!