Data Risk Management Director, Second Line of Defense

Early Warning Services, LLC
New York, US
Hybrid

Job Description

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship. Overall Purpose The Data Risk Management Director will lead elements of and manage the design, implementation, and oversight of the firm’s Data Risk Management Program within the Second Line of Defense (SLOD). This role is responsible for providing management, independent review, challenge, and advisory support to ensure the organization’s management and use of data is aligned with the firm’s risk appetite and stakeholder’s expectations. Reporting to the Senior Director of Data and AI Risk Management within Operational Risk Management, the Director partners closely with first-line business and risk managers, Product Management, Technology (including the Chief Data Office, Data Governance Analytics teams), as well as Compliance, Legal, Privacy, Third-Party Risk, and Technology & Security Risk to embed data risk requirements across the enterprise. The role plays a key part in enabling data-driven decision-making while ensuring data-related risks are appropriately identified, assessed, monitored, and governed. Essential Functions Data Risk Governance & Program Management · Manage the development, maintenance, and ongoing enhancement of the enterprise Data Risk Management framework, policies, standards, procedures, and control expectations, aligned with industry-recognized frameworks such as DAMA-DMBOK and the EDM Council’s DCAM. · Maintain and evolve the data risk and control taxonomies, ensuring consistency with operational risk, compliance risk, and technology risk frameworks. · Oversee the development and use of risk management technologies and tooling used to inventory critical data assets, track data risks, controls, issues, and remediation activities. · Participate in or support enterprise governance forums, committees, and working groups related to data risk, providing independent risk perspectives and recommendations. · Develop and deliver training and awareness related to the Data Risk Management program and expectations. Risk Appetite / Tolerance, Metrics & Monitoring · Support the development and maintenance of data risk appetite or tolerance statements, thresholds, and limits in alignment with enterprise risk appetite and regulatory expectations. · Design, implement, and monitor key risk indicators (KRIs), key performance indicators (KPIs), and key control indicators (KCIs) to measure data risk exposure and program effectiveness. · Analyze trends, emerging risks, and control performance related to data risk concepts. Risk Identification & Assessment · Develop and maintain data risk assessment methodologies, including inherent risk identification, control evaluation, residual risk determination, and escalation criteria. · Execute the second line of defense enterprise-level data risk profile assessment to measure compliance with approved risk appetite or tolerance. · Embed data risk considerations and requirements into other risk domain assessments (e.g., operational risk, AI risk, model risk, third-party risk, privacy, and technology risk). · Identify emerging data risks related to data quality, integrity, lineage, access controls, aggregation, retention, regulatory reporting, and customer impact. Independent Review, Challenge & Quality Assurance · Provide effective independent review and challenge of first-line data risk assessments, control design, mitigation strategies, and risk acceptance decisions. · Execute and/or oversee quality assurance (QA) activities to assess adherence to data risk management policies, standards, and governance requirements. · Identify gaps, weaknesses, or inconsistencies in data risk practices and ensure issues are documented, escalated, and tracked through remediation. · Partner with other second-line risk domains to deliver integrated, holistic risk oversight of data-enabled processes, analytics, and products. Risk Reporting & Insights · Develop and deliver insightful, enterprise-level data risk reporting that clearly communicates risk posture, trends, emerging issues, and program health. · Prepare materials for senior management, governance committees, and external stakeholders that drive informed decision-making and timely action. · Lead regulatory exam support, internal audits, and management self-assessments related to data governance and data risk manageme

Skills & Requirements

Technical Skills

Data risk managementOperational risk managementCompliance riskTechnology riskData governanceData analyticsData control taxonomiesRisk management technologiesRisk indicatorsKey performance indicatorsKey control indicatorsData risk assessment methodologiesData risk profile assessmentData risk reportingRegulatory exam supportInternal auditsManagement self-assessmentsIndependent reviewChallengeAdvisory supportData-driven decision-makingRisk identificationRisk assessmentRisk monitoringRisk governanceRisk reportingInsightful reportingEnterprise-level data risk reportingSenior management reportingGovernance committee reportingExternal stakeholder reportingFinancial servicesData governanceRisk managementComplianceLegalPrivacyThird-party riskTechnology & security risk

Employment Type

FULL TIME

Level

senior

Posted

4/5/2026

Continue to Workday

You will be redirected to the job posting on Workday.