Director - Technology, Data and Cyber (TDC) Risk Validation
Charlotte, NC, US, 28202
SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.
In the Americas, SMBC Group has a presence in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.
Role Description
The Director of TDC Risk Validation role supports the development, maintenance and independent validation of the Information Technology (IT), Cybersecurity and Data risk management frameworks for the SMBC Group Americas Division (AD), in accordance with applicable regulations, home office policies and industry practices for risk management.
The Risk Management Department (RMDAD) is the second line of defense in its role of independently monitoring and assessing business practices as related to the risk appetite framework for SMBC. Within RMDAD, Tech, Data and Cyber Risk Oversight (TDCRO) establish technology, data and cyber risk management policies and framework with defined roles and responsibilities across first and second lines and provides independent challenge and validation of first line risk management execution. The Director is responsible for managing second line oversight areas that holistically impact tech, data, and cyber risk disciplines, including frameworks, policies, procedures, methodology, independent validation approach, risk reporting, etc.
Role Responsibilities:
• Maintains second line risk frameworks, policies, procedures, standards and methodologies across technology, cyber, artificial intelligence (AI) and data risk.
• Leads independent validation and effective challenge of first line TDC risk management execution, including design and operating effectiveness assessments and issue tracking through closure.
• Defines and enables TDC risk tooling strategy.
• Performs insight generation of first line programs to enable independent monitoring, challenge, and validation activities. Transforms tech, cyber, data, AI risk reporting from static reporting to insight-driven, forward looking risk assessment using Power BI, Tableau, or similar tools.
• Manages TDC risk working group, committees, materials, and risk metrics reporting.
Expertise and Qualifications
• Well-versed in technology & cyber risk management practices with the ability to connect and align with the firm’s enterprise risk and operational risk management processes.
• Extensive working experience in risk committee and board-level reporting.
• 10+ years of direct work experience within the financial services or technology industries, focused on risk management, control testing and validation, regulatory & audit.
• Foundational knowledge of enterprise, operational and technology risk management practices.
• Experience and proficiency utilizing Power BI, Tableau, or similar visualization / dashboarding tools to design forward-looking risk dashboards.
• Direct experience (or strong proficiency) in data storytelling, integrating analytics, visualization, and business context to develop board‑level risk narratives that inform strategic decision‑making.
• Direct experience with Power BI, Tableau, or similar tools to design and develop risk dashboards; experience building KRIs, KCIs, or KPIs is a plus.
• Working knowledge of technology, cyber and data risk management processes, controls, industry practices, and framework (e.g., NIST CSF, ISO, ITIL, COBIT, BCBS 239).
• Strong organizational skills and detail oriented with ability to manage concurrent priorities.
• Bachelor’s/University degree, master’s degree preferred.
• Power BI, Tableau, and CISA/CISM/CISSP/ CRISC certifications preferred.
SMBC’s employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.
SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.
Nearest Major Market: Charlotte