Jobs › Phoenix › Principal Technology Risk Management - Data Security
Principal Technology Risk Management - Data Security
Early Warning is hiring for the role of Principal Technology Risk Management - Data Security, Phoenix, AZ (Hybrid). This is a Cybersecurity role in the governance, risk, and compliance field. Review the full details below and apply directly with Early Warning.
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship. Job Description Overall Purpose Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managed consistent with enterprise risk appetite, regulatory expectations, and sound industry practice. May support one or more focus areas based on business need, including Enterprise Technology Risk, Data Security Risk, Access Management Risk, Offensive Security Risk, Vulnerability Management Risk, AI Security Risk, and Asset and Inventory Management Risk. Essential Functions Provide independent review, oversight, and credible challenge of first-line technology risk management activities, controls, and decisions. Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards. Provide independent challenge and oversight of risk identification and assessment activities. Review and challenge risk and control self-assessments, issues management, remediation plans, control validation outcomes, and key risk indicators. Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events. Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness. Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees. Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements. Provide ongoing risk advisory support while maintaining second-line independence and accountability for effective challenge. Recommend opportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity. Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data. Focus: Enterprise Technology and Information Security Risk Provide independent challenge and oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains. Provide independent challenge and oversight of information security risk management practices across threat management, network, endpoint, cloud, architecture, data, access, AI, or application security domains. Assess alignment of technology risk and control activities to enterprise policies, risk frameworks, and applicable industry standards. Evaluate whether risk assessments, control inventories, issues management, and key risk indicators are executed consistently and effectively across the technology organization. Challenge risk identification activities related to significant technology changes, new products or capabilities, and cross-functional initiatives. Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed. Minimum Qualifications Education and/or experience typically obtained through completion of a Bachelor’s degree or equivalent. Typically has 12 years of experience or demonstrated portfolio consistent with experience required of the role in technology risk, information security, operational risk, or related disciplines within a regulated or otherwise complex operating environment. Strong understanding of risk management practices, control frameworks, and second-line oversight within a three lines of defense model. Demonstrated experience providing independent review, challenge, or governance of first-line technology, security, data, or operational risk activities. Strong ability to assess control design and effectiveness, synthesize risk data, identify themes, and translate technical issues into business risk. Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross-functional partners. Strong critical thinking, judgment, and problem-solving skills, with the ability to provide practical, risk-based recommendations in a complex environment. Ability to operate independently, manage competing priorities, and maintain effective working relationships while preserving second-line objectivity. Background and drug screen. Preferred Qualifications Advanced degree or additional related education and/or experience preferred. Experience in financial services, payments, fintech, or another highly regulated industry. Familiarity with relevant regulatory expectations and industry standards and frameworks applicable to technology and security risk management such as; ISO 27002, PCI DSS, NIST, FFIEC, and SOC 2. Experience supporting governance committees, audits, examinations, or regu
Location and market context
This role is based in Phoenix on-site. Local candidates benefit from being close to Early Warning's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About cybersecurity governance roles
Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Roles like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.
How to position yourself for this cybersecurity governance role
Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Early Warning would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Director of Data Governance and Operations · Intel · Phoenix, AZ
- Senior Analyst - Analytics & Reporting (Data Governance) · Western Alliance Bank · Phoenix, AZ
- Senior Model Risk Manager · Western Alliance Bank · Phoenix, AZ
- Enterprise Risk Management Senior Data Analyst · Western Alliance Bank · Phoenix, AZ
- Operations Supervisor - Risk & Compliance · Federal Reserve Bank of San Francisco · Phoenix, AZ
- Site Manager - EH&S Regulatory Compliance · Air Products · Phoenix, AZ
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.