Director Technology Risk positions focus on delivering results in their domain. This page aggregates open Director Technology Risk roles and what employers typically expect.
**About Our Company** We’re a diversified financial services leader with more than $1.5 trillion in assets under management, administration and advisement as of year-end 2024. Our team of 22,000 people across 19 countries, serves more than 3.5 million individual, small business and institutional clients. We are a longstanding leader in financial planning and advice, a global asset manager and an insurer. Our unwavering focus on our clients and strong financial foundation connects each of our unique businesses – Ameriprise Financial, Columbia Threadneedle Investments and RiverSource Insurance and Annuities. Here, we foster meaningful careers, invest in the future, and make a difference for clients, institutions and communities around the world. **Job Description** Ameriprise Financial is looking to add a Director, Technology Risk to the team! The Director, Technology Risk is a leadership role within the Second Line of Defense (2LOD), reporting to the VP, Technology Risk Office. This role is responsible for executing independent oversight of Technology and Cyber / Information Security activities to ensure alignment with enterprise risk management standards while providing effective review, credible challenge, and risk transparency. This role will actively engage with IT stakeholders and senior leadership to foster a robust risk culture. This includes regular interaction and collaboration at various organizational levels. **Key Responsibilities:** - Lead risk oversight activities to ensure effective identification, assessment, and management of risks across the business. Execute risk oversight activities, including monitoring, review, and credible challenge of business processes to ensure alignment with enterprise risk standards and governance expectations. Support effective risk governance through adherence to policies, frameworks, and escalation protocols. - Lead the implementation of the Operational Risk Management (ORM) methodology and requirements across assigned business unit, in agreement with the overall ORM framework - Execute and support Risk and Control Self-Assessments (RCSAs), ensuring consistent application of the risk framework, accurate documentation of risks and controls, and adherence to enterprise standards. Contribute to continuous improvement of RCSA processes, tools, and methodologies. - Provide subject matter expertise and advise on IT related risks and remediation/mitigation of risk exposures. - Review and manage risk events (REVs), ensuring timely identification, documentation, escalation, and resolution. Provide effective challenge on root cause analysis and remediation plans and monitor trends to support proactive risk management. - Support Risk Oversight Committee (ROC) governance by preparing materials, coordinating inputs, and tracking actions and decisions. Ensure timely and accurate reporting of key risk issues and follow-up on committee outcomes. - Develop and deliver risk reporting, dashboards, and analytics to support monitoring and decision-making. - Ensure data quality, consistency, and accuracy, and provide insights into emerging risks, trends, and control effectiveness. - Enhance risk reporting with new ideas gathered from research, best practices, and knowledge. - Support team delivery and effectiveness by providing guidance, coordination, leadership. - Contribute to a collaborative team environment and support broader leadership priorities and initiatives. - Provide leadership, performance management and improvement feedback, coaching, mentoring and development of employee direct reports. **Required Qualifications:** - Bachelor's degree or equivalent - 7-10 years of relevant experience - In depth knowledge of IT technical and operational processes, and associated risks and controls, IT risk management with a strong emphasis on AI risk management. - Technical knowledge of risk management frameworks, applicable standards, and regulatory requirements including, NIST, COBIT, FFIEC, ISO27000,…