Webster Bank
Director - Infrastructure IAM and Delivery Risk Lead
Webster Bank, Stamford, Connecticut, United States, 06925
Infrastructure and IAM Risk Director page is loaded Infrastructure and IAM Risk Director Apply locations CT Stamford HQ Remote-Connecticut time type Full time posted on Posted Today job requisition id R25_0000001230 If you’re looking for a meaningful career, you’ll find it here at Webster. Founded in 1935, our focus has always been to put people first--doing whatever we can to help individuals, families, businesses and our colleagues achieve their financial goals. As a leading commercial bank, we remain passionate about serving our clients and supporting our communities. Integrity, Collaboration, Accountability, Agility, Respect, Excellence are Webster’s values, these set us apart as a bank and as an employer.
Come join our team where you can expand your career potential, benefit from our robust development opportunities, and enjoy meaningful work!
The Director, Front Line Controls Officer will play a critical leadership role in overseeing and strengthening the bank’s technology and infrastructure control environment. This individual will report to the Managing Director Front Line Control Officer and serve as a primary risk partner to the bank’s
Infrastructure
leadership to ensure that technology risks are proactively identified, assessed, and mitigated across the enterprise. Areas of focus include Asset Management, Change Management,
and
Identity and Access Management (IAM)
. Key responsibilities include building and maintaining a comprehensive control inventory, enhancing the risk and control self-assessment (RCSA) program, and ensuring alignment with internal policies, regulatory requirements, and industry best practices. The role will also provide risk partnership for key technology processes, including
asset management
,
patch management, incident and problem management, capacity planning, network security, change management, end user computing, database management, and IAM . The ideal candidate will bring deep expertise in technology risk management
and
internal controls
within the banking sector that enable the candidate to serve as the "voice of risk" in strategic infrastructure initiatives and large-scale, high-visibility regulatory remediation programs. Key Responsibilities: Leadership & Strategy: Oversight and management for a Technology Front Line Unit (FLU) aligning with the vision and objectives set by the Chief Controls Officer and the IT First Line Controls Officer. Leverage agile principals to operate transparently. Controls Design & Inventory: Collaborate with the Technology Front Line Unit to design, implement, and maintain effective controls that mitigate identified risks across core infrastructure and IAM domains. Leverage technical expertise and industry knowledge to build and maintain a comprehensive control inventory, ensuring traceability to risks, regulatory requirements, and internal policies. Proactive Oversight: Drive the early identification of control issues, emerging risks, and process deficiencies. Lead root cause analysis and oversee the development and execution of robust, sustainable remediation plans to address control gaps and prevent recurrence. Analyze risk data to assess likelihood, impact, and trends, and provide actionable insights to senior leadership. Infrastructure and Availability: Evaluate the risk impact of incidents and problems on the control environment and recommend enhancements to prevent recurrence. Provide governance and oversight of patch management programs, ensuring timely remediation of vulnerabilities and alignment with risk appetite. RSCA Program Management: Lead the execution and documentation of RSCA processes across the respective Front Line Units (FLUs) to ensure it aligns with regulatory requirements and industry best practices. Assist with designing and enhancing the RCSA program, ensuring compliance with internal policies, industry best practices and regulatory requirements. Reporting & Communication: Develop and deliver executive-level reporting that highlight risk trends, control effectiveness, and areas requiring attention. Continuous Improvement: Evaluate and improve the overall risk and control environment to adapt to changes in the regulatory environment, business operations, and emerging risks. Audit & Regulatory Coordination: Support internal audits and regulatory examinations, ensuring all required documentation and evidence are accurate and readily available. Act as a liaison between the business and regulators, providing transparent and comprehensive updates on the risk management program. Compliance Assurance: Ensure adherence to applicable regulations and banking standards, partnering closely with Compliance, Internal Audit, and other control functions. Skills, Education and Experience Requirements: • Education: o High school diploma or GED required. o Bachelor’s degree in Technology, Risk Management, or a related field, preferred. o Advanced degree and/or risk certifications preferred (CISA, CISSP, CCSP, PMP, etc.) • Experience: o 7+ years of experience in risk management, operational risk, or internal audit within the banking or financial services industry. o Substantial experience in leading RCSA, internal audit, or similar assessment/testing programs. • Knowledge: o Deep understanding of banking regulations, risk management frameworks, internal control standards, internal audit methodology and QA best practices. o Strong familiarity with infrastructure management practices and systems. o Strong understanding of operational risk management techniques and control assessment methodologies. o In-depth knowledge of OCC Heightened Standards and Regulatory Category IV banking requirements preferred. o Deep understanding of technology risk frameworks for infrastructure, cloud, cybersecurity, and service management (e.g., NIST, ISO, FFIEC), CRI/CRI Profile, and risk rating methodologies. • Skills: o 7+ years of experience in technology risk, operational risk, information security, or audit in a regulated financial or technology-driven environment. o Experience with asset management, change management, database management, identity and access management, configuration management, network security, capacity management, problem and incident management. o Proven experience interfacing with regulators (e.g., OCC, FRB, SEC) and audit functions. o Exceptional written and verbal communication, influencing, and negotiation skills at senior executive levels. o Ability to translate complex technical risks into clear business language. o Strong judgment, discretion, and an ability to operate in fast-paced, ambiguous environments. o Strategic thinker with a practical orientation toward execution and results. The estimated salary range for this position is $140,000.00 to $175,000.00. Actual salary may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position is eligible for incentive compensation. #LI-Hybrid #LI-FO1 All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. Similar Jobs (4)
SDLC & Delivery Risk Director locations 2 Locations time type Full time posted on Posted Today Director - Consumer and Commercial Application Risk Lead locations 2 Locations time type Full time posted on Posted Today Director - Infrastructure Cloud Risk Lead locations 2 Locations time type Full time posted on Posted Yesterday Being passionate about making a difference in people's lives is what working at Webster is all about. Since our founding in 1935, we've maintained a values-guided culture. Whether it’s helping someone buy their first home or build a business, you’ll be part of a caring team that goes above and beyond for our customers, communities and each other. Introduce Yourself
Not finding the right fit? Let us know you're interested in a future opportunity by clicking
Get Started
below or
create an account
by clicking 'Sign In' at the top of the page to set up email alerts as new job postings become available that meet your interest!
#J-18808-Ljbffr
Infrastructure
leadership to ensure that technology risks are proactively identified, assessed, and mitigated across the enterprise. Areas of focus include Asset Management, Change Management,
and
Identity and Access Management (IAM)
. Key responsibilities include building and maintaining a comprehensive control inventory, enhancing the risk and control self-assessment (RCSA) program, and ensuring alignment with internal policies, regulatory requirements, and industry best practices. The role will also provide risk partnership for key technology processes, including
asset management
,
patch management, incident and problem management, capacity planning, network security, change management, end user computing, database management, and IAM . The ideal candidate will bring deep expertise in technology risk management
and
internal controls
within the banking sector that enable the candidate to serve as the "voice of risk" in strategic infrastructure initiatives and large-scale, high-visibility regulatory remediation programs. Key Responsibilities: Leadership & Strategy: Oversight and management for a Technology Front Line Unit (FLU) aligning with the vision and objectives set by the Chief Controls Officer and the IT First Line Controls Officer. Leverage agile principals to operate transparently. Controls Design & Inventory: Collaborate with the Technology Front Line Unit to design, implement, and maintain effective controls that mitigate identified risks across core infrastructure and IAM domains. Leverage technical expertise and industry knowledge to build and maintain a comprehensive control inventory, ensuring traceability to risks, regulatory requirements, and internal policies. Proactive Oversight: Drive the early identification of control issues, emerging risks, and process deficiencies. Lead root cause analysis and oversee the development and execution of robust, sustainable remediation plans to address control gaps and prevent recurrence. Analyze risk data to assess likelihood, impact, and trends, and provide actionable insights to senior leadership. Infrastructure and Availability: Evaluate the risk impact of incidents and problems on the control environment and recommend enhancements to prevent recurrence. Provide governance and oversight of patch management programs, ensuring timely remediation of vulnerabilities and alignment with risk appetite. RSCA Program Management: Lead the execution and documentation of RSCA processes across the respective Front Line Units (FLUs) to ensure it aligns with regulatory requirements and industry best practices. Assist with designing and enhancing the RCSA program, ensuring compliance with internal policies, industry best practices and regulatory requirements. Reporting & Communication: Develop and deliver executive-level reporting that highlight risk trends, control effectiveness, and areas requiring attention. Continuous Improvement: Evaluate and improve the overall risk and control environment to adapt to changes in the regulatory environment, business operations, and emerging risks. Audit & Regulatory Coordination: Support internal audits and regulatory examinations, ensuring all required documentation and evidence are accurate and readily available. Act as a liaison between the business and regulators, providing transparent and comprehensive updates on the risk management program. Compliance Assurance: Ensure adherence to applicable regulations and banking standards, partnering closely with Compliance, Internal Audit, and other control functions. Skills, Education and Experience Requirements: • Education: o High school diploma or GED required. o Bachelor’s degree in Technology, Risk Management, or a related field, preferred. o Advanced degree and/or risk certifications preferred (CISA, CISSP, CCSP, PMP, etc.) • Experience: o 7+ years of experience in risk management, operational risk, or internal audit within the banking or financial services industry. o Substantial experience in leading RCSA, internal audit, or similar assessment/testing programs. • Knowledge: o Deep understanding of banking regulations, risk management frameworks, internal control standards, internal audit methodology and QA best practices. o Strong familiarity with infrastructure management practices and systems. o Strong understanding of operational risk management techniques and control assessment methodologies. o In-depth knowledge of OCC Heightened Standards and Regulatory Category IV banking requirements preferred. o Deep understanding of technology risk frameworks for infrastructure, cloud, cybersecurity, and service management (e.g., NIST, ISO, FFIEC), CRI/CRI Profile, and risk rating methodologies. • Skills: o 7+ years of experience in technology risk, operational risk, information security, or audit in a regulated financial or technology-driven environment. o Experience with asset management, change management, database management, identity and access management, configuration management, network security, capacity management, problem and incident management. o Proven experience interfacing with regulators (e.g., OCC, FRB, SEC) and audit functions. o Exceptional written and verbal communication, influencing, and negotiation skills at senior executive levels. o Ability to translate complex technical risks into clear business language. o Strong judgment, discretion, and an ability to operate in fast-paced, ambiguous environments. o Strategic thinker with a practical orientation toward execution and results. The estimated salary range for this position is $140,000.00 to $175,000.00. Actual salary may vary up or down depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position is eligible for incentive compensation. #LI-Hybrid #LI-FO1 All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. Similar Jobs (4)
SDLC & Delivery Risk Director locations 2 Locations time type Full time posted on Posted Today Director - Consumer and Commercial Application Risk Lead locations 2 Locations time type Full time posted on Posted Today Director - Infrastructure Cloud Risk Lead locations 2 Locations time type Full time posted on Posted Yesterday Being passionate about making a difference in people's lives is what working at Webster is all about. Since our founding in 1935, we've maintained a values-guided culture. Whether it’s helping someone buy their first home or build a business, you’ll be part of a caring team that goes above and beyond for our customers, communities and each other. Introduce Yourself
Not finding the right fit? Let us know you're interested in a future opportunity by clicking
Get Started
below or
create an account
by clicking 'Sign In' at the top of the page to set up email alerts as new job postings become available that meet your interest!
#J-18808-Ljbffr