> Markdown version of [/jobs/ext/1772718-americas-technology-and-data-risk-leader](https://www.wearedevelopers.com/jobs/ext/1772718-americas-technology-and-data-risk-leader). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Americas Technology and Data Risk Leader - **Company:** Ernst & Young LLP - **Location:** Montgomery, AL, United States - **Experience:** Expert - **Salary:** $152,700.0 - $294,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Data Governance, Information Technology - **Published:** July 16, 2026 - **Apply:** https://dejobs.org/x/x/C6502687A8EE464783A9B9548C0A5EEA/job/ ## About the Role * Insight into the business advantages of good risk management and internal controls beyond compliance purposes. * Proven ability to manage multiple projects and meet deadlines in a fast-paced and changing environment. * Skilled in executive-level presentations and briefings. * Demonstrated leadership, negotiation and collaboration skills, with the ability to influence both upward and downward across the organization. * Strategic mindset and the ability to connect technical risk, business priorities and control outcomes in a way that drives action. To qualify for the role you must have * A minimum of 15 years' experience in Technology Risk Management and/or a similar field within Information Security. * An advanced degree in Computer Science, Information Security or a related discipline, or equivalent work experience. * Proficiency in policy and control frameworks such as ISO and COBIT. * Strong English language skills, including excellent writing, presentation, interpersonal and communication capabilities. * A minimum of 10 years of experience managing senior or managerial staff in Governance, Risk and Compliance (GRC) or related areas. Ideally, you'll also have * One or more of the following or equivalent certifications: CRISC, CISSP, CISM, CISA, CIA, GIAC in a related area, CIPP, or CIPT. * A strong understanding of external risk trends and business standards, and a commitment to staying current on methodologies and external developments that EY should prepare for from a risk perspective. * A strong understanding of EY business and Service Line risk priorities. What we look for We seek an individual with a strategic mindset and expertise in technology risk management who can proactively identify, assess and mitigate risks while strengthening the organization's resilience against an evolving threat landscape. The ideal candidate will bring strong leadership skills, the ability to collaborate across departments and geographies, and a clear commitment to maintaining compliance with industry standards and regulatory requirements. ## Description * Lead a strategic approach to identifying, evaluating and mitigating technology risks across the Americas area. * Serve as the steward of the organization's technology risk posture across the area and ensure the most significant risks receive appropriate sponsorship, budget and support for effective remediation. * Lead the consistent implementation of people, process and technical controls designed to prevent data exfiltration across regions, service lines and business environments. * Validate that implementations adhere to global standards and policies while accommodating local regulatory and operational requirements. Risk assessments, methodology and remediation strategy * Oversee the delivery of TARP service offerings and coordinate comprehensive risk assessments using TARP methodology. * Drive the identification, assessment and prioritization of technology and data risks, and develop risk management and mitigation strategies tailored to area needs. * Facilitate the smooth implementation of Information Security programs that involve Area, Regional and Member Firm Risk Management stakeholders. * Collaborate with business and technology stakeholders to understand technology dependencies, relevant threat scenarios and control gaps, and convert those insights into actionable remediation plans. Stakeholder advisory, escalation and communication * Act as the primary liaison between Information Security and business stakeholders at all levels of the firm, explaining the purpose, design and benefits of technology risk and control initiatives in clear, business-friendly language. * Become the trusted advisor on technology risk topics for Area, Regional and Member Firm Risk Management leaders, Business Relationship Managers, IT leaders and other senior stakeholders. * Serve as the primary escalation point for technology risks and implementation challenges, coordinating with regional and global teams to resolve issues and maintain program alignment. * Use strong executive presentation and briefing skills to communicate strategy, progress, risk posture and required decisions to senior management, the program steer co and the Information Security Leadership Team. Control enablement, education and continuous improvement * Drive stakeholder engagement through education, communication and collaboration to foster a culture of compliance, proactive risk management and adoption of controls. * Lead educational initiatives on technology risks, control expectations and external risk trends relevant to the Americas area. * Monitor progress and regularly report on risk status, mitigation efforts and program performance to senior leaders and governance forums. * Stay informed on emerging threats, technologies, methodologies, regulatory changes and business standards in order to continuously refine strategies, processes and policies. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [How Many Jobs Are Available in Technology?](https://www.wearedevelopers.com/magazine/450-how-many-jobs-are-available-in-technology) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)