The Application Risk Domain Officer operates within Technology Risk Management (TRM), part of Corporate Risk, providing independent second‑line oversight across application domains. The role is part of the Information Security and Application Risk Domain Team, which performs domain‑level evaluation and produces evidence‑based views of how application conditions contribute to enterprise risk exposure. The role engages with Technology, including Tech Operations, CIO organizations, to provide challenge and inform risk‑based decisions. Outputs from this role support enterprise risk views provided to senior management, risk committees, and regulators. The Application Risk Domain Officer (P5) serves as the senior second line oversight lead across assigned domains and is a deeply technical individual contributor who provides expert second-line risk oversight across modern software engineering environments and has responsibility across the application risk domain. This role requires hands-on understanding of secure SDLC, CI/CD, infrastructure as code, cloud-native platforms, developer tooling, software supply chain controls, and AI-enabled engineering workflows. The role is responsible for setting direction for domain-level risk assessment and monitoring approaches, identifying and assessing plausible failure modes, and evaluating how those failures contribute to enterprise technology risk exposure. An individual in this role must be able to engage engineering teams with technical credibility, serve as a thought leader, and partner closely with first-line engineering and technology teams to de-construct complex delivery patterns into concrete risk and control considerations and translate technical observations into clear, decision-ready risk insight for senior stakeholders.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed