LoD2: Technology Risk Senior Specialist

Truist BankCharlotte, NC
Onsite

About The Position

Key contributor to the Truist second-line-of-defense (LoD2) Technology Risk team responsible for independent risk oversight of one or more Technology Risk Framework domains and/or Business Unit Technology areas. Partner with Enterprise Technology teammates and stakeholders in assigned oversight areas, advise on risk-related topics, effectively challenge through risk programs, and independently evaluate technology risk in the Truist environment. For this opportunity, Truist will not sponsor an applicant for work visa status or employment authorization, nor will we offer any immigration-related support for this position. This includes, but is not limited to: H-1B, F-1 OPT F-1 STEM OPT F-1 CPT J-1 TN-1 TN-2 E-3 O-1 Future sponsorship for U.S. lawful permanent residence status. Candidate must be located in or willing to self-relocate to one of the following locations: Charlotte, NC, Raleigh, NC, Richmond, VA, or Atlanta, GA. Truist 'in office' requirement is 5 days per week. No full remote or relocation assistance available at this time.

Requirements

  • Bachelor's Degree or an equivalent combination of education and experience.
  • 10+ years of banking, technology, operations or risk management experience.
  • Strong business acumen / knowledge, management experience, problem solving, critical thinking, influencing and decision-making skills.
  • Experience operating independently and navigating ambiguity to deliver value.
  • Excellent interpersonal and communication skills demonstrating the ability to establish credibility with all levels of management effectively.
  • Demonstrated ability to organize and manage complex initiatives and deliver high-quality, executive level work products.
  • Comfort with data and applying analysis to derive value-add insights.
  • Adept with Microsoft Office products.

Nice To Haves

  • Strong expertise in cloud platforms, platform native services, and third-party services, including implementation maturity, gap analysis, risk identification and remediation, control design, and ongoing monitoring.
  • Hands-on cloud architecture or engineering experience enabling effective oversight of cloud environments, CI/CD pipelines, standardized deployment patterns, and automated controls.
  • Ability to evaluate control effectiveness and capability maturity across key cloud operational risk domains.
  • Demonstrated ability to interpret and apply relevant Cloud Security Alliance (CSA), FFIEC, and NIST guidance when reviewing cloud policies, standards, controls, and risk decisions, including evaluating requirement alignment, traceability, and supporting evidence.
  • Experience in assessing whether cloud controls are implemented consistently across AWS, Azure, SaaS, containers, CI/CD pipelines, and infrastructure-as-code environments, including validation of control mapping, coverage, exceptions, and supporting evidence.
  • Experience supporting enterprise cloud transformation initiatives (e.g., migration from on‑prem to cloud), ensuring risks are identified, managed, and aligned with the firm’s risk appetite and regulatory expectations.
  • Solid understanding of Secure SDLC and change management practices in a financial services context, including how controls are embedded across development, testing, deployment, and release cycles.
  • Experience operating in a second line of defense role within a regulated financial services environment, providing independent risk oversight, effective challenge, and credible advisory support to technology and engineering teams.
  • Strong communication and influencing skills, with the ability to translate complex technical risks into clear, actionable insights for senior management, risk committees, auditors, and regulators.
  • Relevant certifications preferred, such as: AWS Certified Solutions Architect, AWS Certified CloudOps Engineer, Cloud+, CRISC, CGEIT, CISA, CGRC, or similar technology risk credentials

Responsibilities

  • Provide independent risk oversight (i.e. LOD2) for Truist Technology and related consult to Truist Business Units through the effective identification, mitigation, monitoring and reporting of technology risk and other related risks (e.g., operational, compliance) within Enterprise Technology.
  • Serve as a subject matter expert and steward of the Technology Risk Framework to identify, report and mitigate technology risks.
  • Execute independent assessment and oversight of the maturity of technology and adequacy of technology controls to achieve business outcomes for performance, stability, security and service availability.
  • Strengthen and sustain proactive risk culture through conducting effective risk focused management and partnership routines with technology teams and internal partners. Interface with senior leaders and key partners across the organization.
  • Review and challenge outcomes of first-line-of-defense risk program execution.
  • Monitor legal, regulatory, compliance and audit matters for assigned Enterprise Technology oversight area(s) and ensures timely action.
  • Lead complex projects that have broad technology and enterprise level impact with implications and/or resource requirements beyond risk management. Provide informal leadership to others and serves as a resource on complex solutions.
  • Comfortable in interdisciplinary, matrix environments. Use acumen and skills to effectively bridge business and IT functions seamlessly. Pivot quickly between advisory consultant and implementation consultant roles.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • disability
  • accidental death and dismemberment
  • tax-preferred savings accounts
  • 401k plan
  • vacation
  • sick days
  • paid holidays
  • defined benefit pension plan
  • restricted stock units
  • deferred compensation plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service