Description
The Director, Internal Audit - Operational Risk is responsible for leading a portfolio of risk-based assurance and advisory activities focused on operational risk management, governance, and organizational resilience. This role serves as an Engagement Owner and trusted advisor to executive leadership by providing independent assessments of governance, risk management, and control effectiveness across key operational risk domains.
The Director oversees audit planning, execution, reporting, issue validation, and regulatory engagement activities while ensuring adherence to Internal Audit standards and methodologies. This role plays a key leadership role in evaluating the effectiveness of operational risk frameworks, identifying emerging risks, and providing insights that strengthen the organization's overall control environment.
Here’s what you can expect from the job and what you need to be successful:
What You’ll Do:
-
Lead a portfolio of risk-based operational risk audit and advisory engagements, ensuring timely execution, consistent methodology application, and high-quality deliverables.
-
Oversee audit planning, risk assessments, scoping decisions, testing strategies, audit conclusions, and reporting activities across assigned operational risk areas.
-
Review and approve audit findings, issue severity ratings, remediation plans, and issue validation activities.
-
Contribute to development and execution of the annual audit plan through participation in audit universe maintenance, risk assessments, and audit coverage planning.
-
Provide independent assessments of governance, risk management, and internal controls related to:
-
Enterprise Risk Management (ERM)
-
Operational Risk Management
-
Third-Party Risk Management (TPRM)
-
Business Continuity and Disaster Recovery (BC/DR)
-
Operational Resilience
-
Model Risk Management (MRM)
-
Enterprise Issue Management
-
Governance Committees and Risk Reporting
-
Change and Transformation Risk
-
Incident and Event Management
-
Evaluate the effectiveness of first- and second-line operational risk programs, governance structures, and oversight functions.
-
Assess enterprise risk frameworks, risk appetite programs, risk assessments, key risk indicators (KRIs), issue management processes, and risk reporting practices.
-
Review control environments supporting significant business transformations, strategic initiatives, technology implementations, and operational change programs.
-
Identify control weaknesses, emerging risks, resilience concerns, and opportunities to strengthen governance and operational effectiveness.
-
Develop and maintain strong relationships with executive leadership, enterprise risk leaders, compliance leaders, and business stakeholders while preserving audit independence.
-
Represent Internal Audit in governance committees, steering committees, and working groups as appropriate.
-
Lead interactions with regulators, external auditors, and other stakeholders regarding operational risk and governance audit activities.
-
Monitor regulatory developments, industry trends, and emerging risk themes to ensure appropriate audit coverage and risk perspectives.
-
Validate corrective action plans and monitor remediation activities to ensure sustainable resolution of identified issues.
-
Drive continuous improvement of audit methodologies, testing approaches, reporting capabilities, and quality standards.
-
Develop and mentor audit professionals through coaching, performance management, capability development, and succession planning.
Essential Skills:
- Required Experience: 8+ years of internal audit standards, methodologies, and professional practices.
- 4+ years of experience leading a diverse team including hiring, coaching and performance management.
-
Experience evaluating:
-
Enterprise Risk Management frameworks
-
Operational Risk Management programs
-
Third-Party Risk Management programs
-
Business Continuity and Disaster Recovery programs
-
Operational Resilience frameworks
-
Model Risk Management programs
-
Enterprise governance and oversight structures
-
Change management and transformation risk
-
Knowledge of risk appetite frameworks, issue management programs, risk assessments, operational loss management, and KRI reporting.
-
Experience assessing control effectiveness, identifying root causes, and validating remediation activities.
-
Strong understanding of financial services regulatory expectations and risk management practices.
-
Ability to provide independent challenge while maintaining effective stakeholder relationships.
-
Experience developing executive-level reporting and presenting findings to executive leadership, governance committees, and Board committees.
-
Strong analytical, organizational, and problem-solving skills.
-
Excellent written and verbal communication skills.
-
Certifications: CIA, CRMA, CRISC, CISA, FRM, CRCM or PMP Preferred
Location: Hillsboro Corporate Office | Hillsboro OR 97124 OR Marlborough Corporate Office | Marlborough, MA OR Chelmsford Corporate Office | Chelmsford, MA
Target Compensation: $164,000 - $197,000 base pay + Annual Bonus
#LI-MG1 #HYBRID
Who We Are:
What makes First Tech different? Click here to learn more!
Every great journey begins with a bold idea—and ours is no different. First Tech and DCU were founded on the belief that financial solutions should put people first. That belief has fueled decades of innovation and service, rooted in the tech sector and expanding to support members from all walks of life.
Employees are eligible for:
- Traditional medical, dental, and vision coverage
- Generous 401(k) match
- Paid Time Off: You'll accrue up to 15 days in your first year. In addition, you'll receive 40 hours of sick time and 3 personal days, which refresh annually
- Paid federal holidays
- Special employee pricing on lending products such as mortgage, auto, and personal loans (eligibility subject to standard account requirements and underwriting criteria)
Employment Statements:
First Tech is an equal opportunity employer, and we value diversity, inclusion, and equity at our company. We evaluate qualified applicants without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.
If you're applying for a job and need a reasonable accommodation for any part of the employment process, please send an email to [email protected] and let us know the nature of your request and contact information. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address.
First Tech is not currently offering Visa transfer/sponsorship for this position.