SonicJobs Logo
Left arrow iconBack to search

Director, Data Management Risk Oversight (Second Line)

Mizuho
Posted a day ago, valid for a month
Location

New York, NY, US

Salary

$165,000 - $220,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Americas Risk Department

The Americas Risk Department, as a second line-of-defense organization, provides common risk-management oversight and services to businesses and legal entities across Mizuho U.S. Operations (MUSO). Effective risk management depends on independent judgment, clear ownership, and consistent execution. The Non-Financial Risk (NFR) team provides independent oversight of material non-financial risks, including Data Management risk.

Position: Director, Data Management Risk Oversight (Second Line)

The Director, Data Management Risk Oversight is the NFR team's senior subject-matter expert for independent oversight of the firm's Data Management program. The role requires deep Data Management knowledge and the judgment and execution discipline to convert that expertise into effective second-line review, challenge, monitoring and escalation.

The position reports to an Executive Director, and member of the firm’s Non-Financial Risk Management Leadership Team. It is an individual-contributor role at hire and may assume direct-report responsibilities as the function develops.

The mandate will be executed through a risk-prioritized and phased Data Management oversight plan. During the initial individual-contributor stage, the Director will focus on the highest-risk Data Management themes and material changes, sequence reviews and monitoring based on risk, regulatory priority and available capacity, and rely on first-line owners and specialist functions for program execution, technical testing, validation and formal determinations within their mandates.

The Director is accountable for executing the full second-line oversight cycle. The work begins with risk-based scoping and structured first-line engagement, and continues through evidence review, documented challenge, assessment of the first line's response, and a documented second-line conclusion or escalation. The first line remains responsible for its programs, controls and remediation. The Director is accountable for completed oversight conclusions, a traceable record of challenge, and monitoring through documented second-line disposition, governance-approved risk acceptance, assessment of closure evidence, or escalation.

The Data Management scope covers governance and accountability; data ownership and stewardship; data quality; lineage and metadata; critical data and authoritative sources; data lifecycle, transformations and reconciliations; data architecture and controls; issue management; and data supporting material regulatory and management reporting. Regulatory Reporting experience supports this scope because the role must assess how Data Management weaknesses can affect reporting accuracy, completeness and timeliness.

As part of the Data Management mandate, the Director will also assess material data risks arising from AI and other emerging technologies. This includes the sourcing, permitted use, quality, lineage, provenance, classification, access, retention and traceability of data used by AI-enabled processes. The Director will coordinate with AI Governance, Model Risk, Legal, Compliance, Information Security, Privacy and other specialist functions and will not replace their responsibilities.

Responsibilities:

Independent Oversight and Credible Challenge

  • Build and execute a risk-based Data Management oversight plan aligned with the NFR framework, the firm's risk profile, regulatory priorities, material program changes and approved capacity. Establish priorities and review cadence with the Executive Director and revisit them when risk, dependencies or capacity change.

  • Lead independent reviews, deep dives, and thematic reviews from scoping through conclusion. Obtain and assess evidence, identify control or governance gaps, document supported observations and challenges, and communicate the risk consequence.

  • Participate at agreed points in first-line and third-party reviews when that is an efficient way to obtain oversight evidence. Consider relevant Internal Audit and regulatory observations, assess their implications for the Data Management risk profile and management response, and perform additional second-line work when warranted.

  • Review and challenge, on a risk-prioritized basis, Data Management policies, standards, procedures, governance structures, risk and control self-assessments, process maps, issues, risk acceptances, and remediation plans.

  • Determine whether first-line responses and remediation actions address the underlying risk and root cause. Monitor open matters and assess closure evidence as required by the applicable issue-management framework; escalate when the response, evidence, pace, or residual risk is not acceptable.

  • Assess material Data Management incidents, control failures, emerging risks, and program changes for systemic implications across businesses, legal entities, and reporting processes.

Data Management Risks Related to AI and Emerging Technology

  • Assess, through the risk-based Data Management oversight plan, whether material AI uses comply with applicable requirements for data sourcing, permitted use, quality, lineage, provenance, classification, access, retention and traceability.

  • Evaluate whether material AI-related data risks are appropriately identified, governed, monitored and reflected in the Data Management risk profile, issues and reporting.

  • Coordinate with AI Governance, Model Risk and other relevant specialist functions, using their reviews and determinations as inputs without duplicating their responsibilities.

Continuous Monitoring and Risk Indicators

  • Establish and maintain a phased, risk-based monitoring program for Data Management using reliable key risk indicators, risk-appetite measures, issues, incidents, control results, and relevant Internal Audit and regulatory findings.

  • Review and challenge Data Management metrics used in board, risk-committee, and Non-Financial Risk Committee (NFRC) reporting, including definitions, data sources, ownership, thresholds, escalation triggers, trend interpretation, and the connection to risk appetite. Develop second-line indicators where needed to support independent monitoring.

  • Where AI or another emerging technology creates material Data Management risk, assess whether that risk is reflected in relevant indicators, issues, escalation and risk reporting.

  • Use monitoring results to identify where deeper review is warranted, explain changes in the risk profile, and recommend proportionate action.

  • Maintain a traceable record of reviews performed, challenges raised, first-line responses, second-line conclusions, follow-up, and escalation.

Governance and Senior Reporting

  • Represent NFR in Data Management forums, committees, working groups and material change initiatives and, where relevant, in AI or emerging-technology governance discussions involving material Data Management risk.

  • Provide a clear, independent view of the Data Management risk profile, including material data risks arising from AI or emerging technology, and challenge decisions or representations that are not supported by evidence.

  • Prepare concise reporting for senior management and risk committees that explains the risk, supporting evidence, management response, residual exposure, and required decision or action.

  • Support regulatory examinations, Internal Audit activity, and management responses within the role's second-line mandate.

Relationship Leadership and Execution

  • Build credible working relationships with first-line Data Management, Regulatory Reporting, Finance, Technology, business and control-function leaders while maintaining independence of judgment. Engage AI Governance, AI-use owners and emerging-technology teams when material Data Management risk warrants.

  • Translate broad priorities into executable reviews and monitoring activities with clear objectives, milestones, evidence needs, and conclusions.

  • Plan and deliver the priority reviews and monitoring activities established in the oversight plan, identify dependencies early, and promptly escalate constraints that threaten required risk coverage, quality, or timing.

  • Coordinate with other NFR teams and relevant specialist functions to provide a coherent second-line view without duplicating ownership. Provide information to Internal Audit without treating its work as a substitute for second-line oversight.

  • Provide technical guidance where useful, while remaining accountable for the second-line assessment and oversight outcome.

  • If direct reports are added, set clear priorities, coach staff, review work quality, and maintain accountability for the team's delivery.

Director-Level Performance Expectations:

  • Produces completed, evidence-based oversight work that reaches a clear second-line conclusion.

  • Exercises skeptical and independent judgment while remaining constructive and fact-based.

  • Balances commercial outcomes for the firm with robust, pragmatic risk oversight and independence

  • Converts Data Management knowledge into specific review questions, challenge, risk implications and follow-up actions, including for material data risks arising from AI or emerging technology where applicable.

  • Assesses the quality of the first line's response and carries each material challenge through documented disposition, governance-approved risk acceptance, assessment of closure evidence under the applicable issue-management framework, or escalation.

  • Maintains sufficient documentation for management, Internal Audit, or a regulator to understand what was reviewed, what was challenged, how the response was assessed, and how the matter was resolved.

  • Delivers agreed work across multiple priorities and maintains clear ownership of milestones, conclusions, follow-up, and escalation.

Expected First-Year Outcomes:

  • A documented, risk-based and phased Data Management oversight plan is operating. First-year priorities and sequencing are agreed with the Executive Director, committed work is completed, and material changes in scope or timing are documented and escalated.

  • Independent reviews and targeted deep dives produce supported conclusions, documented challenge, agreed follow-up, and escalation where needed.

  • Material data risks arising from AI and emerging technologies are incorporated into the Data Management oversight plan where warranted by risk and available capacity.

  • Data Management indicators have been independently assessed against material risks and risk appetite, with coverage or data-quality gaps documented, challenged, and tracked to agreed resolution.

  • Risk-prioritized policies, standards, procedures, and material program changes receive timely, documented second-line review and challenge.

  • Senior management receives a clear view of the Data Management risk profile, material gaps, management response, residual risk, and decisions required.

Qualifications:

  • Bachelor's degree in Data Management, Information Systems, Risk Management, Computer Science, Accounting, Finance, or a related discipline, or an equivalent combination of relevant education and experience; an advanced degree is preferred.

  • At least 10 years of relevant experience in financial services or another highly regulated environment, including significant financial-services Data Management or Data Governance responsibility and a demonstrated record of leading independent reviews in second-line risk, Internal Audit, compliance testing, or another assurance function from scope through evidence review, challenge, conclusion and follow-up.

  • Strong working knowledge of enterprise Data Management frameworks and controls, including governance and accountability, data quality, lineage, metadata, critical data elements, and issue remediation.

  • Experience with AI governance, emerging-technology risk, or Data Management controls supporting AI is preferred but not required.

  • Understanding of BCBS 239 and U.S. supervisory expectations for data aggregation, governance, and reporting. Experience with the data supporting material regulatory reports, including FR 2052a or other U.S. regulatory submissions, is preferred.

  • Demonstrated ability to challenge senior first-line stakeholders, influence outcomes, and maintain productive working relationships without compromising independence.

  • Strong risk judgment and the ability to distinguish a technical observation from a material control, governance, or reporting risk.

  • Clear, economical written and verbal communication, including senior-management and committee reporting.

  • Strong project and execution management skills, including the ability to manage ambiguity, changing priorities, dependencies, and escalation.

  • Ability to lead through influence is required; prior experience supervising staff or leading review teams is preferred.

  • CDMP or other DAMA credentials, and audit, risk, technology, accounting, AI governance, or comparable professional credentials are preferred but not required

The expected base salary ranges from $165,000 - $220,000. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, including Medical, Dental and 401K plans, successful candidates are also eligible to receive a discretionary bonus.

#LI-Hybrid

Other requirements

Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process.   

Company Overview

Mizuho Financial Group, Inc. is the 15th largest bank in the world as measured by total assets of ~$2 trillion. Mizuho's 60,000 employees worldwide offer comprehensive financial services to clients in 35 countries and 800 offices throughout the Americas, EMEA and Asia. Mizuho Americas is a leading provider of corporate and investment banking services to clients in the US, Canada, and Latin America. Through its acquisition of Greenhill​, Mizuho provides M&A, restructuring and private capital advisory capabilities across Americas, Europe and Asia. Mizuho Americas employs approximately 3,500 professionals, and its capabilities span corporate and investment banking, capital markets, equity and fixed income sales & trading, derivatives, FX, custody and research. Visit www.mizuhoamericas.com.​​

Mizuho Americas offers a competitive total rewards package.

We are an EEO/AA Employer - M/F/Disability/Veteran.

We participate in the E-Verify program.

We maintain a drug-free workplace and reserve the right to require pre- and post-hire drug testing as permitted by applicable law.

#LI-MIZUHO




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.