Summary
Responsible for the analytical and documentation-intensive work of the enterprise risk function — developing and operationalizing key risk indicators (KRIs) and key performance indicators (KPIs), supporting Risk Oversight Committee (ROC) and Board reporting, and building the foundation for the Risk & Control Self-Assessment (RCSA) program. Reporting to the Manager, Enterprise Risk, this role turns risk data into clear, decision-ready reporting and helps establish the repeatable analytical infrastructure the function needs as the organization scales.
The role gathers and analyzes risk data from across the Risk Office and business units, maintains reporting and dashboards against the board-approved risk appetite, and supports the documentation and methodology work that underpins enterprise risk management. It coordinates with Compliance, Fraud, Finance, and business partners to source data and validate results. As a second-line risk function, the role provides enterprise-wide risk governance and reporting distinct from business-line risk ownership.
Operating with general guidance within established policy and methodology, the Enterprise Risk Specialist produces analysis and draft reporting for review, applies practical judgment in day-to-day work, and escalates questions outside precedent to the Manager, Enterprise Risk.
Essential Functions:
KRI / KPI Development & Reporting
- Develops, monitors, and reports on Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) across enterprise risk programs, aligning metrics with risk appetite and regulatory expectations.
- Establishes and documents thresholds, tolerance bands, and escalation triggers for each indicator, in coordination with the Manager.
- Identifies data sources and builds repeatable — ideally automated — data collection and calculation methods, monitoring data quality.
- Designs dashboards and reporting views presenting KRIs/KPIs against appetite for management and the ROC, with trend analysis and commentary.
- Operationalizes KRI monitoring into a regular reporting cadence and recalibrates indicators and thresholds periodically as the risk profile evolves.
ROC / Board Reporting Support
- Supports maintenance of the Risk Appetite Statement and prepares supporting analysis for the annual review-and-approval cycle.
- Produces the quarterly Risk Dashboard and supporting materials reporting risk levels and trends against appetite, with tolerance/warning status.
- Assists in preparing Risk Oversight Committee materials — reporting packages, supporting analysis, and consolidated risk reporting drawn from across the Risk Office.
- Performs risk exposure and trend analysis, drafting observations on out-of-tolerance levels and emerging risks for the Manager’s review.
RCSA Foundation & Enterprise Risk Support
- Supports build-out of the RCSA program — methodology, risk-and-control taxonomy, templates, and residual-risk approach — in coordination with the Lead and Manager.
- Assists in running the RCSA pilot with one or two business units, capturing risks, controls, and issues into a register integrated with issue tracking.
- Maintains risk registers, the risk library, documentation, and analytical records supporting the enterprise risk management framework (e.g., COSO ERM).
- Supports regulatory examinations (e.g., NCUA) and audits by preparing data, documentation, and draft analysis.
Model Risk Oversight
- Supports administration of the model risk management program, maintaining a model inventory and monitoring model risk exposure in coordination with the Manager.
- Assists in coordinating model validation, tiering, and periodic review activities across model owners, escalating gaps to the Manager.
Program Support
- Supports risk acceptance and issue management programs, tracking documentation, deadlines, and follow-up actions, and flagging exceptions to the Manager.
- Assists with third-party/vendor risk management activities, including vendor due diligence review and monitoring, with guidance from the Manager.
- Supports business continuity, disaster recovery, and incident response planning activities in coordination with the Resilience Analyst/Specialist.
- Assists with regulatory examinations (e.g., NCUA), audits, and similar inquiries by preparing documentation and supporting management responses.
- Identifies opportunities to improve processes across enterprise risk programs and recommends refinements to the Manager.
- Performs other duties and responsibilities as assigned in support of departmental and organizational objectives.
Qualifications
Experience
- Minimum of 2 to 4 years of experience in risk management, data analysis, compliance, audit, or a related analytical function, preferably within a financial institution.
- Demonstrated experience producing analytical reporting, dashboards, or metrics for management audiences preferred.
Education
- Bachelor’s degree in business administration, finance, data analytics, risk management, or a related field, or equivalent experience.
- Relevant certification (e.g., CERP or similar) a plus.
Knowledge
- Working knowledge of enterprise risk management concepts, including risk appetite, KRIs/KRMs, risk assessments, and risk reporting.
- Familiarity with COSO ERM or similar frameworks and, ideally, RCSA methodology and residual-risk concepts.
- Understanding of credit union / financial institution risk data and NCUA expectations relevant to risk reporting.
- Strong data and analytical tool skills — advanced Microsoft Excel; familiarity with dashboarding, data visualization, or risk platforms (e.g., Tandem) a plus.
Skills/Abilities
- Strong analytical and critical-thinking skills; able to synthesize data from multiple sources into clear, decision-ready reporting.
- Strong attention to detail and data-quality discipline; produces accurate, well-documented analysis.
- Clear written and verbal communication; able to present technical and quantitative material to non-technical audiences.
- Strong documentation skills for methodology, procedures, and program materials.
- Applies practical judgment within established methodology; escalates questions outside precedent to the Manager, Enterprise Risk.
- Collaborative team contributor; coordinates with Compliance, Fraud, Finance, and business units to source and validate data.
- Organized self-starter able to manage multiple priorities and meet reporting deadlines with limited direction.
Physical Requirements/Work Environment
- Primarily office-based work with frequent use of computers, phones, and other standard office equipment.
- Ability to sit, stand, and work at a desk for extended periods throughout the workday.
- Occasional lifting or moving of light materials (up to 15–20 pounds), such as files or office supplies.
- May require participation in meetings, training sessions, or site visits within the organization.
- Work environment includes deadlines, audits, or regulatory review periods requiring focused attention and multitasking.
- Ability to communicate clearly in person, by phone, and electronically with internal stakeholders and external partners.