Wheeling, WV

Salary
—
Posted
Aug 17, 2026
Location
Wheeling, WV
Last confirmed open
Aug 20, 2026

What this job asks for AI summary

This role leads the enterprise IT Governance, Risk, and Compliance (GRC) program for a bank, owning the full lifecycle of technology risk management — from policy hierarchy and control frameworks to regulatory examination management and third-party risk oversight. The position requires deep familiarity with banking regulators (OCC, FDIC, Federal Reserve) and frameworks such as NIST CSF, CIS Controls, and FFIEC, and involves building and mentoring a team of GRC analysts while reporting risk themes to Board-level committees.

Senior level

Must have (9)
NIST CSFCIS ControlsFFIEC CATNIST AI RMF or ISO/IEC 42001SOC 2SOX ITGCServiceNow GRC or ArcherAWS, Azure or GCPMicrosoft Office
Nice to have (1)
SOC 1

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 20, 2026. It is a model, not a headcount.

Why we read it this way (7)

No work location is specified in the posting; CBSA and state fields are left blank. The quarterly travel requirement suggests this is not a fully remote role.

The role has explicit people-management duties (building, leading, and mentoring a GRC team; managing budget and staffing plans), which makes 11-3021 Computer and Information Systems Managers a plausible alternative SOC. However, the primary day-to-day work is security/risk analysis, examination management, and control assessment — squarely in the 15-1212 domain — so that code is preferred.

No minimum years of experience are stated anywhere in the posting.

Cloud platforms (AWS, Azure, GCP) appear under 'Other Requirements' as a working-knowledge expectation rather than a hard gate on a specific platform; they are captured as a single required skill with alternatives reflecting the 'or' framing in the posting.

SOC 1 appears only in the duties narrative (not in the requirements section) and is listed as preferred accordingly.

ISO/IEC 42001 is listed alongside NIST AI RMF as an alternative in the requirements section; it is also captured separately as a preferred skill given its secondary framing in the AI governance context.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-63B.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗