VP, Head of Enterprise Risk Management (ERM)

<span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Where it all began…</b><br>In 1951 SF Fire Credit Union first opened its doors from a modest 10′ × 15′ office space in 17 Engine. It was from those humble beginnings—where everyone pitched in to help one another in their community—that the organization forged its way of business forever. Today, the San Francisco-based credit union has grown to $1.7B in assets and a membership that extends from the regional firefighters we trace our roots back to throughout our many neighbors in San Francisco, San Mateo and Marin Counties. Our members benefit from the ideas and principles that have shaped us: Shared trust, continuous innovation of products and services, competitive rates, and excellent member service. These qualities foster a true sense of member-ownership and strengthen the credit union’s bond with the people for whom this credit union was created.<br><b>What we stand for…</b><br>There are a few things we look for those we hire at SF Fire Credit Union, regardless of role or team.<br>First, do they align with our values?<br>Be Personal – Walk the Member/Employee Path<br>Be a Leader – Empower, Collaborate, Own<br>Be Outside the Box – Innovate, Educate, Engage<br>Be Real – Integrity and Transparency Matter<br>Be the Connection – Serve our Community<br>Second, will they thrive in a culture like ours, where we default to trust, embrace feedback, and desire to innovate? Finally, do they share our vision to help empower members to accomplish their dreams and build lasting financial security in whatever way is most relevant to their role?<br><b>What it feels like…</b><br>Most days it feels more like going to work with a big family. Whether it’s a pot luck lunch, baking birthday cakes for colleagues in the kitchen, or after-hours get together, we’re here to do a great job and have a good time while doing it! We value a good sense of humor, are motivated by a higher purpose, and always bring an “in-this-together” attitude.  While we’re driven to do great work, we also value real work/life balance. </span></span><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Is This the Career for You?</b></span></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">The Vice President, Head of Enterprise Risk Management (ERM) is a senior leadership role responsible for designing, implementing, and continuously maturing the Credit Union’s enterprise risk management framework. This role provides strategic oversight across all risk disciplines, including ERM, Compliance, Business Continuity Planning (BCP), and Vendor Risk Management.</span></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">The VP will lead the organization’s efforts to identify, assess, monitor, and mitigate risks across all NCUA risk categories, while ensuring alignment with regulatory expectations, industry best practices, and organizational strategy. A critical component of this role is strong expertise in technology and IT-related risks, including cybersecurity, data governance, and IT compliance.</span></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b><u>What You’ll Be Doing</u></b></span></span></p><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Enterprise Risk Management Leadership</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Lead the development, implementation, and ongoing enhancement of a formal Enterprise Risk Management (ERM) framework aligned with regulatory expectations and industry standards (e.g., COSO ERM Framework).</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Establish a holistic risk management approach that integrates risk awareness into strategic planning and operational decision-making.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Provide enterprise-wide oversight of risk identification, assessment, mitigation, and monitoring activities.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Risk Oversight Across NCUA Risk Categories</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Maintain oversight across all seven NCUA risk categories, including Credit Risk, Interest Rate Risk, Liquidity Risk, Operational Risk, Compliance Risk, Strategic Risk, and Reputation Risk.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure risks are effectively assessed, documented, and managed across all business units.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Risk Assessments & RCSA Program</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Design and oversee the Enterprise Risk Assessment program to identify emerging and top organizational risks.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Lead the implementation and ongoing enhancement of Risk and Control Self-Assessments (RCSA) across the organization.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure consistency, quality, and reliability of risk assessments across business lines.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Partner with business leaders to strengthen control environments and risk mitigation strategies.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Risk Appetite & Key Risk Indicators (KRIs)</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Develop, refine, and maintain the organization’s Risk Appetite Framework, ensuring alignment with strategic objectives and board expectations.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Establish and monitor KRIs and thresholds to proactively manage risk exposure.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Provide actionable insights and early warning signals to executive leadership.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Risk Reporting & Governance</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Deliver comprehensive, timely, and insightful risk reporting to executive management.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Establish strong risk governance structures, including policies, committees, and escalation protocols.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure transparency and clarity regarding risk exposure, trends, and emerging risks.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Compliance Oversight</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Oversee the Compliance function, ensuring adherence to applicable laws, regulations, and regulatory guidance.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Maintain strong regulatory relationships and support regulatory examinations and audits.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure integration of compliance risk into the broader ERM framework.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Business Continuity Planning</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Provide executive oversight of Business Continuity and Disaster Recovery programs.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure organizational resilience through robust continuity planning, testing, and response capabilities.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Oversee crisis management frameworks and incident response coordination.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Vendor Risk Management</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Oversee the Third-Party/Vendor Risk Management program, ensuring appropriate due diligence, risk assessment, and ongoing monitoring.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure compliance with regulatory expectations related to third-party risk management.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Evaluate concentration risk, critical vendor dependencies, and operational resilience risks.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Technology Risk & IT Compliance</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Serve as a key leader overseeing technology-related risks, including Cybersecurity Risk, Information Security, Data Privacy & Governance, and Cloud & Third-Party Technology Risks.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Partner with IT and Information Security leadership to ensure robust risk identification and mitigation practices.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Ensure compliance with relevant regulatory guidance and frameworks (e.g., FFIEC guidance, NCUA expectations).</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Translate complex technical risks into clear business and executive-level insights.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Leadership & Collaboration</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Lead, mentor, and develop a multi-functional risk team spanning ERM, Compliance, Business Continuity Planning (BCP), and Vendor Risk Management.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Foster a strong risk culture across the organization through training, communication, and leadership.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Serve as a trusted advisor to executive leadership on all risk-related matters.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Collaborate cross-functionally with Finance, IT, Internal Audit, and business units.</span></span></li></ul><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b><u>What We Look For In You</u></b></span></span></p><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Bachelor’s degree required; advanced degree preferred (e.g., MS in Risk Management or related field).</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">12–15+ years of progressive experience in risk management, compliance, or related fields within financial services (credit union or banking experience strongly preferred).</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">10–15 years of experience in senior leadership roles.</span></span></li></ul><h3><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Technical & Leadership Expertise</b></span></span></h3><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Deep knowledge of enterprise risk management frameworks (e.g., COSO ERM).</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Strong understanding of NCUA regulations and supervisory expectations.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Demonstrated expertise in Risk Appetite Frameworks & KRIs, RCSA Programs & Enterprise Risk Assessments, and Risk Governance & Reporting.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Strategic thinker with strong execution capabilities.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Exceptional communication and relationship management skills.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Proven ability to build and mature risk programs within a dynamic environment.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Strong analytical, problem-solving, and decision-making capabilities.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">High integrity and sound judgment.</span></span></li></ul><h2><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b>Physical Demands</b></span></span></h2><ul><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">The physical demands described here are representative of those required to successfully perform the essential functions of this role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">While performing the duties of this role, the employee is regularly required to sit for extended periods of time, use hands to handle objects and operate a computer, and communicate verbally and hear effectively.</span></span></li><li><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">Specific vision abilities required include close vision and the ability to adjust focus.</span></span></li></ul><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><i>Note: This job description is non-contractual and is not intended to be an exhaustive list of responsibilities. Duties and responsibilities may be modified or updated at any time.</i></span></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><b><u>Salary</u></b></span></span></p><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;">This compensation range takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At SFFCU, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for the <b>San Francisco Market</b> is an annual salary of $156,000 to $234,000.<br><span style="line-height:115%;"><b>OUR BENEFITS</b><br>We have a competitive compensation and benefits package, but the true reward of working for SF Fire Credit Union goes beyond what you’ll see on a pay-stub. We genuinely care our employees and we strive to invest in their professional and personal growth. We’re a relatively small organization at about 200 employees, so you can see the impact of your efforts and the value your contributions bring to our members and fellow employees.</span></span></span></p><ul style="margin-bottom:11px;"><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">401(k) and Employer Match</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">Health, Vision, Dental and Life Insurance</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">Annual Incentive/Bonus Program</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">Tuition Reimbursement Program</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">11 Paid Holidays + Competitive PTO package</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">Home & Consumer Loan Program (Discounted Rates)</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">Professional development and training programs</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">On-demand personal coaching resource</span></span></span></li><li style="margin-bottom:11px;"><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;">Wellness Program (Discounted Gym Membership)</span></span></span></li></ul><p><span style="font-family:Arial, Helvetica, sans-serif;"><span style="font-size:11px;"><span style="line-height:115%;"><i>“Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.”</i> </span></span></span></p><p></p>

Back to blog