Technology Risk Advisor
PNC Financial
- Location
- PA Pittsburgh 15222
- Work model
- On-Site
- Level
- Mid
- Posted
- Sep 1, 2026
Skills
About this role
Position
Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a(n) Technology Risk Advisor within PNC's Technology organization, you will be based in Pittsburgh PA, Dallas TX, Strongsville OH, Phoenix AZ, or Birmingham AL. As a Technology Risk Advisor – In Technology Risk Quantification, you will serve as the senior risk leader responsible for establishing and overseeing quantitative technology risk management practices within the Line of Business. This role provides strategic leadership for the identification, measurement, monitoring, and reporting of technology risk exposures and supports executive decision-making through data-driven risk insights. The position partners closely with Technology, Information Security, Operational Risk, Audit, Compliance, Finance, and Enterprise Risk Management teams to develop and mature technology risk quantification capabilities that align with PNC’s Enterprise Risk Management Framework and regulatory expectations. Primary Responsibilities: · Establishes and maintains a comprehensive Technology Risk Quantification program that enables business and technology leaders to understand cyber, operational, infrastructure, and emerging technology risks in financial terms. · Develops methodologies, models, and frameworks to quantify technology risk exposures, including: · Cybersecurity events · System failures and outages · Data loss and disclosure events · Privilege misuse · Fraud and technology-enabled scams · Third-party technology dependencies · AI and emerging technology risks Oversees development of risk scenarios, loss-event libraries, threat intelligence inputs, and control effectiveness analyses to support risk measurement activities. Partners with Technology and Information Security teams to identify key risk indicators, control performance metrics, risk concentration measures, and leading indicators that improve risk visibility and decision-making. Provides credible challenge and independent assessment of technology risk exposures, risk acceptance decisions, and remediation priorities. Ensures technology risk quantification practices align with: · Enterprise Risk Management Framework · Operational Risk Management Standards · OCC Heightened Standards · Regulatory expectations for model governance and risk measurement · Industry frameworks (NIST, FAIR, CIS, COBIT) Supports executive management, risk committees, and Board reporting through development of meaningful quantitative risk insights and scenario-based analyses. Leads cross-functional teams in the execution of technology risk assessments, stress testing, operational resilience analyses, and emerging risk evaluations. Monitors internal and external risk trends, threat landscape developments, technology modernization initiatives, and regulatory changes to identify emerging risks. Oversees the development of risk dashboards and risk appetite metrics that enable leaders to monitor technology risk exposure against established thresholds. Develops and mentors technology risk professionals while building organizational capabilities in quantitative risk analysis and risk-informed decision making. Risk Quantification Responsibilities: Technology Loss Modeling: · Develops and enhances technology loss estimation methodologies. · Evaluates loss frequency and severity drivers. · Performs Monte Carlo, scenario-based, and probabilistic analyses where applicable. · Supports capital planning and enterprise risk aggregation activities. Risk Scenario Development · Leads development of enterprise technology risk scenarios across: · Cybersecurity · Infrastructure availability · Cloud services · Identity and Access