About this role
BlackRock is seeking a Director to lead the Data Risk Oversight team within Enterprise Risk Management in New York. The role focuses on the quality, integrity, and reliability of enterprise data across its lifecycle. It is about data risk—data being inaccurate, incomplete, untimely, or unfit for purpose—rather than data security or cybersecurity, which are governed separately. The successful candidate will provide independent review and challenge of first-line data owners, hold them accountable for compliance with data risk requirements, and present senior committees and boards with a clear, evidence-based view of residual data risk.
Responsibilities
-
Oversight of First Line Data Owners
-
Provide independent oversight, review, and challenge of first-line data owners and data stewards to ensure they identify, assess, and manage data risk in line with the firm’s data risk management policies and standards.
-
Hold the first line accountable for compliance with data risk requirements across the data lifecycle, including ownership and accountability, data quality controls, metadata and lineage documentation, and fitness for purpose.
-
Assess the design and operating effectiveness of first-line data quality controls, including data quality rules, thresholds, validation checks, and reconciliation processes, and challenge remediation where controls are insufficient.
-
Partner with first-line teams across Aladdin Data, portfolio management, capital markets, operations, and their functional data owners to embed clear ownership and a strong culture of accountability for data risk.
-
Review and challenge Risk and Control Self-Assessments (RCSAs) for data risk, ensuring material data risks are transparently assessed, linked to appropriate controls, and that residual risk is formally accepted within the firm’s risk tolerance.
-
Data Incidents and Operating Events
-
Oversee the follow-up of data-related incidents and operating events, ensuring they are captured, triaged, and escalated in line with BlackRock’s incident management and operating event processes.
-
Provide independent challenge on root cause analysis, remediation, and preventative actions, confirming that lessons learned are embedded and that thematic issues are identified across events.
-
Ensure timely escalation of significant data incidents to the Data Risk Oversight Committee (DROC) and, where appropriate, the Enterprise Risk Committee and boards.
-
Track remediation and issues to closure, monitoring Risk & Control Issues (RCIs) and control improvements arising from events and assessments, and escalating overdue or unresolved items.
-
Metrics, Risk Indicators, and Reporting
-
Develop and maintain data risk metrics and indicators, including Enterprise Risk Indicators (ERIs) with clear thresholds that inform an assessment of the firm’s data risk profile.
-
Establish ownership and reporting of data risk indicators, and translate underlying data into a concise, decision-useful view of residual risk for the DROC, the Enterprise Risk Committee, and the Board Risk Committee.
-
Produce board- and committee-ready reporting that clearly articulates inherent risk, the control environment, and the resulting level of residual data risk the firm is running relative to its risk tolerance.
-
Support the maturation of the data risk framework, including the data risk and control taxonomy, expansion of RCSA coverage, and continuous enhancement of oversight practices as the risk landscape evolves.
-
Governance and Stakeholder Engagement
-
Act as a key contributor to the Data Risk Oversight Committee (DROC), supporting its mandate to monitor compliance with data risk management policies and standards and to escalate matters as appropriate.
-
Collaborate with Legal & Compliance, Internal Audit, Information Security, and Privacy to ensure a coordinated approach to data governance and a clear delineation between data quality oversight and data security oversight.
-
Engage with regulators and internal audit on data risk matters, supporting the firm’s commitments to establishing and operating an effective enterprise data risk oversight framework.
-
Leadership Expectations
-
Build and lead a high-performing data risk oversight team, setting direction and developing specialist talent as the discipline scales.
-
Influence senior stakeholders across the first and second lines, exercising sound, independent judgment and the confidence to challenge constructively while maintaining trusted relationships.
-
Champion a culture in which first-line teams own and manage data risk, supported by clear frameworks, standards, and guidance.
-
Communicate complex data risk topics simply and credibly to the most senior audiences, including executive committees and the board.
-
What We Look For
-
10+ years of experience in data risk, data governance, operational or enterprise risk management, or a closely related control or audit discipline, ideally within asset management, banking, or financial services.
-
Strong understanding of data quality and data governance principles across the data lifecycle, including ownership, metadata, lineage, data quality controls, and fitness for purpose, with the ability to distinguish and coordinate with data security and privacy disciplines.
-
Demonstrated experience providing independent oversight, review, and challenge of first-line teams, and holding stakeholders accountable for control performance.
-
A track record of designing risk metrics and indicators and producing decision-useful reporting for senior committees and boards.
-
Experience following up on incidents and operating events, including root cause analysis, remediation tracking, and escalation.
-
Excellent judgment, critical reasoning, and the ability to challenge the status quo and drive pragmatic solutions across cross-functional teams.
-
Clear, credible communication skills, with the ability to influence outcomes at the most senior levels.
-
Familiarity with industry-leading frameworks (for example, DAMA DMBOK, COSO ERM, NIST CSF 2.0) and relevant regulatory expectations (for example, OCC guidance) is preferred.
-
A bachelor’s degree is required; an advanced degree or relevant professional certification (e.g., CDMP, CRISC, CISA) is a plus.