Technology Risk · Cybersecurity Compliance · IT Controls
Principal Director, Technology & Cybersecurity Risk Oversight
12+ years of Big Four advisory, intelligence community support, and enterprise risk leadership across highly regulated technology environments. I build the independent oversight functions, control environments, and governance frameworks that give boards, regulators, and executives the confidence to operate at scale.
I'm Jack Blair, a technology risk and cybersecurity compliance professional whose career spans Big Four advisory, intelligence community engagements, and enterprise second-line risk oversight at one of the largest financial institutions in the United States. My work sits at the intersection of technology, governance, and regulatory accountability — where the stakes are highest and the margin for error is zero.
As a Principal Director at Fannie Mae, I lead independent oversight of enterprise technology domains — system availability, SDLC, change management, incident response, configuration governance, and operational resilience — across environments operating at multi-trillion-dollar scale. I've served as an independent advisor to boards and senior executives on material cybersecurity risk themes, and I've built the control frameworks that regulators rely on.
My foundation includes Deloitte Risk & Financial Advisory serving Fortune 50 financial services clients and U.S. intelligence agencies, supported by a Top Secret security clearance with Counterintelligence Polygraph. Earlier in my career I developed deep analytical and financial management skills supporting advanced programs at Lockheed Martin. I don't just understand technology risk — I've operated inside the most demanding environments where it lives.
I'm seeking meaningful opportunities where my knowledge, skills, and background can help a risk organization mature, grow, or sustain operational effectiveness — bringing disciplined oversight, practical experience, and a genuine commitment to building functions that hold up when it matters most.
Second-line risk leadership for enterprise technology control environments — system availability, SDLC, change management, incident response, configuration governance, and cloud infrastructure security across complex, highly regulated platforms.
Deep expertise in IT General Controls, application controls, and SOX 404 readiness. Proven ability to assess design and operating effectiveness, identify control gaps, and build sustainable audit-ready environments that hold up under regulator scrutiny.
Extensive experience with NIST CSF, NIST 800-53r5, FFIEC, FISMA, FISCAM, OMB Circulars, and COBIT. Trusted independent advisor to executive leadership on regulatory expectations, examination preparedness, and compliance program maturity.
Built and led ERM programs spanning key risk indicator monitoring, issue management, control testing oversight, and compliance reporting for executive and regulator audiences across both commercial and government environments.
Recurring presence before boards, audit committees, and senior leadership on material technology risk themes, cybersecurity exposures, and operational resilience. Skilled at translating deeply technical risk signals into governance-level clarity and action.
Supported Big Four engagements helping clients strengthen control documentation, testing approaches, and audit sustainability ahead of major transactions — with hands-on experience rationalizing control environments under time pressure across financial services and government sectors.
Serve as principal second-line risk leader for enterprise technology domains at one of the nation's largest housing finance institutions, with oversight responsibility spanning a $4.1T mortgage guarantee portfolio and critical national infrastructure. Provide independent challenge and oversight of control environments supporting system availability, SDLC, change management, incident management, configuration governance, and operational resilience.
Served as lead cybersecurity risk manager responsible for overseeing cyber and technology risk operations, compliance with applicable regulations, and managing adherence to enterprise policies and risk tolerances across one of the most scrutinized financial institutions in the country.
Served as lead technology risk manager for a critical national financial market infrastructure firm, responsible for risk and control compliance across an enterprise-wide technology portfolio spanning information security, cybersecurity, cloud infrastructure, access management, business resiliency, and disaster recovery in a cloud-native application environment.
Led and supported IT compliance, IT controls, audit readiness, and risk management engagements for Fortune 50 financial services clients and large U.S. intelligence agencies. Served as Senior Consultant and acting Manager specializing in IT compliance, with additional responsibilities as project manager for technology control and risk management engagements supporting multiple large U.S. intelligence agencies. Top Secret security clearance with Counterintelligence Polygraph.
IT and financial management consultant for financial institution clients on enterprise risk management, IT risk, audit readiness, and process improvement — working directly with executive banking leadership.
IT and financial management consultant supporting audit readiness, enterprise risk management, and business process improvement engagements for federal and public sector clients.
Supported program management, budgeting, and financial analysis for highly complex national security aerospace development efforts within Lockheed Martin's Advanced Development Programs. Supported implementation of a large-scale, air-gapped SAP ERP environment, helping align financial management, business operations, and system deployment within a secure mission environment.
The next generation of technology risk leadership won't just govern AI — it will use AI to perform better oversight, move faster, and build more resilient control environments. I'm already operating there.
I have practical, hands-on experience deploying generative AI tools across research, content development, control documentation, risk analysis, and presentation development — while applying professional judgment to validate outputs and maintain governance integrity.
Effective risk oversight isn't a friction tax on the business — it's the independent signal that gives leadership the confidence to move faster, build bigger, and operate at scale without fear.
Jack Blair — Technology Risk Leadership Philosophy
I'm looking for meaningful opportunities where my experience in technology risk, cybersecurity oversight, and IT controls can help an organization mature its risk program, strengthen its control environment, or sustain operational effectiveness. If you're building something worth protecting — let's talk.