About Experience Education Certifications Contact Projects ↗ View Live: RISK
Senior Leader – IT, Cybersecurity & Information Security Risk Governance (Second Line)

Harish Reddy Ravi

Independent Challenge & Executive-Ready Risk Leadership Across
Cybersecurity · IT · Data · AI · Third-Party Risk

📍 Arlington, VA ✉️ iam.harishreddy@gmail.com 🔗 LinkedIn 📞 630.464.6618
View Experience
risk.profile — live
15+ Yrs Experience
VP Current Level
4 Certifications
AWS Cloud Arch.
CISSP NIST FFIEC RCSA KRI SDLC DR / BCP AI Risk Cloud
Risk Frameworks
Cloud Architecture
Regulatory Compliance

Professional Summary

Technology and information security risk leader with experience in regulated financial services, providing independent second-line oversight across cybersecurity, IT, data, AI, and third-party risk domains. Partner closely with senior leadership, business lines, IT, Information Security, Compliance, and risk management teams to identify, assess, monitor, and challenge risk across applications, infrastructure, cloud platforms, operational processes, and critical vendor relationships. Translate complex technical and control issues into clear, business-relevant narratives, strengthen risk governance and issue management, and support alignment with enterprise objectives, risk appetite, and regulatory expectations including FHFA, FFIEC and OCC.

Core Competencies

Second Line Risk Oversight
IT & Information Security Risk Governance
Cybersecurity Risk
Technology Risk (Infrastructure, Applications, Cloud, SaaS)
Data & AI Risk
Third-Party / Vendor Risk
Risk Assessments & Independent Challenge
Executive / Board Risk Reporting
Issue Management & Escalation
KRIs / Dashboards
Risk Governance (Three Lines of Defense)
Regulatory & Audit Engagement
Operational Resilience / DR
SDLC
Control Evaluation

Professional Experience

Vice President – Operational Risk Officer

Comerica Bank · Detroit, MI (remote)
2024 – 2026

Led enterprise-wide IT and regulatory risk management covering operations, third-party vendors, disaster recovery, and emerging technologies. Designed and executed enterprise risk assessment methodologies and implemented frameworks aligned with NIST and FFIEC guidelines. Established governance and transparency through risk dashboards and KRIs that translated complex risk data into action-oriented narratives for executive leadership and Audit Committees.

  • Owned the design and execution of enterprise risk assessment methodologies, enabling consistent identification, analysis, evaluation, and treatment of operational and technology risks across business units.
  • Led program improvement initiatives through deep dives into risk performance data, lessons learned, and control effectiveness metrics, driving measurable improvements in risk outcomes.
  • Developed and maintained risk dashboards, KRIs, and executive reporting, translating complex risk data into clear, action-oriented leadership narratives.
  • Partnered closely with senior leaders, audit committees, and cross-functional teams to align risk standards, metrics, and remediation plans with business objectives.
  • Conducted operational and system-level reviews to improve risk processes, methodologies, and governance standards.
  • Built and led high-performing teams while implementing risk assessment frameworks aligned with NIST and FFIEC guidelines, including interfacing with OCC and FFIEC during regulatory examinations.
  • Owned MRA and MRIA remediation to enhance governance, drive timely corrective actions, and achieve 100% successful closure.

Senior Technology Risk Manager

Freddie Mac · McLean, VA
2019 – 2024

Established and led the enterprise technology risk management process by instituting clear policies and standards, repeatable risk assessments, and building standardized control frameworks.

  • Designed and implemented standardized risk frameworks, policies, and assessment methodologies adopted across multiple business and technology functions.
  • Conducted enterprise risk assessments spanning operations, architecture, cloud, SDLC, AI, and resiliency, supporting proactive risk identification and consistent risk treatment.
  • Established policies, standards, KRIs, and reporting frameworks to monitor risk trends, effectiveness of controls, and program performance, including interaction with FHFA on regulatory issues.
  • Advised and trained stakeholders on risk standards, assessment processes, and mitigation approaches, improving organizational risk capability and adoption.
  • Identified best practices and scalable solutions to support consistent risk management across diverse teams.

Senior Software Engineer

Blackboard · Washington, DC
2010 – 2019

Led globally distributed teams and partnered with security and operations leaders to deliver scalable, secure platforms — experience that informs practical, implementation-aware risk standards and methodologies.

  • Established and onboarded new development teams in Bogotá, Colombia and Chennai, India, while leading agile delivery from project initiation through release.
  • Facilitated all Scrum ceremonies, partnered closely with product owners on backlog management, and reinforced Agile and Scrum best practices to ensure continuous feature delivery.
  • Led development of AWS-enabled microservices for Blackboard Learn, collaborated with security teams on investigations and feature implementation, built tools to resolve migration and data issues.
  • Earned multiple performance awards for impact and delivery.

Additional Relevant Experience

AOL Senior Java Consultant · Ashburn
Booz Allen Hamilton Java Consultant · Washington, DC
Verizon Java Consultant · Ashburn
Sears Java Consultant · Chicago

Education

🎓

Master of Science (MS)

Computer Science

Western Michigan University · Kalamazoo, MI

🎓

Bachelor of Technology (BTech)

Information Technology

CBIT · Hyderabad, India

Certifications

☁️

AWS Certified Solutions Architect Associate

Certified
🔷

Microsoft Certified Azure Fundamentals

Certified
🗄️

Graph Data Modeling Fundamentals

Certified
🔐

Certified Information Systems Security Professional (CISSP)

Active
🤖

AWS Generative AI

In Progress

Featured Projects

Risk Intelligence Platform

RISK

An enterprise-grade risk management platform demonstrating modern approaches to KRI tracking, regulatory compliance monitoring, and executive reporting. Features real-time composite risk scoring, AI-assisted findings, multi-axis risk profiling, and OCC submission drafting.

Executive Dashboard KRI Metrics FFIEC OCC Compliance AI Findings Regulation Explorer
View Live App →
risk-intelligence.vercel.app
Risk Intelligence Dashboard — Executive view showing composite risk score, KRI metrics, and 12-month trend chart

Get In Touch

✉️ iam.harishreddy@gmail.com
🔗 LinkedIn Profile
📞 630.464.6618
📍 Arlington, VA

Want to learn more about my experience?