Managing control updates, annual mapping, and testing requirements * Design, document, and maintain Risk and Control Matrices (RCMs/RACMs) across business and IT processes * Continuously improve and ...
Managing control updates, annual mapping, and testing requirements * Design, document, and maintain Risk and Control Matrices (RCMs/RACMs) across business and IT processes * Continuously improve and ...
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Boston, MA · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · Hybrid
$100K - $135K/yr
Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · On-site
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... Manage applicable policy and program governance, while performing assurance activities to assess ...
Operational Risk Manager - Cybersecurity
Johnston, RI · On-site
$100K - $135K/yr
Operational Risk Manager - Cybersecurity Work Arrangement Hybrid work arrangement required with 4 ... Manage applicable policy and program governance, while performing assurance activities to assess ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
Operational Risk Manager
Johnston, RI · On-site
The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM oversight ...
Operational Risk Manager
Johnston, RI · On-site
The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM oversight ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
Operational Risk Manager
Johnston, RI · On-site
The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM oversight ...
Operational Risk Manager
Johnston, RI · On-site
The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM oversight ...
Operational Risk Manager
Boston, MA · On-site
Description The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM ...
Operational Risk Manager
Boston, MA · On-site
Description The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
You will be responsible for executing control monitoring and testing programs, maintaining risk and control inventories, performing risk assessments, managing issues through remediation, and ...
Operational Risk Manager
Westwood, MA · On-site
Description The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM ...
Operational Risk Manager
Westwood, MA · On-site
Description The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM ...
Operational Risk Manager
Westwood, MA · On-site
Description The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM ...
Operational Risk Manager
Westwood, MA · On-site
Description The Manager of Operational Risk Management (ORM) would support ORM program elements for several Enterprise Service functions. Finance, HR, and Legal areas for ORM.. In supporting the ORM ...
Drive the development, implementation, and continuous evolution of the governance program, driving ... Actively manage the enterprise risk register, driving risk prioritization, maintaining visibility ...
Drive the development, implementation, and continuous evolution of the governance program, driving ... Actively manage the enterprise risk register, driving risk prioritization, maintaining visibility ...
Risk Program Manager information
See Woonsocket, RI salary details
$49.3K - $59.7K
4% of jobs
$59.7K - $70K
6% of jobs
$70K - $80.3K
11% of jobs
$84.2K is the 25th percentile. Wages below this are outliers.
$80.3K - $90.6K
11% of jobs
The median wage is $98.8K / yr.
$90.6K - $101K
23% of jobs
$101K - $111.3K
13% of jobs
$118.1K is the 75th percentile. Wages above this are outliers.
$111.3K - $121.6K
12% of jobs
$121.6K - $131.9K
8% of jobs
$131.9K - $142.3K
6% of jobs
$142.3K - $152.6K
4% of jobs
$152.6K - $162.9K
2% of jobs
$49.3K
$106.9K
$162.9K
How much do risk program manager jobs pay per year?
What are the 3 C's of risk management?
What are the typical challenges faced by a Risk Program Manager when balancing compliance requirements with business objectives?
What is the highest salary for a risk manager?
What is the difference between Risk Program Manager vs Risk Analyst?
| Aspect | Risk Program Manager | Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRM, FRM, or PMP often preferred | Certifications such as CRM or FRM may be beneficial but less common |
| Work Environment | Oversees risk management programs across departments, strategic focus | Analyzes data, identifies risks, supports risk mitigation efforts |
| Employer & Industry Usage | Used in finance, insurance, large corporations | Common in finance, banking, and consulting firms |
| Search & Comparison Intent | Looking for managerial or program oversight roles | Seeking entry-level or analytical risk roles |
The Risk Program Manager focuses on leading and coordinating comprehensive risk management strategies, while the Risk Analyst primarily analyzes data to identify and assess risks. Both roles are essential in risk management but differ in scope and responsibilities.
What does a risk program manager do?
How much does a risk manager get paid?
What are the key skills and qualifications needed to thrive as a Risk Program Manager, and why are they important?
Principal Technology Risk Analyst - Program & Regulatory Assurance
Smithfield, RI • On-site
Full-time
Posted 19 days ago
Fidelity Investments rating
8.8
Based on 269 frontline employees who took The Breakroom Quiz
9th of 150 rated financial services
Job description
Title: Principal Technology Risk Analyst
Note: Fidelity will not provide immigration sponsorship for this position.
The Role
The Enterprise Technology Risk group is seeking a passionate, driven and experienced professional to contribute to the Technology Risk Program and Regulatory Assurance CoE team.This role is responsible for performing regulatory and program management responsibilities, including designing and maintaining technology controls to support program and regulatory requirements. This role will require networking and relationship management skills to collaborate with the Controls Testing team, and various business units and risk teams across the enterprise. You will be working on:
- Ensuring risk and control taxonomy aligns with enterprise standards
- Developing and monitoring technology controls for security and compliance
- Providing technical support and acting as liaison for technology risk management
- Managing control updates, annual mapping, and testing requirements
- Design, document, and maintain Risk and Control Matrices (RCMs/RACMs) across business and IT processes
- Continuously improve and standardize control documentation and governance practices
- Overseeing control certification process
- Partnering with Control Testing team to track progress and remediation
- Representing ETRA in enterprise control initiatives and special projects
- Supporting regulatory activities, risk assessments, and examinations
- Leading and supporting SOX 404 compliance, including control documentation
- Reviewing SOC reports, assessing CUECs, and communicating control gaps
The Team
The Technology Risk Program and Regulatory Assurance team is responsible for managing controls to support program requirements, monitoring the results of control testing to meet program requirements, and ensuring a consistent risk and control taxonomy is leveraged in accordance with enterprise best practices. Additionally, this team supports regulatory activities such as maintaining application, server, and database inventories by entity.Technology Risk is part of the broader Legal, Risk and Compliance group and partners with Corporate Audit, Enterprise Compliance, and Security to protect the interests of our customers, our employees, and Fidelity's brand. You will also work closely with the Enterprise Technology Risk teams as well as Fidelity technology and business owners, and Operational Risk teams.
The Expertise and Skills You Bring
- 5 -7 years' experience in information technology risk, controls, or audit roles
- Bachelor's degree in computer science, technology, or a related field of study preferred
- Professional technology and associated risk certifications (CISSP, CISA, CRISC, CISM), Certified risk/fraud examiners (CRE, CFE), and/or Cloud Certification(s) (CCSP, CCSK, AWS) preferred
- Experience documenting controls for large scale financial service organizations (cloud, distributed, vendor solutions, mainframe, network environments, and AI)
- Demonstrated technical abilities in multiple areas (e.g., technology infrastructure and application controls, cyber security, access management, network and cloud, resiliency, etc.)
- Working knowledge of Cloud security and controls and cloud technology environments (AWS/Azure, SaaS, PaaS)
- You have a strong knowledge of information technology processes and controls, and a comprehensive understanding of risk, quality control and assurance functions
- Your love of solving complex problems, and comfort with ambiguous situations, and your ability to help solution innovative ways to mitigate risk using your advanced analytical and critical thinking skills
- Your ability to build and maintain collaborative working relationships with Information Technology and Business personnel to design effective controls
- Your process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
- Knowledge of Industry standards, regulations, frameworks and best practices, such as NIST SP 800-53, COBIT, AICPA Trust Principles, ISO27001, SWIFT, HITRUST, and SOX404 is preferred
- ISO9001 and/or ISO27001 certification preferred, with responsibility to support and participate in ISO peer audit reviews.
- Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferred
- Your excellent verbal and written communication skills enabling you to prepare and present recommendations to senior management
Note: Fidelity will not provide immigration sponsorship for this position.
Fidelity's Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.
Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.
What Fidelity Investments employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Fidelity
Sourced by ZipRecruiter