1

Senior Risk Engineer Jobs in Indianapolis, IN (NOW HIRING)

AI DevSecOps Senior Engineer

Indianapolis, IN ยท Hybrid

$109K - $150K/yr

AI DevSecOps Senior Engineer AI DevSecOps Senior Engineer Locations: This role requires associates ... Lead development and execution of risk assessment methodologies to fit business, regulatory, and ...

Senior CSV Engineer

Indianapolis, IN ยท On-site

$110 - $160/hr

About the Job Performance Validation is seeking a Senior CSV Engineer to join our Indianapolis team ... Working knowledge of risk-based cGMP principles, FDA regulations, EU Annex 11, Data Integrity ...

Senior Safety Engineer I

Lebanon, IN ยท On-site

$89K - $120K/yr

Senior Safety Engineer I SUMMARY Mortenson is currently seeking a Senior Safety Engineer I that ... Work with client safety personnel, union representatives, and insurance risk engineers * Ensure ...

Senior Mechanical Engineer

Indianapolis, IN ยท Hybrid

$98K - $160K/yr

Senior Mechanical Engineer Working Pattern: Full-time Working location: Indianapolis, IN (Hybrid ... Experience with New Product Introduction (NPI), change management, and risk management processes

Senior Mechanical Engineer

Indianapolis, IN ยท On-site

$98K - $160K/yr

Senior Mechanical Engineer Working Pattern: Full-time Working location: Indianapolis, IN (Hybrid ... Experience with New Product Introduction (NPI), change management, and risk management processes

Senior Mechanical Engineer

Indianapolis, IN ยท Hybrid

$98K - $160K/yr

Senior Mechanical Engineer Working Pattern: Full-time Working location: Indianapolis, IN (Hybrid ... Experience with New Product Introduction (NPI), change management, and risk management processes

next page

Showing results 1-20

Senior Risk Engineer information

See Indianapolis, IN salary details

$56.9K

$121K

$175.4K

How much do senior risk engineer jobs pay per year?

As of Aug 30, 2026, the average yearly pay for senior risk engineer in Indianapolis, IN is $120,972.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,900.00 and $137,200.00 per year, depending on experience, location, and employer.

What does a senior risk engineer do?

A Senior Risk Engineer is responsible for identifying, assessing, and mitigating risks in engineering projects or operations, often within sectors like insurance, energy, or manufacturing. They analyze potential hazards, develop risk management strategies, and ensure compliance with regulations and industry standards. These professionals also provide recommendations to improve safety, reduce losses, and support business decision-making. Senior Risk Engineers often mentor junior staff and work closely with project managers, safety teams, and other stakeholders.

How does a senior risk engineer typically collaborate with cross-functional teams to address potential hazards in large-scale projects?

A Senior Risk Engineer often works closely with project managers, design engineers, safety specialists, and operations teams to identify, assess, and mitigate risks associated with large-scale projects. This collaboration involves leading risk assessment workshops, reviewing technical documents, and ensuring that all stakeholders understand risk mitigation strategies. Effective communication and the ability to translate complex technical risks into actionable plans are key to success in this role. Regular meetings and progress reviews help ensure that risk controls are integrated throughout all project phases.

What are the key skills and qualifications needed to thrive as a senior risk engineer, and why are they important?

To thrive as a Senior Risk Engineer, you need deep expertise in risk assessment, engineering principles, and regulatory compliance, typically supported by a degree in engineering or a related field and several years of industry experience. Familiarity with risk analysis tools (such as HAZOP, FMEA), industry standards, and certifications like Professional Engineer (PE) or Certified Safety Professional (CSP) are often required. Strong analytical thinking, communication, and leadership skills help you effectively identify risks and guide teams in implementing mitigation strategies. These competencies are critical for ensuring operational safety, regulatory adherence, and minimizing potential losses in complex engineering environments.

What is the difference between Senior Risk Engineer vs Risk Analyst?

AspectSenior Risk EngineerRisk Analyst
Required CredentialsBachelor's or higher in engineering, risk management certifications (e.g., CRM)Bachelor's in finance, economics, or related field; risk management certifications often preferred
Work EnvironmentEngineering firms, industrial sites, insurance companiesFinancial institutions, insurance companies, consulting firms
Employer & Industry UsageUsed in engineering, manufacturing, energy sectorsCommon in finance, insurance, and corporate risk departments

While both roles focus on assessing and managing risks, the Senior Risk Engineer typically works in technical and industrial environments, applying engineering principles. The Risk Analyst often operates within financial or corporate settings, analyzing data to inform risk decisions. The roles share certifications and require analytical skills but differ mainly in industry focus and technical depth.

How much do senior risk engineers make in the US?

Senior risk engineers in the US typically earn between $90,000 and $130,000 annually, with salaries varying based on experience, industry, and location. They often hold certifications such as FRM or CRM and work in industries like insurance, finance, or manufacturing, where risk assessment and mitigation are critical.

Is risk engineering a good career?

Risk engineering is a viable career that involves identifying and analyzing potential hazards to prevent losses in industries such as insurance, manufacturing, and energy. It requires strong analytical skills, knowledge of safety standards, and often certifications like the Certified Risk Manager (CRM). The field offers opportunities for advancement and specialization, with a focus on problem-solving and risk mitigation.

What are popular job titles related to Senior Risk Engineer jobs in Indianapolis, IN?

For Senior Risk Engineer jobs in Indianapolis, IN, the most frequently searched job titles are:

What job categories do people searching Senior Risk Engineer jobs in Indianapolis, IN look for?

The top searched job categories for Senior Risk Engineer jobs in Indianapolis, IN are:

Infographic showing various Senior Risk Engineer job openings in Indianapolis, IN as of August 2026, with employment types broken down into 75% Full Time, 5% Part Time, and 20% Contract. Highlights an 100% In-person job distribution, with an average salary of $120,972 per year, or $58.2 per hour.

Senior Director - GRC Engineer

Indianapolis, IN โ€ข On-site

Initial Therapeutics, Inc.
Biotechnology Research and Developmentย โ€ขย 11 - 50 employees

$155 - $227/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Job description

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless workโ€”but itโ€™s work worth doing. If youโ€™re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.

The Senior Director, Governance Risk and Compliance (GRC) Engineer is a senior leader within the Digital Legal Office (DLO) GRC & Service Management organization. The role translates the DLOโ€™s privacy, AI, and data governance frameworks into effective, auditable, and increasingly automated control designs. The GRC Engineer bridges the gap between what regulatory and policy obligations require, and how those obligations are implemented as operational controls by business control owners across the enterprise.

The GRC Engineer leads the engineering team that ensures controls are well-designed, produce the evidence required for KRI/KPI measurement, and can be sustained and automated over time. They also have responsibility for the control maturity roadmap; synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a strategic plan that prioritizes where and how controls need to mature.

The GRC Engineer is the primary technical enablement partner for the DLO Embedded Team, equipping them to guide business control owners through implementation. This influence model requires a senior individual who can credibly engage at the right level across the enterprise, driving adoption of control designs with stakeholders who have contending priorities and significant organizational authority.

This role also serves as the DLOโ€™s peer-level liaison to Cyber Engineering and Security Architecture teams, ensuring that DLO-owned control designs are technically coherent with the broader enterprise security architecture, and that shared control boundaries are clearly defined.

Control Design & Architecture
  • Own end-to-end design of DLO-owned privacy, AI, and data governance controls - translating regulatory obligations, policy requirements, and risk appetite into auditable, repeatable control architectures.
  • Define and retain control design specifications for each control in the DLO GRC Framework, including test procedures, evidence requirements, data flows, and automation targets.
  • Apply privacy-by-design and AI-by-design principles throughout the control engineering lifecycle, from inception through deployment and ongoing sustainment.
  • Lead technical analysis to identify control gaps, design deficiencies, and automation opportunities; propose and drive remediation with appropriate urgency.
  • Develop and publish design documentation, technical specifications, and implementation guides that create consistency in how controls are built and validated.
  • Design control evidence outputs that directly feed KRI/KPI measurement - ensuring that what gets measured is a function of control design, not manual data collection.
Control Maturity Roadmap & Strategic Direction
  • Be responsible for the DLO control maturity roadmap - a multi-year strategic plan defining how DLO-owned controls will evolve in response to regulatory change, technology advancement, and enterprise risk posture shifts.
  • Synthesize inputs from GRC Analysts (risk assessments, control effectiveness ratings, gap analyses) and KRI/KPI performance data to identify where controls are underperforming, immature, or misaligned to risk appetite and translate those findings into prioritized maturity initiatives.
  • Define maturity targets for each control domain (privacy, AI, data governance), establishing clear progression criteria from initial/ad-hoc through optimized/automated states.
  • Lead strategic planning processes that translate the roadmap into prioritized, funded, and governed initiatives with clear milestones, owners, and success metrics.
  • Anticipate regulatory and technology trends (e.g., EU AI Act enforcement, evolving NIST frameworks, agentic AI) and proactively incorporate their implications into control design direction and maturity targets.
  • Partner with GRC Analysts and Service Management to align the control maturity roadmap with the risk assessment calendar and service delivery capacity.
  • Engage DLO leadership and senior stakeholders regularly to communicate roadmap progress, emerging risks, and recommended strategic investments in control maturity.
Embedded Team & Business Control Owner Enablement
  • Serve as the senior technical enablement partner for the DLO Embedded Team, providing control design blueprints, reference architectures, and technical guidance that equip them to work effectively with business control owners.
  • Develop reusable control design frameworks, templates, and implementation patterns that business teams can adapt to their specific processes and technology environments.
  • Directly engage business control owners on complex or contested control designs - providing the technical authority and credibility required to resolve design disagreements, negotiate evidence requirements, and drive adoption of control standards.
  • Provide support and direction on how to translate assessment findings, incidents, and issues into actionable control improvements.
  • Triage and advise on sophisticated, ambiguous control scenarios where regulatory guidance, technical constraints, and business priorities must be carefully balanced.
  • Build engagement models that create a consistent control design culture across the enterprise - proactively sharing protocols, lessons learned, and design patterns.
Cyber Engineering & Architecture Partnership
  • Serve as the DLOโ€™s peer-level liaison to the CISO organizationโ€™s Engineering and Security Architecture teams for matters of control design, technical integration, and shared control boundaries.
  • Ensure DLO-owned controls are technically coherent with enterprise security architecture - particularly where privacy, AI, and cybersecurity controls share infrastructure, tooling, or evidence sources.
  • Partner on control design reviews where DLO and Cyber controls intersect (e.g., data protection controls that serve both privacy and security objectives).
  • Evaluate and recommend privacy-enhancing technologies (PETs), AI governance tools, and GRC platform capabilities in coordination with Cyber Architectureโ€™s technology roadmap.
  • Coordinate with the AI Strategy & Digital Risk role to present a coherent DLO interface to the CISO organization.
GRC Platform & Automation Enablement
  • Partner with Service Management to design control configurations within the GRC platform (ServiceNow IRM), ensuring that what is designed can be operationalized, monitored, and reported against.
  • Provide engineering leadership for the automation and AI-enablement of control operations across DLO owned and non-DLO owned controls - identifying where intelligent workflows, AI agents, and tooling can reduce manual effort and improve control reliability.
  • Ensure that changes to the regulatory environment or technology landscape trigger appropriate design reviews and service updates, maintaining a living control ecosystem.
  • Contribute to the DLO service catalog by ensuring controls are represented as managed services with defined inputs, outputs, SLAs, and continuous improvement mechanisms.
Basic Qualifications
  • Bachelorโ€™s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related technical field.
  • 10+ years of progressive experience in GRC, risk engineering, privacy engineering, or security architecture
  • 5+ years of experience focused on control design, implementation, or assurance at an enterprise scale.
Preferred Qualifications
  • Demonstrated ability to translate regulatory and policy requirements into technical control specifications and implementation guidance.
  • Experience influencing senior team members on control design decisions in a matrixed, federated operating model.
  • Experience with GRC platforms (ServiceNow IRM preferred) including control configuration, evidence management, and reporting design.
  • Deep solid understanding of privacy and AI regulatory frameworks (GDPR, NIST Privacy Framework, NIST AI RMF, EU AI Act, U.S. state privacy laws).
  • Experience developing and owning control maturity roadmaps, including defining maturity models, setting progression targets, and aligning investment to risk posture.
  • Experience operating within a federated risk model, enabling business control owners rather than implementing controls directly.
  • Strong verbal and written communication skills, with demonstrated ability to convey technical control design concepts to non-technical senior leaders.
  • Experience in regulated industriesโ€”pharmaceutical, healthcare, or life sciences strongly preferred.
  • Professional certification in privacy, risk, or security (e.g., CIPP/E, CIPT, CRISC, CISSP, CDPSE).
  • Experience with privacy-enhancing technologies (PETs), AI governance tooling, or data classification technologies.
  • Familiarity with ISO 27001/27701, SOC 2 controls, or equivalent control frameworks.
  • Experience scaling control capabilities across a large, matrixed enterprise with multiple lines of defense.
  • Hands-on experience with control automation, including workflow orchestration, API-based evidence collection, or AI-assisted monitoring.
  • Prior exposure to 2nd/3rd line of defense coordination (Internal Audit, Enterprise Risk, Quality).
  • Track record of partnering with cybersecurity engineering and architecture functions on shared control design.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.

Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.

Employee Resource Groups
  • Africa, Middle East, Central Asia (AMECA)
  • Black Employees at Lilly (BE@Lilly)
  • Chinese Culture Network (CCN)
  • EnAble
  • Evolve
  • Lilly Indian Network (LIN)
  • Organization of Latinx at Lilly (OLA)
  • Pride (LGBTQ+ Allies)
  • Veterans Leadership Network (VLN)
  • Womenโ€™s Initiative for Leading at Lilly (WILL)

Actual compensation will depend on a candidateโ€™s education, experience, skills, and geographic location.

The anticipated wage for this position is

$154,500 - $226,600

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance).

  • including eligibility to participate in a company-sponsored 401(k)
  • pension
  • vacation benefits
  • eligibility for medical, dental, vision and prescription drug benefits
  • flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts)
  • life insurance and death benefits
  • certain time off and leave of absence benefits
  • well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities)

Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lillyโ€™s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

#WeAreLilly

#J-18808-Ljbffr