1

Senior Technology Risk Management Jobs in Rhode Island

Job Summary The Technology Risk Assessor is responsible for managing and assessing a portfolio of technology vendors, with a focus on vendor risk, performance, and overall value delivery. This role ...

next page

Showing results 1-20

Senior Technology Risk Management information

What are the key skills and qualifications needed to thrive as a Senior Technology Risk Management professional, and why are they important?

To thrive as a Senior Technology Risk Management professional, you need a deep understanding of IT risk frameworks, cybersecurity principles, and regulatory requirements, often supported by a degree in information security or related fields and certifications like CISA, CISSP, or CRISC. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and incident management systems is typically required. Strong analytical thinking, communication skills, and stakeholder management abilities help professionals excel in this role. These skills and qualities are vital for effectively identifying, assessing, and mitigating technology risks to protect organizational assets and ensure regulatory compliance.

How does a Senior Technology Risk Management professional typically collaborate with other departments within an organization?

A Senior Technology Risk Management professional regularly works with teams across IT, compliance, internal audit, and business units to identify, assess, and mitigate technology-related risks. This collaboration often involves participating in cross-functional meetings, providing guidance on risk controls, and ensuring that technology initiatives align with the overall risk appetite of the organization. Strong communication skills are essential, as the role requires translating complex technical risks into actionable recommendations for non-technical stakeholders. Building solid relationships with various departments is crucial to effectively manage and respond to emerging risks.

What is Senior Technology Risk Management?

Senior Technology Risk Management refers to a leadership role responsible for identifying, assessing, and mitigating technology-related risks within an organization. Professionals in this position develop risk management strategies, ensure compliance with regulations, and oversee the implementation of security controls to protect information systems. They collaborate with IT, business, and compliance teams to address vulnerabilities and respond to emerging threats. Their work helps safeguard critical assets and supports the organization's overall risk management framework.

How much does a senior technology risk analyst make at Fidelity?

A senior technology risk analyst at Fidelity typically earns between $90,000 and $130,000 annually, depending on experience, location, and certifications. Compensation may also include bonuses and benefits related to risk management and cybersecurity tools.

What is the difference between Senior Technology Risk Management vs Cybersecurity Analyst?

AspectSenior Technology Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, large enterprisesIT firms, government agencies, tech companies

While both roles focus on security, Senior Technology Risk Management emphasizes strategic risk assessment and mitigation planning, whereas Cybersecurity Analysts focus on technical security operations and incident response. The roles often collaborate but differ in scope and daily responsibilities.

What are the most commonly searched types of Technology Risk Management jobs in Rhode Island? The most popular types of Technology Risk Management jobs in Rhode Island are:
What job categories do people searching Senior Technology Risk Management jobs in Rhode Island look for? The top searched job categories for Senior Technology Risk Management jobs in Rhode Island are:
What cities in Rhode Island are hiring for Senior Technology Risk Management jobs? Cities in Rhode Island with the most Senior Technology Risk Management job openings:
Infographic showing various Senior Technology Risk Management job openings in Rhode Island as of May 2026, with employment types broken down into 1% As Needed, 84% Full Time, 10% Part Time, 3% Temporary, and 2% Contract. Highlights an 98% Physical, 1% Hybrid, and 1% Remote job distribution.
Technology Risk Director- Enterprise Engineering

Technology Risk Director- Enterprise Engineering

Citizens

Johnston, RI • Remote

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 23 days ago


Job description

The Enterprise Technology & Security (ETS) Risk Director directs a team of risk professionals, developing comprehensive risk management strategies, and ensuring the organization's technology risk practices are robust, effective, and aligned with industry standards and regulatory requirements. This executive-level position provides strategic leadership over a dedicated ETS risk function, setting the direction for risk identification, assessment, and mitigation across the bank's technology and security domains. The Director serves as a key advisor to senior leadership on technology risk matters, drives the maturation of the enterprise risk framework, and maintains strong relationships with regulators, audit, and governance bodies.

Responsibilities

  • Lead and oversee the Technology Risk Management function, providing strategic direction to a team of risk professionals and fostering a culture of accountability, excellence, and continuous improvement.

  • Develop, implement, and continuously evolve a comprehensive technology risk management strategy and framework aligned with enterprise risk appetite, regulatory expectations, and industry best practices.

  • Oversee the identification, assessment, monitoring, and reporting of technology and security risks across systems, applications, infrastructure, and processes.

  • Serve as the primary executive liaison for regulatory examinations, internal audits, and supervisory engagements related to technology and security risk, ensuring effective coordination and highquality outcomes.

  • Define and maintain technology risk policies, standards, control libraries, and assessment methodologies to support consistent and scalable risk management practices.

  • Partner with senior technology leaders, business executives, compliance, audit, and governance teams to embed risk management into strategic planning and decisionmaking.

  • Provide clear, actionable, executivelevel risk reporting and insights to the Risk Committees and senior management, translating complex risk landscapes into strategic guidance.

  • Oversee the portfolio of risk findings, regulatory commitments, and corrective action plans, driving timely, effective, and sustainable remediation.

  • Lead oversight of Third-Party Risk Management for the organization's technology and security critical service provider relationships.

  • Monitor industry trends, emerging threats, and regulatory developments to proactively adjust the organization's risk posture.

  • Champion a strong riskaware and riskinformed culture across the technology organization through education, engagement, and communication.

Team-Specific Requirements

Cloud & Modern Engineering Platforms

  • Working knowledge of cloud services and architectures (AWS and Azure preferred), including shared responsibility models, identity and access management, and cloudnative security controls.

  • Experience assessing risk in DevSecOps, CI/CD pipelines, containerized workloads (Docker/Kubernetes), and infrastructureascode environments.

Infrastructure, Platform & Engineering Risk

  • Strong understanding of enterprise infrastructure platforms, including Windows, Linux (RHEL), virtualization (VMware), databases, middleware, and core network services.

  • Experience evaluating endoflife (EOL) / endofsupport (EOS) risk, technical debt, and remediation prioritization across large engineering estates.

Cybersecurity & Resilience

  • Handson familiarity with vulnerability management, platform hardening, secure configuration standards, and threat remediation prioritization.

  • Experience with technology resilience, including BCP/DR, cyber recovery, data protection, backup strategies, and resiliency testing.
  • Ability to translate engineering and cyber risks into business impact, service disruption, regulatory exposure, and customer risk.

Risk Frameworks & Governance

  • Deep experience with enterprise technology risk management routines, including RCSAs, issue management, risk assessments, targeted reviews, and control testing.

  • Working knowledge of regulatory and risk frameworks relevant to financial institutions (FFIEC, NIST, ISO, COBIT, COSO, CRI).
  • Proven ability to synthesize large volumes of technical risk data into clear, prioritized executivelevel insights.

Risk, Issue, and Compliance Management

  • Experience using GRC Archer (or equivalent platforms such as OpenPages) to manage RCSAs, issues, action plans, metrics, and regulatory responses.

  • Familiarity with risk reporting, risk dashboards, and executivelevel risk metrics.

Engineering, Security & ITSM Tooling

  • Working knowledge of common enterprise tooling used by engineering and cyber teams, such as ServiceNow, Jira, and Confluence, to support risk intake, issue tracking, and remediation monitoring.

  • Familiarity with vulnerability and security tools such as Qualys, Wiz, CrowdStrike, CyberArk, Splunk, or similar platforms to support effective oversight and challenge.

Monitoring & Reporting

  • Exposure to engineering and operational monitoring platforms (e.g., DataDog, Grafana, Tableau, Power BI), with the ability to interpret signals, trends, and risk indicators rather than operate the tools directly.

Experience & Skills

Required:

  • 12+ years of progressive experience in IT risk management, information security, or internal audit, including 5+ years in a senior leadership role.

  • Demonstrated executive leadership experience, including building and developing high-performing risk teams in complex, regulated environments.

  • Comprehensive expertise in risk frameworks including CRI Profile, NIST 800-53, NIST CSF, COBIT, and ITIL, with a track record of applying them at an enterprise scale.

  • Deep familiarity with regulatory expectations and supervisory frameworks applicable to regional banks (OCC, Federal Reserve, FDIC).

  • Exceptional communication and influencing skills; proven ability to present risk strategy and findings to Board-level and executive audiences.

  • Experience leading large-scale regulatory examinations, audit engagements, and enterprise-wide corrective action programs.

  • Proven ability to set strategic direction, manage organizational priorities, and deliver results in a fast-paced, evolving environment.

Preferred:

  • Prior experience as a risk director or equivalent executive in a federally regulated financial institution.

  • Track record of building or transforming enterprise-level technology risk programs.

  • Strong network within the financial services risk and technology community.

Education

  • Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field required; Master's degree (MBA, MS in Cybersecurity, or equivalent) strongly preferred.
  • One or more of the following certifications are preferred:
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)

Hours & Work Schedule

  • Hours per Week: 40 
  • Work Schedule: Monday-Friday
  • Hybrid: 4 days per week onsite, 1 day remote

Pay Transparency

The salary range for this position is $190,000 - $240,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to the work location, and relevant skills and experience.

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens' paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits .

#LI-Citizens1

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Equal Employment and Opportunity Employer

Job Applicant Data Privacy Policy

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.