1

Senior Technology Risk Management Jobs (NOW HIRING)

The Company's Records and Information Management (RIM) Program is part of the IT Governance, Risk and Compliance organization. In collaboration with various stakeholders, the RIM team supports the ...

The Risk team is responsible for Upstart's enterprise risk management program and risk governance ... As the Senior Manager, Technology Risk you will lead the second-line technology and information ...

Showing results 41-60

Senior Technology Risk Management information

See salary details

$22.5K

$118.3K

$210K

How much do senior technology risk management jobs pay per year?

As of Jul 26, 2026, the average yearly pay for senior technology risk management in the United States is $118,258.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,500.00 and $145,000.00 per year, depending on experience, location, and employer.

What does a technology risk manager do?

A technology risk manager identifies, assesses, and mitigates risks related to information technology and cybersecurity within an organization. They develop policies, implement controls, and monitor systems to ensure data security and compliance, often using tools like risk assessment frameworks and security protocols. Strong analytical skills and knowledge of industry standards such as ISO 27001 or NIST are essential for this role.

How much does a senior technology risk analyst make at Fidelity?

A senior technology risk analyst at Fidelity typically earns between $90,000 and $130,000 annually, depending on experience, location, and certifications. The role often requires knowledge of risk assessment tools and regulatory compliance standards.

What is the highest salary for a risk manager?

Senior Technology Risk Management professionals can earn salaries up to $150,000 or higher annually, depending on experience, certifications, and the size of the organization. Top earners in this field often have advanced skills in cybersecurity, compliance, and risk assessment, and may receive bonuses or other incentives.

How does a Senior Technology Risk Management professional typically collaborate with other departments within an organization?

A Senior Technology Risk Management professional regularly works with teams across IT, compliance, internal audit, and business units to identify, assess, and mitigate technology-related risks. This collaboration often involves participating in cross-functional meetings, providing guidance on risk controls, and ensuring that technology initiatives align with the overall risk appetite of the organization. Strong communication skills are essential, as the role requires translating complex technical risks into actionable recommendations for non-technical stakeholders. Building solid relationships with various departments is crucial to effectively manage and respond to emerging risks.

What are the key skills and qualifications needed to thrive as a Senior Technology Risk Management professional, and why are they important?

To thrive as a Senior Technology Risk Management professional, you need a deep understanding of IT risk frameworks, cybersecurity principles, and regulatory requirements, often supported by a degree in information security or related fields and certifications like CISA, CISSP, or CRISC. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and incident management systems is typically required. Strong analytical thinking, communication skills, and stakeholder management abilities help professionals excel in this role. These skills and qualities are vital for effectively identifying, assessing, and mitigating technology risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Senior Technology Risk Management vs Cybersecurity Analyst?

AspectSenior Technology Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, large enterprisesIT firms, government agencies, tech companies

While both roles focus on security, Senior Technology Risk Management emphasizes strategic risk assessment and mitigation planning, whereas Cybersecurity Analysts focus on technical security operations and incident response. The roles often collaborate but differ in scope and daily responsibilities.

What is the highest paying risk management job?

In risk management, senior roles such as Chief Risk Officer (CRO) or Director of Risk Management tend to have the highest salaries, often exceeding six figures annually. These positions require extensive experience, advanced certifications like FRM or CRM, and strong leadership skills, especially in financial services, insurance, or large corporations.

What is Senior Technology Risk Management?

Senior Technology Risk Management refers to a leadership role responsible for identifying, assessing, and mitigating technology-related risks within an organization. Professionals in this position develop risk management strategies, ensure compliance with regulations, and oversee the implementation of security controls to protect information systems. They collaborate with IT, business, and compliance teams to address vulnerabilities and respond to emerging threats. Their work helps safeguard critical assets and supports the organization's overall risk management framework.
More about Senior Technology Risk Management jobs
What cities are hiring for Senior Technology Risk Management jobs? Cities with the most Senior Technology Risk Management job openings:
What are the most commonly searched types of Technology Risk Management jobs? The most popular types of Technology Risk Management jobs are:
What states have the most Senior Technology Risk Management jobs? States with the most job openings for Senior Technology Risk Management jobs include:
Infographic showing various Senior Technology Risk Management job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, 1% Temporary, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $118,258 per year, or $56.9 per hour.
Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Northern Trust

Chicago, IL

$83K - $102K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Northern Trust rating

8.2

Company rating: 8.2 out of 10

Based on 27 frontline employees who took The Breakroom Quiz


Job description

About Northern Trust


As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world's most successful individuals, families, corporations and institutions.


Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.


With more than 135 years of financial experience and over 24,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.


Senior Lead, Technology Risk & Controls- SOX / SOC Programs

Summary:

You will joinNorthernTrust's Technology Risk and Control team as a leader responsible for overseeing the Technology SOX and SOC (SOC 1 / SOC 2) control programs across a global technology environment. This role partners closely with Technology leadership, Control Officers, Compliance, Internal Audit, External Audit, and Second Line of Defense (2LOD) partners to ensure the design, implementation, monitoring, and continuous improvement of technology controls supporting regulatory, financial reporting, and client assurance requirements.

As a trusted advisor to senior technology executives, you will provide subject matterexpertiseon IT General Controls (ITGCs), technology risk management, control maturity, audit readiness, and remediation strategies. You will drive enterprise-wide control excellence, lead interactions with external auditors, oversee complex remediation initiatives, and influence risk-informed decision-making across the global technology organization.

You will be part of a dedicated and high-performing team committed to strengthening control awareness, operational resilience, and risk governance throughout Northern Trust's technology environments.

Responsibilities:

  • Represent the Technology organization asliaisonforthe global SOX and SOCreport issuance, ensuring effective governance, control execution, audit readiness, and regulatory compliance.

  • Serve as the subject matter expert for Information Technology General Controls (ITGCs), including Access Management, Privileged Access Management, Change Management, System Development Lifecycle (SDLC), Information Produced by the Entity (IPE), Technology Operations, Automated Controls, and Cloud and Infrastructure Controls.

  • Lead and perform technology risk and control assessments across critical applications, infrastructure platforms, cybersecurity processes, cloud environments, and technology-enabled business services.

  • Drive control design reviews, control effectiveness assessments, maturity evaluations, and control optimization initiatives to improve the overall technology control environment.

  • Partner with technology executives, application owners, and control owners toidentify, assess, and remediate control deficiencies, audit findings, and regulatory issues through sustainable corrective action plans.

  • Adviseoncomplexremediation programs, including root cause analysis, corrective action planning, issue governance, and validation of remediation effectiveness.

  • Serve as the primary liaison for External Audit, Internal Audit, Compliance, and Risk Management functions by coordinating audit activities, leading walkthroughs, challenging audit observations whenappropriate, and ensuringtimelydelivery of evidence and management responses.

  • Monitor andadviseon SOXand SOC scoping activities, application onboarding, impact assessments, control changes, and implementation of new regulatory or audit requirements.

  • Support Control Officers in executive reporting, issue tracking and resolution, key risk indicator reporting, and risk appetite monitoring.

  • Review and challenge risk assessments, control documentation, management assertions, testing results, and deliverables prepared by team members and third-party partners.

  • Influence behaviors to reduce risk and foster a strong technology risk management culture throughout the enterprise.

  • Identifyopportunities to enhance control monitoring, analytics, automation, and continuous assurance capabilities.

Your Knowledge and Skills:

  • Deepexpertisein SOX, SOC 1, and SOC 2 compliance programs within complex technology environments.

  • Significant experienceexecuting risk assessments, control effectiveness assessments, inherent risk evaluations, and residual risk assessments.

  • Significant experienceevaluating and testing controls across technology domains including Identity and Access Management, Cloud Governance, Change Management, Software Development Lifecycle, Cybersecurity Operations, Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information Security, and IT Asset Management.

  • Excellent executive presentation skills, including preparation and delivery of materials for senior leadership, governance committees, and regulatory audiences.

  • Excellent written and verbal communication skills with the ability to influence and challenge senior stakeholders.

  • Significant experiencedeveloping and implementing Technology Risk and Control Frameworks, Risk and Control Matrices, and control monitoring programs.

  • Extensive experience managing relationships with External Auditors, Internal Audit, Compliance, and 2LOD Risk Management functions.

  • Proven ability to lead large-scale remediation initiatives, including root cause analysis, corrective action planning, and sustainable control implementation.

  • Strong understanding of industry frameworks and standards including COSO, COBIT, NIST, SOX, SOC 1, and SOC 2.

  • Experienceleveraginggovernance, risk, and compliance (GRC) platforms and workflow tools such as Archer, ServiceNow,AuditBoard, Power BI, or equivalent technologies.

Knowledge:

Recognized subject matter expert in Technology Risk Management, IT Controls, Audit, and Regulatory Compliance. Possesses extensive knowledge of technology control frameworks, financial reporting controls, information security principles, and risk management practices.

Demonstrates exceptional leadership, consultative, analytical, and communication capabilities with a proven ability to influence senior executives, technology leadership, auditors, regulators, and business stakeholders. Exercises independent judgment and leads highly visible, complex initiatives with enterprise-wide impact.

Experience:

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Accounting, Finance, ora relateddiscipline.

  • Minimum 10 years of progressive experience in Technology Risk Management, IT Audit, Information Security Risk Management, SOX / SOC Compliance, Technology Controls, or related fields.

  • Minimum 5 years of experience leading enterprise-wide SOX, SOC, IT Controls, or Technology Risk programs within highly regulated organizations, preferably in financial services.

  • Demonstrated experience influencing senior technology executives and driving risk-based decision-making across large organizations.

  • Significant experienceserving as the primary liaison with external auditors, including KPMG, PwC, EY, Deloitte, or equivalent, and leading audit readiness and remediation activities.

  • Proventrack recordleading complex, cross-functional remediation programs involving senior stakeholders and executive visibility.

  • Experience managing global teams, consultants, and third-party service providers.

Certifications:

  • Relevant industry recognized certification preferred, such as:Certified Information Systems Auditor (CISA);Certified Information Systems Security Professional (CISSP);Certified in Risk and Information Systems Control (CRISC); Certified Internal Auditor (CIA); Certified Public Accountant (CPA)

Salary Range:

$95,600 - 162,400 USD

Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.


Work Authorization


Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).


Working with Us


As a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.


Philanthropy is deeply rooted in Northern Trust's history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.


Reasonable Accommodation


Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com, or alternatively you can discuss your individual requirements with the recruiter you are working with.



What Northern Trust employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom