Lead and oversee the Technology Risk Management function, providing strategic direction to a team of risk professionals and fostering a culture of accountability, excellence, and continuous ...
Lead and oversee the Technology Risk Management function, providing strategic direction to a team of risk professionals and fostering a culture of accountability, excellence, and continuous ...
Lead and oversee the Technology Risk Management function, providing strategic direction to a team of risk professionals and fostering a culture of accountability, excellence, and continuous ...
Lead and oversee the Technology Risk Management function, providing strategic direction to a team of risk professionals and fostering a culture of accountability, excellence, and continuous ...
Cybersecurity Risk Management & Oversight * Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and ...
Cybersecurity Risk Management & Oversight * Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and ...
Cybersecurity Risk Management & Oversight * Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and ...
Cybersecurity Risk Management & Oversight * Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and ...
Essential Duties and Responsibilities: * IT SOX Audit Management: * Manage the IT compliance ... Conduct regular risk assessments and control evaluations across IT systems and processes.
Essential Duties and Responsibilities: * IT SOX Audit Management: * Manage the IT compliance ... Conduct regular risk assessments and control evaluations across IT systems and processes.
Associate - Tech Risk & Control
Phoenix, AZ ยท On-site
Role Overview As an Associate Technology Risk Manager in CPD, you will orchestrate delivery of cross GI risk artifacts, such as MAPs, OREs, and PSRs, when inputs span multiple teams or responsibility ...
Associate - Tech Risk & Control
Phoenix, AZ ยท On-site
Role Overview As an Associate Technology Risk Manager in CPD, you will orchestrate delivery of cross GI risk artifacts, such as MAPs, OREs, and PSRs, when inputs span multiple teams or responsibility ...
Associate - Tech Risk & Control
Phoenix, AZ ยท On-site
$78K - $124K/yr
Role Overview As an Associate Technology Risk Manager in CPD, you will orchestrate delivery of cross GI risk artifacts, such as MAPs, OREs, and PSRs, when inputs span multiple teams or responsibility ...
Associate - Tech Risk & Control
Phoenix, AZ ยท On-site
$78K - $124K/yr
Role Overview As an Associate Technology Risk Manager in CPD, you will orchestrate delivery of cross GI risk artifacts, such as MAPs, OREs, and PSRs, when inputs span multiple teams or responsibility ...
IT Manager II - IT Governance, Risk and Controls
Phoenix, AZ ยท On-site
$94K - $115K/yr
The position is responsible for supporting and executing IT risk management activities aligned with the Company's Risk Appetite and Corporate Strategy. You will partner with IT leadership, other Risk ...
IT Manager II - IT Governance, Risk and Controls
Phoenix, AZ ยท On-site
$94K - $115K/yr
The position is responsible for supporting and executing IT risk management activities aligned with the Company's Risk Appetite and Corporate Strategy. You will partner with IT leadership, other Risk ...
IT Manager II - IT Governance, Risk and Controls
Phoenix, AZ ยท On-site
$94K - $115K/yr
The position is responsible for supporting and executing IT risk management activities aligned with the Company's Risk Appetite and Corporate Strategy. You will partner with IT leadership, other Risk ...
IT Manager II - IT Governance, Risk and Controls
Phoenix, AZ ยท On-site
$94K - $115K/yr
The position is responsible for supporting and executing IT risk management activities aligned with the Company's Risk Appetite and Corporate Strategy. You will partner with IT leadership, other Risk ...
IT Risk Manager
Scottsdale, AZ ยท Hybrid
Partner with Enterprise Risk Management in the execution of Risk and Control Self Assessments. * Own and maintain the business-line's detailed process and technical recovery plans. * Partner with ...
IT Risk Manager
Scottsdale, AZ ยท Hybrid
Partner with Enterprise Risk Management in the execution of Risk and Control Self Assessments. * Own and maintain the business-line's detailed process and technical recovery plans. * Partner with ...
IT Risk Manager
Scottsdale, AZ ยท On-site
Partner with Enterprise Risk Management in the execution of Risk and Control Self Assessments. * Own and maintain the business-line's detailed process and technical recovery plans. * Partner with ...
IT Risk Manager
Scottsdale, AZ ยท On-site
Partner with Enterprise Risk Management in the execution of Risk and Control Self Assessments. * Own and maintain the business-line's detailed process and technical recovery plans. * Partner with ...
Information Risk Management, Vice President
Tempe, AZ ยท Hybrid
$125K - $164K/yr
This means investing in talent, technologies, and tools that empower you to own your career. Join ... Support coordination with global related entities' risk management harmonization efforts in order ...
Information Risk Management, Vice President
Tempe, AZ ยท Hybrid
$125K - $164K/yr
This means investing in talent, technologies, and tools that empower you to own your career. Join ... Support coordination with global related entities' risk management harmonization efforts in order ...
Bachelor's degree required in technology, engineering, risk management, computer science, information systems, or equivalent field. * Experience with key risks associated to Dev/Sec/Ops, deployment ...
Bachelor's degree required in technology, engineering, risk management, computer science, information systems, or equivalent field. * Experience with key risks associated to Dev/Sec/Ops, deployment ...
Risk Treatment Specialist
Tempe, AZ ยท On-site
$108K - $185K/yr
Operational Risk, Financial Risk, Cyber Resilience, Cybersecurity, Risk Management, IT Risk and Control, and/or IT Audit * Strong working knowledge of the inherent risks in the financial services ...
Risk Treatment Specialist
Tempe, AZ ยท On-site
$108K - $185K/yr
Operational Risk, Financial Risk, Cyber Resilience, Cybersecurity, Risk Management, IT Risk and Control, and/or IT Audit * Strong working knowledge of the inherent risks in the financial services ...
Sr. IT Risk Manager
Scottsdale, AZ ยท On-site
Third-Party Management * Guide business partners through governance processes related to new products and services, initiatives, and vendors including support documentation of associated risk ...
Sr. IT Risk Manager
Scottsdale, AZ ยท On-site
Third-Party Management * Guide business partners through governance processes related to new products and services, initiatives, and vendors including support documentation of associated risk ...
Sr. IT Risk Manager
Scottsdale, AZ ยท Hybrid
Third-Party Management * Guide business partners through governance processes related to new products and services, initiatives, and vendors including support documentation of associated risk ...
Sr. IT Risk Manager
Scottsdale, AZ ยท Hybrid
Third-Party Management * Guide business partners through governance processes related to new products and services, initiatives, and vendors including support documentation of associated risk ...
Governance Risk Analyst
$68.75 - $86/hr
... IT risk management programs while leveraging automation, scripting, and reporting tools to enhance governance processes and control execution. Key Responsibilities Support governance, risk, and ...
Governance Risk Analyst
$68.75 - $86/hr
... IT risk management programs while leveraging automation, scripting, and reporting tools to enhance governance processes and control execution. Key Responsibilities Support governance, risk, and ...
Job Summary The Director, Risk Management oversees the development and implementation of risk ... Evaluates and implements new technologies to enhance operational efficiency. * Develops and ...
Job Summary The Director, Risk Management oversees the development and implementation of risk ... Evaluates and implements new technologies to enhance operational efficiency. * Develops and ...
Job Summary The Director, Risk Management oversees the development and implementation of risk ... Evaluates and implements new technologies to enhance operational efficiency. * Develops and ...
Job Summary The Director, Risk Management oversees the development and implementation of risk ... Evaluates and implements new technologies to enhance operational efficiency. * Develops and ...
TheSenior Technology RiskAnalystis expected to manage and mature the enterprise risk register and drive highquality risk assessments across new and existing information system capabilities.
TheSenior Technology RiskAnalystis expected to manage and mature the enterprise risk register and drive highquality risk assessments across new and existing information system capabilities.
Technology Risk Management information
See Arizona salary details
$40.5K - $51K
8% of jobs
$51K - $61.5K
14% of jobs
$66.4K is the 25th percentile. Wages below this are outliers.
$61.5K - $72.1K
6% of jobs
$72.1K - $82.6K
8% of jobs
$82.6K - $93.1K
11% of jobs
The median wage is $95.3K / yr.
$93.1K - $103.6K
13% of jobs
$103.6K - $114.1K
11% of jobs
$117.3K is the 75th percentile. Wages above this are outliers.
$114.1K - $124.6K
15% of jobs
$124.6K - $135.1K
8% of jobs
$135.1K - $145.6K
4% of jobs
$145.6K - $156.1K
2% of jobs
$40.5K
$96.6K
$156.1K
How much do technology risk management jobs pay per year?
What is a Technology Risk Management job?
A Technology Risk Management job involves identifying, assessing, and mitigating risks related to an organization's technology infrastructure, systems, and data. Professionals in this field develop policies, ensure compliance with regulatory requirements, and implement security controls to protect against cyber threats and operational failures. They collaborate with IT, security, and business teams to address vulnerabilities and enhance resilience. The role requires knowledge of risk assessment frameworks, regulatory standards, and emerging technology risks.
What are the key skills and qualifications needed to thrive in the Technology Risk Management position, and why are they important?
To excel in Technology Risk Management, you need a background in information security, risk assessment, and regulatory compliance, often supported by a relevant degree and experience in IT or cybersecurity. Familiarity with risk management frameworks (such as NIST or ISO 27001), governance, risk and compliance (GRC) tools, and certifications like CISA, CISSP, or CRISC are highly valued. Strong analytical thinking, communication skills, and the ability to influence and collaborate across departments are vital soft skills for this role. These competencies are crucial to effectively identify, mitigate, and communicate technology risks, helping organizations manage threats while ensuring business continuity and compliance.
What does technology risk management do?
What is the highest paying risk management job?
Is risk management a good career?
What are the typical daily responsibilities for someone working in Technology Risk Management?
Professionals in Technology Risk Management are typically responsible for identifying and assessing potential technology-related risks, developing policies and controls to mitigate those risks, and monitoring compliance with internal and external regulations. Their day-to-day activities often include conducting risk assessments, coordinating with IT teams on security initiatives, preparing reports for senior management, and responding to incidents or audit findings. Collaboration with various departments such as IT, compliance, and business units is frequent to ensure comprehensive risk oversight. This role requires staying up-to-date on emerging threats and evolving regulatory requirements to proactively manage the organization's risk posture.
How much do technology risk consultants make?

Other
Medical, Dental, Vision, Retirement, PTO
Posted 12 days ago
Job description
Description
The Enterprise Technology & Security (ETS) Risk Director directs a team of risk professionals, developing comprehensive risk management strategies, and ensuring the organization's technology risk practices are robust, effective, and aligned with industry standards and regulatory requirements. This executive-level position provides strategic leadership over a dedicated ETS risk function, setting the direction for risk identification, assessment, and mitigation across the bank's technology and security domains. The Director serves as a key advisor to senior leadership on technology risk matters, drives the maturation of the enterprise risk framework, and maintains strong relationships with regulators, audit, and governance bodies.
Responsibilities
Lead and oversee the Technology Risk Management function, providing strategic direction to a team of risk professionals and fostering a culture of accountability, excellence, and continuous improvement.
Develop, implement, and continuously evolve a comprehensive technology risk management strategy and framework aligned with enterprise risk appetite, regulatory expectations, and industry best practices.
Oversee the identification, assessment, monitoring, and reporting of technology and security risks across systems, applications, infrastructure, and processes.
Serve as the primary executive liaison for regulatory examinations, internal audits, and supervisory engagements related to technology and security risk, ensuring effective coordination and highquality outcomes.
Define and maintain technology risk policies, standards, control libraries, and assessment methodologies to support consistent and scalable risk management practices.
Partner with senior technology leaders, business executives, compliance, audit, and governance teams to embed risk management into strategic planning and decisionmaking.
Provide clear, actionable, executivelevel risk reporting and insights to the Risk Committees and senior management, translating complex risk landscapes into strategic guidance.
Oversee the portfolio of risk findings, regulatory commitments, and corrective action plans, driving timely, effective, and sustainable remediation.
Lead oversight of Third-Party Risk Management for the organization's technology and security critical service provider relationships.
Monitor industry trends, emerging threats, and regulatory developments to proactively adjust the organization's risk posture.
Champion a strong riskaware and riskinformed culture across the technology organization through education, engagement, and communication.
Team-Specific Requirements
Cloud & Modern Engineering Platforms
Working knowledge of cloud services and architectures (AWS and Azure preferred), including shared responsibility models, identity and access management, and cloudnative security controls.
Experience assessing risk in DevSecOps, CI/CD pipelines, containerized workloads (Docker/Kubernetes), and infrastructureascode environments.
Infrastructure, Platform & Engineering Risk
Strong understanding of enterprise infrastructure platforms, including Windows, Linux (RHEL), virtualization (VMware), databases, middleware, and core network services.
Experience evaluating endoflife (EOL) / endofsupport (EOS) risk, technical debt, and remediation prioritization across large engineering estates.
Cybersecurity & Resilience
Handson familiarity with vulnerability management, platform hardening, secure configuration standards, and threat remediation prioritization.
- Experience with technology resilience, including BCP/DR, cyber recovery, data protection, backup strategies, and resiliency testing.
Ability to translate engineering and cyber risks into business impact, service disruption, regulatory exposure, and customer risk.
Risk Frameworks & Governance
Deep experience with enterprise technology risk management routines, including RCSAs, issue management, risk assessments, targeted reviews, and control testing.
- Working knowledge of regulatory and risk frameworks relevant to financial institutions (FFIEC, NIST, ISO, COBIT, COSO, CRI).
Proven ability to synthesize large volumes of technical risk data into clear, prioritized executivelevel insights.
Risk, Issue, and Compliance Management
Experience using GRC Archer (or equivalent platforms such as OpenPages) to manage RCSAs, issues, action plans, metrics, and regulatory responses.
Familiarity with risk reporting, risk dashboards, and executivelevel risk metrics.
Engineering, Security & ITSM Tooling
Working knowledge of common enterprise tooling used by engineering and cyber teams, such as ServiceNow, Jira, and Confluence, to support risk intake, issue tracking, and remediation monitoring.
Familiarity with vulnerability and security tools such as Qualys, Wiz, CrowdStrike, CyberArk, Splunk, or similar platforms to support effective oversight and challenge.
Monitoring & Reporting
Exposure to engineering and operational monitoring platforms (e.g., DataDog, Grafana, Tableau, Power BI), with the ability to interpret signals, trends, and risk indicators rather than operate the tools directly.
Experience & Skills
Required:
12+ years of progressive experience in IT risk management, information security, or internal audit, including 5+ years in a senior leadership role.
Demonstrated executive leadership experience, including building and developing high-performing risk teams in complex, regulated environments.
Comprehensive expertise in risk frameworks including CRI Profile, NIST 800-53, NIST CSF, COBIT, and ITIL, with a track record of applying them at an enterprise scale.
Deep familiarity with regulatory expectations and supervisory frameworks applicable to regional banks (OCC, Federal Reserve, FDIC).
Exceptional communication and influencing skills; proven ability to present risk strategy and findings to Board-level and executive audiences.
Experience leading large-scale regulatory examinations, audit engagements, and enterprise-wide corrective action programs.
Proven ability to set strategic direction, manage organizational priorities, and deliver results in a fast-paced, evolving environment.
Preferred:
Prior experience as a risk director or equivalent executive in a federally regulated financial institution.
Track record of building or transforming enterprise-level technology risk programs.
Strong network within the financial services risk and technology community.
Education
- Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field required; Master's degree (MBA, MS in Cybersecurity, or equivalent) strongly preferred.
- One or more of the following certifications are preferred:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
Hours & Work Schedule
- Hours per Week: 40ย
- Work Schedule: Monday-Friday
- Hybrid: 4 days per week onsite, 1 day remote
Pay Transparency
The salary range for this position is $190,000 - $240,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to the work location, and relevant skills and experience.
We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens' paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits .
#LI-Citizens1
Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.
Equal Employment Opportunity
Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.
Education:Why Work for UsEmployment Type: 1ST