Technology Risk and Governance
$110K - $315K/yr
This role is a key contributor to enterprise risk management, partnering with the Chief Compliance Officer and risk owners to ensure technology risks are identified, documented, reported, and ...
$110K - $315K/yr
This role is a key contributor to enterprise risk management, partnering with the Chief Compliance Officer and risk owners to ensure technology risks are identified, documented, reported, and ...
$110K - $315K/yr
This role is a key contributor to enterprise risk management, partnering with the Chief Compliance Officer and risk owners to ensure technology risks are identified, documented, reported, and ...
Boston, MA · On-site
Your secondary responsibility within the Technology Risk Group, will be to assist the Vendor Risk Manager in supporting the Third Party Risk Assessment process. In this role, you will review the ...
Boston, MA · On-site
Your secondary responsibility within the Technology Risk Group, will be to assist the Vendor Risk Manager in supporting the Third Party Risk Assessment process. In this role, you will review the ...
Boston, MA · On-site +1
$140K - $150K/yr
DE performing risk management and IT audits, and implementing ITGC or cybersecurity controls for ... Category:Information Technology Please be advised that Fidelity's business is governed by the ...
Boston, MA · On-site +1
$140K - $150K/yr
DE performing risk management and IT audits, and implementing ITGC or cybersecurity controls for ... Category:Information Technology Please be advised that Fidelity's business is governed by the ...
Boston, MA · On-site
$140K - $150K/yr
DE performing risk management and IT audits, and implementing ITGC or cybersecurity controls for ... Category: Information Technology Please be advised that Fidelity's business is governed by the ...
Boston, MA · On-site
$140K - $150K/yr
DE performing risk management and IT audits, and implementing ITGC or cybersecurity controls for ... Category: Information Technology Please be advised that Fidelity's business is governed by the ...
$129K - $137K/yr
Supports enterprise risk management by partnering with technology domains to assess the effectiveness of controls, implements automated monitoring and data analysis solutions to identify emerging ...
$129K - $137K/yr
Supports enterprise risk management by partnering with technology domains to assess the effectiveness of controls, implements automated monitoring and data analysis solutions to identify emerging ...
Boston, MA · On-site
$129K - $137K/yr
Supports enterprise risk management by partnering with technology domains to assess the effectiveness of controls, implements automated monitoring and data analysis solutions to identify emerging ...
Boston, MA · On-site
$129K - $137K/yr
Supports enterprise risk management by partnering with technology domains to assess the effectiveness of controls, implements automated monitoring and data analysis solutions to identify emerging ...
We are conducting a confidential search for a large, publicly traded global technology company seeking a Lead / Manager, IT Audit & Technology Risk. This is a high-visibility opportunity to help ...
New
Quick apply
We are conducting a confidential search for a large, publicly traded global technology company seeking a Lead / Manager, IT Audit & Technology Risk. This is a high-visibility opportunity to help ...
New
$125K - $180K/yr
We are conducting a confidential search for a large, publicly traded global technology company seeking a Lead / Manager, IT Audit & Technology Risk. This is a high-visibility opportunity to help ...
New
$125K - $180K/yr
We are conducting a confidential search for a large, publicly traded global technology company seeking a Lead / Manager, IT Audit & Technology Risk. This is a high-visibility opportunity to help ...
New
Enterprise Risk Management is hiring a Head of Cyber & Technology Risk to assist in strengthening the technology risk and control environment that protects the firm's systems, data, and operations.
Enterprise Risk Management is hiring a Head of Cyber & Technology Risk to assist in strengthening the technology risk and control environment that protects the firm's systems, data, and operations.
Enterprise Risk Management is hiring a Head of Cyber & Technology Risk to assist in strengthening the technology risk and control environment that protects the firm's systems, data, and operations.
Enterprise Risk Management is hiring a Head of Cyber & Technology Risk to assist in strengthening the technology risk and control environment that protects the firm's systems, data, and operations.
We are working on a confidential search for a Manager / Lead-level Technology Risk & IT Transformation professional to join the internal risk and controls function of a well-established global ...
New
Quick apply
We are working on a confidential search for a Manager / Lead-level Technology Risk & IT Transformation professional to join the internal risk and controls function of a well-established global ...
New
Understand the impact of key technology trends and workforce changes impacting our clients through ... Credit Risk, Liquidity Risk, Market Risk, Capital Management/Stress Testing * Knowledge of ...
Understand the impact of key technology trends and workforce changes impacting our clients through ... Credit Risk, Liquidity Risk, Market Risk, Capital Management/Stress Testing * Knowledge of ...
This role focuses on transforming how organizations manage IT risk, controls, and regulatory compliance through operating model optimization, advanced technology enablement, and integrated risk ...
This role focuses on transforming how organizations manage IT risk, controls, and regulatory compliance through operating model optimization, advanced technology enablement, and integrated risk ...
Required : • 6+ years of experience in cybersecurity risk management, information security, technology risk, or a related field. • Demonstrated experience conducting structured cybersecurity or ...
Required : • 6+ years of experience in cybersecurity risk management, information security, technology risk, or a related field. • Demonstrated experience conducting structured cybersecurity or ...
Client Delivery - Support workplans, manage assigned tasks, gather requirements, and contribute to ... delivery of technology solutions, with exposure to AI/ML or GenAI and experience in risk ...
Client Delivery - Support workplans, manage assigned tasks, gather requirements, and contribute to ... delivery of technology solutions, with exposure to AI/ML or GenAI and experience in risk ...
Boston, MA · On-site
$90K - $115K/yr
Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...
Boston, MA · On-site
$90K - $115K/yr
Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...
Client Delivery -- Support workplans, manage assigned tasks, gather requirements, and contribute to ... delivery of technology solutions, with exposure to AI/ML or GenAI and experience in risk ...
Client Delivery -- Support workplans, manage assigned tasks, gather requirements, and contribute to ... delivery of technology solutions, with exposure to AI/ML or GenAI and experience in risk ...
Weekly Pay: Get paid every week so that you can manage your money on your terms. * Free BJ's ... Reports To : VP, IT Security and Compliance Team Size : Leads a team of compliance, risk, and ...
Weekly Pay: Get paid every week so that you can manage your money on your terms. * Free BJ's ... Reports To : VP, IT Security and Compliance Team Size : Leads a team of compliance, risk, and ...
This role involves overseeing technology risk management, third-party risk, and developing risk intelligence capabilities. Responsibilities : • Lead the transition of risk management from a cyber ...
This role involves overseeing technology risk management, third-party risk, and developing risk intelligence capabilities. Responsibilities : • Lead the transition of risk management from a cyber ...
Sr. Associate, Technology Infrastructure Business Control & Risk Management Country: United States ... Certified Information Security Manager (CISM) * Certified Business Continuity Professional (CBCP)
Sr. Associate, Technology Infrastructure Business Control & Risk Management Country: United States ... Certified Information Security Manager (CISM) * Certified Business Continuity Professional (CBCP)
$56.2K - $68K
4% of jobs
$68K - $79.8K
6% of jobs
$79.8K - $91.5K
11% of jobs
$96K is the 25th percentile. Wages below this are outliers.
$91.5K - $103.3K
11% of jobs
The median wage is $112.7K / yr.
$103.3K - $115.1K
23% of jobs
$115.1K - $126.8K
13% of jobs
$134.6K is the 75th percentile. Wages above this are outliers.
$126.8K - $138.6K
12% of jobs
$138.6K - $150.4K
8% of jobs
$150.4K - $162.1K
6% of jobs
$162.1K - $173.9K
4% of jobs
$173.9K - $185.7K
2% of jobs
$56.2K
$121.8K
$185.7K
| Aspect | Technology Risk Manager | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISA | CISSP, CEH, Security+ |
| Work Environment | Risk assessment, policy development, compliance | Monitoring security threats, incident response, vulnerability analysis |
| Industry Usage | Financial, healthcare, technology firms | IT security teams, government agencies, corporations |
The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

$110K - $315K/yr
Full-time
Posted 10 days ago
Job Overview
The position reports to the Chief Information Security Officer and leads the enterprise-wide technology risk and governance program. This role establishes the risk framework, policies, and governance needed to identify, assess, and mitigate risk across IT services, platforms, and third parties.
Partnering with senior leadership across Technology, Cyber Security, Compliance, Legal, and business, the role translates complex technical and control issues into clear business risk narratives (operational, regulatory, reputational, and financial) and drives risk-based prioritization of remediation.
The position owns the technology risk policy suite and associated standards and oversees the technological aspects of the third-party risk program, including vendor onboarding due diligence and ongoing monitoring in partnership with Compliance and procurement stakeholders.
This role is a key contributor to enterprise risk management, partnering with the Chief Compliance Officer and risk owners to ensure technology risks are identified, documented, reported, and addressed through effective controls, risk acceptance, and continuous improvement. It also evaluates and implements tools and reporting to increase risk visibility and strengthen governance.
Responsibilities
Own the enterprise technology risk framework and governance model, aligned to the organization's enterprise risk framework.
Provide advisory support for material technology decisions (new systems, products, vendors, and significant changes), translating technical and control issues into business impact.
Establish clear governance and reporting for senior management and committees on material IT, cyber, third-party, and emerging technology risks, including key risk indicators and metrics.
Design and continuously improve technology risk assessment and control evaluation processes, including remediation tracking and governance for risk acceptance, waivers, and exceptions.
Lead and mature AI risk governance in partnership with IT, Security, Compliance, and the business.
Support enterprise data governance initiatives (classification, retention, and handling) in collaboration with Technology and business stakeholders.
Own the technology risk policy suite and standards, ensuring they are implemented, reviewed regularly, and supported through training and awareness.
Oversee technology aspects of third-party risk, including onboarding due diligence, review of assurance (e.g., SOC reports), remediation tracking, and ongoing monitoring in partnership with Compliance and procurement stakeholders.
Partner with Cyber Security to ensure threat, vulnerability, patch, and incident risk governance aligns to the current threat landscape and control expectations.
Drive operational resilience for technology services, including business continuity planning, crisis/incident governance, root-cause analysis, and lessons learned.
Support client, regulator, and internal audit engagements related to technology risk, including responses to inquiries and evidence of control design and effectiveness.
Qualifications
Experience leading technology risk, IT risk, cyber/operational risk, or technology governance in a regulated environment.
Demonstrated ability to design and implement risk frameworks and governance processes, including assessment, prioritization, remediation tracking, and risk acceptance.
Broad technical knowledge across enterprise IT (infrastructure, applications, identity and access management, cloud/SaaS, and data governance) and how controls mitigate risk.
Strong stakeholder management skills with a track record of influencing senior leaders and driving outcomes across Technology, Compliance, Legal, and Internal Audit.
Excellent written, verbal, and presentation skills; able to communicate complex technical risk issues clearly to executives and governance committees.
Experience in developing and defining enterprise risk level appetite, tolerance thresholds, and escalation criteria.
Ability to challenge control owners constructively and drive accountability and remediation.
Preferred
Familiarity with industry regulations and standards (SOX, PCI, DORA) and technical frameworks (e.g., NIST, ISO 27001) and attack frameworks (e.g., MITRE ATT&CK or similar).
Experience interacting directly with regulators, auditors, and board risk committees.
Understanding of secure software development and application security risks
The base salary range for this position is $110,000 - $315,000 per year.
Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture.Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate's base salary placement within the listed range will vary based on the candidate's relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process.
Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world.
All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.
Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability, contact us to discuss the nature of your request and contact information.
Sourced by ZipRecruiter
201 - 500 Employees
Boston, MA, US
1999