As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk ...
IT Risk and Compliance Analyst
Portland, OR · On-site
$99K - $100K/yr
The ideal candidate will be responsible for ensuring that IT risk management processes are embedded in the enterprise, enabling optimal risk assessments returns. This role involves supporting IT risk ...
Quick apply
IT Risk and Compliance Analyst
Portland, OR · On-site
$99K - $100K/yr
The ideal candidate will be responsible for ensuring that IT risk management processes are embedded in the enterprise, enabling optimal risk assessments returns. This role involves supporting IT risk ...
As an IT Audit Manager or Senior Manager, you will lead, manage, and develop a team of IT auditors in the planning and execution of IT, cybersecurity, and technology risk audits using a risk-based ...
As an IT Audit Manager or Senior Manager, you will lead, manage, and develop a team of IT auditors in the planning and execution of IT, cybersecurity, and technology risk audits using a risk-based ...
IT Security Risk Management Analyst
Odell, OR · On-site
... ation Security Governance Work Shift: Day Work Days: MON-FRI Scheduled Hours: 8:30 AM-5 PM Scheduled Daily Hours: 8 HOURS Pay Range: $96,000.00-$120,000.00 The Security Risk Management Analyst will ...
IT Security Risk Management Analyst
Odell, OR · On-site
... ation Security Governance Work Shift: Day Work Days: MON-FRI Scheduled Hours: 8:30 AM-5 PM Scheduled Daily Hours: 8 HOURS Pay Range: $96,000.00-$120,000.00 The Security Risk Management Analyst will ...
Financial Risk Manager
Portland, OR · On-site
Partner with internalstakeholders (Treasury, Legal, Finance, Operations, IT) to define ... risk management or corporate insurance * Hands-on experience implementing ormaterially supporting a ...
Financial Risk Manager
Portland, OR · On-site
Partner with internalstakeholders (Treasury, Legal, Finance, Operations, IT) to define ... risk management or corporate insurance * Hands-on experience implementing ormaterially supporting a ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Enterprise Risk Management: Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving mitigation strategies aligned with business objectives. * Evaluate ...
Principal Program Manager, Tech Risk (BC/DR)
OR · On-site +1
Drive cross-functional execution across Technology, Security, Office Operations, Vendor Management, Enterprise Risk Management, Compliance, and business process owners to ensure continuity and ...
Principal Program Manager, Tech Risk (BC/DR)
OR · On-site +1
Drive cross-functional execution across Technology, Security, Office Operations, Vendor Management, Enterprise Risk Management, Compliance, and business process owners to ensure continuity and ...
SUMMARY The IT Risk Analyst II is responsible for measuring and identifying technical risks within ... Capable of managing varied assignments and working independently. * Ability to define problems ...
New
SUMMARY The IT Risk Analyst II is responsible for measuring and identifying technical risks within ... Capable of managing varied assignments and working independently. * Ability to define problems ...
New
Senior Regional Risk Manager
Portland, OR · On-site
Provide risk-based leadership and oversight to reduce regulatory risk in the region. Lead in a ... Demonstrated ability to use technology and tools to gain efficiencies and speed * Self-motivated ...
Senior Regional Risk Manager
Portland, OR · On-site
Provide risk-based leadership and oversight to reduce regulatory risk in the region. Lead in a ... Demonstrated ability to use technology and tools to gain efficiencies and speed * Self-motivated ...
Supplier Diversity & Risk Manager | Full-Time | Denver Tech Center Location US-Remote Job Post Information* : Posted Date 2 months ago(5/4/2026 3:29 PM) Job ID 2026-30175 Location Name Remote ...
Supplier Diversity & Risk Manager | Full-Time | Denver Tech Center Location US-Remote Job Post Information* : Posted Date 2 months ago(5/4/2026 3:29 PM) Job ID 2026-30175 Location Name Remote ...
Support adoption of innovative technologies and emerging approaches to risk management Sponsor ... Stakeholder Partnership * Present monitoring strategies, risk assessments, and recommendations to ...
Support adoption of innovative technologies and emerging approaches to risk management Sponsor ... Stakeholder Partnership * Present monitoring strategies, risk assessments, and recommendations to ...
Job Summary Aptive is seeking a registered nurse risk manager. IHSC's mission is to provide medical ... We specialize in applying technology, creativity and human-centered services to optimize mission ...
Job Summary Aptive is seeking a registered nurse risk manager. IHSC's mission is to provide medical ... We specialize in applying technology, creativity and human-centered services to optimize mission ...
The JD reads Cyber and Tech Risk UW SR
Portland, OR · On-site +1
$103K - $122K/yr
... and technology risk. We combine underwriting expertise, cyber risk intelligence, and advanced ... Our cyber offerings are supported by proactive risk management services and data driven insights ...
The JD reads Cyber and Tech Risk UW SR
Portland, OR · On-site +1
$103K - $122K/yr
... and technology risk. We combine underwriting expertise, cyber risk intelligence, and advanced ... Our cyber offerings are supported by proactive risk management services and data driven insights ...
Manager, Risk
Beaverton, OR · On-site
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
Manager, Risk
Beaverton, OR · On-site
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
... Technology preferred. * Successful in implementing a credit risk management function. Has built or ... rebuilt the organization, infrastructure, processes, and systems/tools to be best in class.
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
Technology Risk Manager information
See Oregon salary details
$54.5K - $65.8K
4% of jobs
$65.8K - $77.2K
6% of jobs
$77.2K - $88.6K
11% of jobs
$92.9K is the 25th percentile. Wages below this are outliers.
$88.6K - $100K
11% of jobs
The median wage is $109.1K / yr.
$100K - $111.4K
23% of jobs
$111.4K - $122.8K
13% of jobs
$130.3K is the 75th percentile. Wages above this are outliers.
$122.8K - $134.2K
12% of jobs
$134.2K - $145.6K
8% of jobs
$145.6K - $157K
6% of jobs
$157K - $168.3K
4% of jobs
$168.3K - $179.7K
2% of jobs
$54.5K
$117.9K
$179.7K
How much do technology risk manager jobs pay per year?
What is the difference between Technology Risk Manager vs Cybersecurity Analyst?
| Aspect | Technology Risk Manager | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISA | CISSP, CEH, Security+ |
| Work Environment | Risk assessment, policy development, compliance | Monitoring security threats, incident response, vulnerability analysis |
| Industry Usage | Financial, healthcare, technology firms | IT security teams, government agencies, corporations |
The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.
What are some common challenges Technology Risk Managers face when working across different departments?
What are the key skills and qualifications needed to thrive as a Technology Risk Manager, and why are they important?
What are Technology Risk Managers?

Job description
The Team:Â
Upstart's Risk team is enhancing its second line of defense function in support of our application to establish Upstart Bank, N.A., a de novo national bank. The Risk team is responsible for Upstart's enterprise risk management program and risk governance, and for providing independent oversight and credible challenge across all core risk categories- including operational risk, third party risk, technology and information security risk, and treasury risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment, monitoring, reporting, and control of material risks, in alignment with OCC, FDIC, and FFIEC regulatory expectations.
As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk framework- leveraging and enhancing Upstart's existing technology and information security risk infrastructure to meet bank regulatory standards- and will provide independent oversight and credible challenge of the first-line technology and information security functions across all technology domains, including IT operations, cybersecurity, cloud infrastructure, affiliate-provided technology, and core banking systems. This role reports to the head of third party and technology risk and manages a team of two technology and security risk professionals.Â
How you'll make an impact
- Provide independent second-line review and credible challenge of first-line technology and information security activities, including but not limited to: cybersecurity controls, software development lifecycle (SDLC) and incident response programs, technology resiliency and third-party arrangements
- Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security risk assessments; and provide independent oversight of technology and security risks in alignment with OCC guidance on cloud computing
- Serve as a primary second-line point of contact for OCC examiners, internal audit, and other external stakeholders on technology risk and information security program topics and inquiries; prepare and deliver technology risk reporting to risk committees, the CRO, and the board.Â
- Build and lead a growing Technology Risk team, shaping how the bank identifies, prioritizes, and responds to its most important technology and security risks in alignment with applicable industry regulations
- Partner with first-line IT and cybersecurity teams, TPRM, ERM, Legal, and Compliance to ensure technology and information security risk is integrated into enterprise risk programs, cross-functional risk assessments, and the bank's overall 2LOD reporting and governance structure
Minimum QualificationsÂ
- Bachelor's degree or equivalent practical experience in information technology, cybersecurity, or a related field
- 8+ years of experience in technology risk, information security risk management, IT audit, or GRC in a banking or financial services environment
- 3+ years of direct people management experience leading technology risk, information security governance, risk, and compliance, or information technology audit professionals
- Demonstrated experience applying FFIEC IT Examination Handbook standards and OCC guidance on technology risk and information security in a bank or federally regulated institution
- Experience engaging banking regulators (OCC, FDIC, or Federal Reserve) on technology risk, cybersecurity, or IT controls examination matters
Preferred Qualifications
- Experience building or significantly enhancing a technology risk or information security GRC program in a de novo bank, early-stage bank, or similar environment where the program required meaningful design and build-out
- Knowledge of cloud risk management and OCC/FFIEC guidance on cloud computing (OCC Bulletin 2020-46), particularly in cloud-native or fintech-adjacent technology environments
- Familiarity with affiliate technology risk oversight, including independent oversight of bank-affiliate technology service arrangements, associated data segregation requirements, and Regulation W implications
- Experience with GRC tool implementation or administration in a bank regulatory context
- Current professional certification in information security or technology risk management (CISSP, CISA, CRISC, CISM, or comparable)
- Knowledge of AI/ML technology risk and related governance considerations in a fintech, lending, or model-intensive operating environment
Position location This role is available in the following locations: RemoteÂ
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSeniorÂ