1

Technology Risk Manager Jobs in Brooklyn, NY (NOW HIRING)

Demonstrated second-line risk management experience across both core technology risk domains including cybersecurity, IT operations, data risk, and third-party technology risk and AI risk governance ...

The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and ...

The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and ...

VP - IT Risk Management

New York, NY

$171K - $215K/yr

Company Description A Major International Bank, their Risk Management Department (Midtown) is seeking a VP - IT Risk Management, and VP Operational Risk in their HQ NYC office. The incumbent will be ...

Conduct risk assessments to evaluate the adequacy and effectiveness of policies, procedures, processes, systems, technology, and other internal controls. * Manage triggers for when a risk assessment ...

Risk Manager

Manhattan, NY · On-site

$136K - $154K/yr

... Tech, and international locations. The role exercises functional expertise and influence but has no supervisory responsibilities . This position reports to the Director, Risk Management and Insurance ...

Showing results 21-40

Technology Risk Manager information

See Brooklyn, NY salary details

$54.2K

$117.3K

$178.8K

How much do technology risk manager jobs pay per year?

As of Aug 11, 2026, the average yearly pay for technology risk manager in Brooklyn, NY is $117,302.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,600.00 and $135,600.00 per year, depending on experience, location, and employer.

What is the difference between Technology Risk Manager vs Cybersecurity Analyst?

AspectTechnology Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, technology firmsIT security teams, government agencies, corporations

The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What are some common challenges technology risk managers face when working across different departments?

Technology Risk Managers often encounter challenges in aligning risk management strategies with the priorities of various business units. Departments may have differing levels of risk tolerance, technical understanding, and resource availability, which can make establishing consistent policies and controls difficult. Success in the role relies on strong communication and negotiation skills, as well as the ability to educate stakeholders about the importance of risk mitigation while balancing business objectives. Building collaborative relationships and maintaining flexibility are key to overcoming these cross-departmental challenges.

What are the key skills and qualifications needed to thrive as a technology risk manager, and why are they important?

To thrive as a Technology Risk Manager, you need expertise in risk assessment, cybersecurity principles, and regulatory compliance, often supported by a degree in information security or related fields. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC (governance, risk, and compliance) tools, and certifications like CISM or CISSP are typically required. Strong analytical thinking, communication, and stakeholder management skills help you translate technical risks into business terms and coordinate mitigation efforts. These abilities are critical to proactively identifying threats and ensuring organizational resilience against evolving technology risks.

What is a technology risk manager?

Technology Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with information technology systems and processes within an organization. They ensure that IT operations comply with regulations and best practices while safeguarding data and technology assets from threats such as cyberattacks, data breaches, and system failures. Their work involves developing risk management strategies, conducting risk assessments, and collaborating with other departments to ensure the organization's technology infrastructure is secure and resilient.
What cities near Brooklyn, NY are hiring for Technology Risk Manager jobs? Cities near Brooklyn, NY with the most Technology Risk Manager job openings:
Infographic showing various Technology Risk Manager job openings in Brooklyn, NY as of August 2026, with employment types broken down into 33% Full Time, and 67% Part Time. Highlights an 100% In-person job distribution, with an average salary of $117,302 per year, or $56.4 per hour.

Director of Technology Risk & Controls

Rockefeller Capital Management

Manhattan, NY • On-site

$225K - $275K/yr

Full-time

Medical, Retirement, PTO

Re-posted 13 days ago


Job description

About Rockefeller Capital Management
Rockefeller Capital Management was established in 2018 as a leading independent financial advisory services firm. Originally founded in 1882 as the family office of John D. Rockefeller, the Firm has evolved to offer strategic advice to ultra- and high-net-worth individuals and families, institutions, and corporations from offices in 33 markets throughout the United States, as well as an office in London. The Firm oversees $224 billion in client assets as of June 30, 2026.
Position
The Director of Technology Risk & Controls will serve as the first-line owner of Technology risk and controls across Rockefeller Capital Management. This role has enterprise-wide accountability for identifying, assessing, and managing technology risks, while enabling innovation and facilitating governance in areas like artificial intelligence (AI), automation, and other emerging technologies. The role ensures that effective risk management practices and controls are embedded into day-to-day technology delivery, supporting the firm's fiduciary obligations, protecting client trust, and safeguarding the stability, resilience, and integrity of Rockefeller's technology platforms. This leader will play a pivotal role in shaping and executing the firm's technology risk and control strategy in close partnership with key stakeholders.
Responsibilities
  • Serve as the first-line owner for all technology risk and controls across the firm's Technology domains - engineering, cloud infrastructure, data platforms, networks, end-user devices, and digital products - with direct accountability for the end-to-end RCSA lifecycle (risk identification, control design, testing, issue tracking, and reporting), operating within the firm's defined risk appetite and tolerance thresholds and fostering a risk-aware culture across all Technology teams.
  • Lead technology risk governance, including oversight of enterprise control frameworks, governance structures, and decision rights across Technology; develop and maintain a structured hierarchy of IT policies, standards, and procedures across key control domains (IAM, data protection, change management, SDLC, and vendor oversight); and implement consistent controls across engineering, infrastructure, and data platforms, including application and process-level controls supporting financial, operational, and regulatory requirements.
  • Serve as the central coordination point for all Technology-related regulatory exams and internal/external audits, managing the full audit lifecycle including evidence collection, walkthroughs, and issue remediation; own first-line compliance monitoring and regulatory reporting for the Technology organization, including control-effectiveness measurement and risk trend and scenario analysis.
  • Establish and execute first-line risk governance for technology and information security controls - including vulnerability management, patching, endpoint security, network security, and data protection - setting control requirements, monitoring effectiveness, and challenging Information Security and Engineering teams to ensure risks are continuously identified, prioritized, remediated, and monitored in accordance with firm standards and regulatory expectations.
  • Manage first-line risk governance for AI, automation, and other emerging technologies, ensuring robust controls and responsible AI practices are embedded throughout implementation lifecycles and strong data governance is enforced; assess and manage technology and data risks associated with third-party platforms, vendors, and strategic partnerships to ensure external services meet the firm's risk and compliance standards.
  • Partner with the Technology team to define and embed risk and control requirements and assurance gates throughout the full software development and delivery lifecycle - from requirements and design through secure development, testing, deployment, and ongoing operations - independently verifying adherence and ensuring risk controls are operationalized in day-to-day technology processes.
  • Oversee first-line technology incident management - cyber and operational - setting escalation and reporting standards, monitoring that incidents are contained and remediated by Security Operations and Production teams, and coordinating response, reporting, and post-incident review in close partnership with Enterprise Risk, Compliance, Legal, and other control functions.
  • Maintain a comprehensive, forward-looking view of the firm's technology risk posture; define and maintain the technology risk metrics framework including KRIs, KPIs, and control-effectiveness measures; and produce executive and board-level risk dashboards and audit-ready evidence to provide actionable insights to senior leadership and support governance forums and regulatory transparency.

Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Engineering, or a related discipline; advanced degree preferred
  • 10+ years of experience in technology risk management, IT controls, or related roles within financial services or similarly regulated environments
  • Demonstrated expertise in AI, automation, and emerging technology risk, including model risk management, data governance, and responsible AI frameworks
  • Proven track record designing, implementing, and leading enterprise technology risk and control frameworks in complex organizations
  • Strong technical acumen across financial services platforms, preferably wealth management, including digital client experiences, data platforms, cloud environments, and third-party technology ecosystems

Skills
  • Demonstrated ability to operate as a firm-wide leader, setting strategic direction for the firm's technology risk and control platform and influencing outcomes at the most senior levels of the organization.
  • Strong executive presence, judgment, and communication skills.
  • Collaborative, cross-functional leader who combines entrepreneurial energy with hands-on execution to deliver measurable risk reduction and business outcomes.
  • Proven track record to translate technical, operational, and emerging risks into actionable business, client, and governance insights.
  • Able to translate technical and risk concepts into actionable business and regulatory insights.
  • Strategic thinker, passionate about identifying opportunities and driving change.
  • Intellectually curious, global perspective, high energy, driven, ambitious, commercial; wants to win and works well in fast-paced environment.
  • Adaptable, comfortable in ambiguity, with strong ability to creatively solve problems, communicate ideas, drive agendas, and build consensus.

Compensation Range
The anticipated base salary range for this role is $225,000 to $275,000. Base salary for the role will depend on several factors, including a candidate's qualifications, skills, competencies, and experience, and may fall outside of the range shown. In addition, this role may be eligible for a discretionary bonus. Rockefeller Capital Management offers a comprehensive benefit package including health coverage, vacation time, paid leave, retirement plan, and more. Visit careers.rockco.com to learn more about additional opportunities and benefits offerings.
Disclosure
Rockefeller & Co. LLC, Rockefeller Financial LLC, Rockefeller Trust Company, N.A., The Rockefeller Trust Company (Delaware), Rockefeller Financial Services, Inc. and all other subsidiaries of Rockefeller Capital Management L.P. (individually and collectively, "Rockefeller") is an equal opportunity employer and does not discriminate on the basis of race, religion, sex, gender, sexual orientation, gender identity or expression, national origin, citizenship, age, military or veteran status, marital or partnership status, caregiver status, legally recognized disability, or any other basis protected by applicable federal, state or local law ("protected characteristics").
Rockefeller Capital Management participates in the E-Verify program in certain locations, as required by law.