
Senior Manager, Technology Risk and Governance
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Oversee internal audits, external audits, regulatory assessments, and various technology assurance initiatives.
• Manage the intake, prioritization, routing, timelines, deliverables, evidence collection, and response protocols for technology-related audits and examinations.
• Ensure the technology team's evidence is complete, consistent, and of high quality prior to submission to auditors or examiners.
• Maintain a centralized repository containing audit documentation, evidence, responses, findings, and commitments to remediation.
• Monitor audit and examination issues, remediation actions, deadlines, and provide status reports to technology leadership.
• Coordinate responses for customer data, security, and technology due diligence, including questionnaires, documentation, and necessary clarifications.
• Collaborate with Information Security, Privacy, Legal, Risk, Procurement, and Technology teams to collect and validate responses.
• Maintain standardized responses, reusable evidence artifacts, and approved language for documentation.
• Identify recurring themes in due diligence or gaps in evidence and suggest improvements for processes, controls, or documentation.
• Manage a centralized inventory and dashboard of accepted technology risks.
• Oversee risk acceptance reviews, durations, expirations, revalidation needs, re-approvals, and overdue assessments.
• Provide insights and reporting on trends in risk acceptance, concentration, and exposures.
• Facilitate governance and escalation processes related to risk acceptance.
• Track commitments to remediation tied to audit findings, assessments, customer concerns, and compliance reviews.
• Monitor action plans, escalate delays or inadequate closure evidence, and support governance routines for issues.
• Ensure that findings and remediation actions are traceable, auditable, and in line with enterprise issue-management standards.
• Design and sustain processes, procedures, templates, and playbooks for audit coordination, due diligence responses, and risk acceptance reporting.
• Define metrics and dashboards for cycle time, issue aging, evidence quality, response timeliness, and remediation effectiveness.
• Enhance assurance workflows, documentation practices, intake processes, and executive reporting.
• Cultivate relationships across Technology, Information Security, Enterprise Risk, Legal, Privacy, Internal Audit, Finance, and other business stakeholders.
• Prepare executive summaries, dashboards, briefing materials, status updates, and actionable insights for leadership.
• Escalate significant risks, delays, and persistent control issues.
• A Bachelor’s degree in information technology, cybersecurity, risk management, accounting, business, or a related field, or an equivalent combination of education and professional experience.
• Over 7 years of experience in technology risk management, IT compliance or audit, Information Security governance, operational risk, issue management, compliance coordination, or technology control functions.
• Proven experience in coordinating internal/external audits, regulatory examinations, or customer due diligence requests.
• Strong comprehension of technology control environments, including identity and access management, vulnerability management, change management, infrastructure operations, third-party technology services, backup/recovery, and incident response.
• Experience in regulated industries such as financial services, insurance, healthcare, or utilities.
• Knowledge of frameworks such as NIST Cybersecurity Framework, COBIT, ISO 27001, SOC 1 / SOC 2, FFIEC, NYDFS, PCI DSS, OSFI B-13, COSO, or other relevant technology risk/compliance standards.
• Experience in developing metrics and dashboards, managing issue portfolios, and generating governance reports for technology risk and compliance activities.
• Excellent organizational and program management skills.
• Ability to handle multiple concurrent requests and meet deadlines.
• Outstanding written and verbal communication skills.
• Capability to synthesize technical information into executive-ready reports.
• Proven ability to collaborate cross-functionally through indirect influence of contributing teams.
• Familiarity with Governance, Risk, and Compliance (GRC) platforms or audit management tools.
• Applicants must not require immigration sponsorship or additional/permanent work authorization now or in the future to work in the United States.
• Professional certifications such as CGRC, CRISC, CISM, CISSP, or CIA are advantageous.
• A resume is required to apply.
• Eligibility for an annual incentive (bonus) plan.
• Medical insurance coverage.
• Dental insurance benefits.
• Vision insurance available.
• Employee assistance program.
• Life insurance provisions.
• Disability plans offered.
• Parental leave policy.
• Paid time off.
• 401(k) retirement plan.
• Tuition reimbursement support.
• Flexible workplace and work-life balance options.
• Opportunities for career growth.
• Retirement assistance available.
• Flexible location options, enabling work from a preferred place.
• Accommodations for application or interview processes.
Circana
Zero Hash
World Kinect
The Hartford
Get handpicked remote jobs straight to your inbox weekly.