
Technology & Cyber Risk Manager
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Lead zerohash’s cyber risk framework, which encompasses risk methodology, risk appetite metrics, and a scenario library.
• Generate independent risk assessments for senior leadership and the board.
• Maintain the technology and cyber risk register as a dynamic, continuously updated log.
• Review and critically evaluate first-line security outputs, including penetration test results, vulnerability metrics, and control assessments.
• Develop independent risk evaluations.
• Collaborate with Engineering and Security teams to identify risks across infrastructure, applications, and AI systems.
• Oversee the AI governance program, which includes a use case registry, risk classification, and supervision of AI systems that interact with end-user or transaction data.
• Assist with regulatory and counterparty risk assessments in the capacity of the second-line technology risk owner.
• Monitor emerging technology risks, such as AI, model risk, and cryptographic risk.
• Provide independent technical risk assessments for custody-critical and security-critical vendors to inform the broader vendor risk program.
• Minimum of 5 years in technology risk, cyber risk, or information security risk management, with at least 2 years in a dedicated second-line role at a bank, regulated fintech, or similar entity.
• Direct experience with GSIB-style third-party assessments, either as the evaluator or the assessed party.
• Capability to read and critically evaluate first-line security outputs and generate independent risk evaluations.
• Practical experience with quantitative risk modeling, specifically using FAIR methodology or an equivalent.
• Understanding of AI/ML risk governance concepts, including model inventories, use case classification, and human-in-the-loop design.
• Knowledge of DORA ICT risk requirements or similar EU financial regulations.
• Strong written communication skills, as board and regulatory-grade risk reporting is a key deliverable.
• Preferred experience within a digital asset, payments, or crypto-adjacent regulated institution.
• Formal FAIR certification or an equivalent quantitative risk credential (preferred).
• Familiarity with post-quantum cryptography standards and cryptographic inventory frameworks.
• Healthcare Insurance: zerohash covers approximately 100% of employee premiums, as well as a portion for spouse/children (U.S. only).
• Vision & Dental Insurance (U.S. only).
• Opportunity to earn equity.
• Maternity & Paternity leave (after 6 months).
• WeWork All Access Membership.
• WFH Yearly Stipend.
• L&D Yearly Stipend (after 6 months).
ReWorks Solutions
Johnson & Johnson
Thermo Fisher Scientific
Get handpicked remote jobs straight to your inbox weekly.