Senior Manager, Technology Risk and Governance

Posted 7hrs ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Technology compliance leader coordinating audits, due diligence, and accepted-risk governance for TruStage’s insurance and financial services business. Driving remediation oversight, control transparency, and executive reporting.

Responsibilities:

  • Coordinate internal audits, external audits, regulatory reviews, and other technology assurance activities
  • Manage intake, prioritization, routing, timelines, deliverables, evidence collection, and response protocols for technology audits and examinations
  • Review technology-team evidence for completeness, consistency, and quality before delivery to auditors or examiners
  • Maintain a centralized repository of audit documentation, evidence, responses, findings, and remediation commitments
  • Track audit and examination issues, remediation actions, deadlines, and status reporting to technology leadership
  • Coordinate customer data, security, and technology due diligence responses, questionnaires, documentation, and clarifications
  • Partner with Information Security, Privacy, Legal, Risk, Procurement, and Technology teams to gather and validate responses
  • Maintain standard responses, reusable evidence artifacts, and approved language
  • Identify recurring due diligence themes or evidence gaps and recommend process, control, or documentation improvements
  • Administer a centralized inventory and dashboard of accepted technology risks
  • Monitor risk acceptance reviews, durations, expirations, revalidation requirements, re-approvals, and overdue reviews
  • Provide reporting and insights on risk acceptance trends, concentration, and exposures
  • Facilitate risk acceptance governance and escalation routines
  • Track remediation commitments associated with audit findings, assessments, customer issues, and compliance reviews
  • Monitor action plans, escalate delays or inadequate closure evidence, and support issue governance routines
  • Ensure findings and remediation actions are traceable, auditable, and aligned with enterprise issue-management standards
  • Design and maintain processes, procedures, templates, and playbooks for audit coordination, due diligence responses, and risk acceptance reporting
  • Define metrics and dashboards for cycle time, issue aging, evidence quality, response timeliness, and remediation performance
  • Improve assurance workflows, documentation discipline, intake processes, and executive reporting
  • Build relationships across Technology, Information Security, Enterprise Risk, Legal, Privacy, Internal Audit, Finance, and business stakeholders
  • Prepare executive summaries, dashboards, briefing materials, status updates, and actionable leadership insights
  • Escalate material risks, delays, and recurring control concerns

Requirements:

  • Bachelor’s degree in information technology, cybersecurity, risk management, accounting, business, or related field, or equivalent combination of education and/or related professional work experience
  • 7+ years of experience in technology risk management, IT compliance or audit, Information Security governance, operational risk, issue management, compliance coordination, or technology control functions
  • Demonstrated experience coordinating internal/external audits, regulatory exams, or customer due diligence requests
  • Strong understanding of technology control environments, including identity and access management, vulnerability management, change management, infrastructure operations, third-party technology services, backup/recovery, and incident response
  • Experience in a regulated industry such as financial services, insurance, healthcare, or utilities
  • Familiarity with NIST Cybersecurity Framework, COBIT, ISO 27001, SOC 1 / SOC 2, FFIEC, NYDFS, PCI DSS, OSFI B-13, COSO, or other relevant technology risk/compliance standards
  • Experience developing metrics and dashboards, managing issue portfolios, and producing governance reporting for technology risk and compliance activities
  • Strong organizational and program management skills
  • Ability to manage multiple concurrent requests and deadlines
  • Excellent written and verbal communication skills
  • Ability to synthesize technical input into executive-ready reporting
  • Proven ability to work cross-functionally through indirect influence of contributing teams
  • Experience with Governance, Risk, and Compliance (GRC) platforms or audit management tools
  • Applicants must not require immigration sponsorship or additional/permanent work authorization now or in the future to work in the United States
  • Professional certifications such as CGRC, CRISC, CISM, CISSP, or CIA are a plus
  • Resume required to apply

Benefits:

  • Annual incentive (bonus) plan eligibility
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Employee assistance program
  • Life insurance
  • Disability plans
  • Parental leave
  • Paid time off
  • 401(k)
  • Tuition reimbursement
  • Flexible workplace and work-life balance
  • Career growth
  • Retirement assistance
  • Flexible location / ability to work in a preferred place
  • Application or interview process accommodations