Director Application & Data Technology Risk
$153,600–$230,400 year
HybridCharlotte, North Carolina, United States or Columbus, Ohio, United States
Job Summary
Lead the identification and management of application-level technology risks across the software development lifecycle, including secure design, SDLC controls, and operational resilience. Assess risks introduced through modern engineering practices such as agile delivery, DevOps, CI/CD pipelines, APIs, and third-party integrations. Evaluate data risk and sensitive data exposure within applications, providing risk guidance on AI, GenAI, and automation use cases with emphasis on data sourcing and access governance. Partner with application, platform, and security teams to promote adherence to engineering control expectations while serving as a trusted risk advisor to CIOs and senior technology leaders. Translate complex technical risks into clear, business-relevant narratives for senior leadership and risk committees, defining and monitoring risk metrics to support audit and regulatory activities. Lead and develop a team of technology risk professionals focused on application and emerging technology risk.
Required Qualifications
- 10+ years of experience in technology risk management, application security, IT audit, engineering, or related domains
- Strong working knowledge of application architectures, SDLC, DevOps practices, and CI/CD pipelines
- Demonstrated experience assessing data risks and data exposure within application environments
- Practical understanding of AI and automation risks, including model governance, data usage, and control considerations
- Solid familiarity with cloud and infrastructure control domains (IAM, logging, encryption, network security, resiliency)
- Proven ability to communicate effectively with senior leaders and translate technical issues into executive-level insights
- Experience working with industry frameworks (e.g., NIST, CIS Controls, COBIT, secure SDLC standards)
- Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Hartford, CT or Charlotte, NC) 3 days a week
- Candidates must be eligible to work in the US without company sponsorship
Desired Qualifications
- Prior hands-on experience in software engineering, application architecture, platform operations, or DevOps
- Experience managing risk in high-growth, technology-driven organizations with evolving governance expectations
- Relevant certifications such as CISSP, CISM, CRISC, CISA, or cloud security certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.