Fidelity Investments logo
Fidelity InvestmentsPosted 1 month ago

Principal Technology Risk Analyst - Program & Regulatory Assurance

On-siteWestlake, Texas, United States or Merrimack, New Hampshire, United States

Full TimeSenior LevelEnterprise

Job Summary

Design and maintain technology controls to support program and regulatory requirements, ensuring risk and control taxonomy aligns with enterprise standards. Develop and monitor controls for security and compliance, documenting Risk and Control Matrices across business and IT processes. Oversee the control certification process and lead SOX 404 compliance, including reviewing SOC reports and assessing control gaps. Collaborate with the Controls Testing team and various business units to track remediation and represent the Enterprise Technology Risk group in regulatory activities and examinations. This role requires 5-7 years of experience in IT risk, controls, or audit, with a Bachelor's degree preferred. Certifications such as CISSP, CISA, or CRISC are highly valued. The position is onsite at Fidelity and does not offer immigration sponsorship.

Required Qualifications

  • 5 -7 years' experience in information technology risk, controls, or audit roles
  • Bachelor's degree in computer science, technology, or a related field of study
  • Demonstrated technical abilities in multiple areas (e.g., technology infrastructure and application controls, cyber security, access management, network and cloud, resiliency, etc.)
  • Working knowledge of Cloud security and controls and cloud technology environments (AWS/Azure, SaaS, PaaS)
  • Strong knowledge of information technology processes and controls
  • Comprehensive understanding of risk, quality control and assurance functions
  • Ability to build and maintain collaborative working relationships with Information Technology and Business personnel to design effective controls
  • Process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
  • Knowledge of Industry standards, regulations, frameworks and best practices, such as NIST SP 800-53, COBIT, AICPA Trust Principles, ISO27001, SWIFT, HITRUST, and SOX404
  • Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer
  • Excellent verbal and written communication skills enabling you to prepare and present recommendations to senior management
  • 100% onsite presence
  • No immigration sponsorship

Desired Qualifications

  • Professional technology and associated risk certifications (CISSP, CISA, CRISC, CISM), Certified risk/fraud examiners (CRE, CFE), and/or Cloud Certification(s) (CCSP, CCSK, AWS)
  • Experience documenting controls for large scale financial service organizations (cloud, distributed, vendor solutions, mainframe, network environments, and AI)
  • ISO9001 and/or ISO27001 certification
  • Responsibility to support and participate in ISO peer audit reviews

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce