Principal Technology Risk Analyst - Program & Regulatory Assurance
On-siteWestlake, Texas, United States or Merrimack, New Hampshire, United States
Job Summary
Design and maintain technology controls to support program and regulatory requirements, ensuring risk and control taxonomy aligns with enterprise standards. Develop and monitor controls for security and compliance, documenting Risk and Control Matrices across business and IT processes. Oversee the control certification process and lead SOX 404 compliance, including reviewing SOC reports and assessing control gaps. Collaborate with the Controls Testing team and various business units to track remediation and represent the Enterprise Technology Risk group in regulatory activities and examinations. This role requires 5-7 years of experience in IT risk, controls, or audit, with a Bachelor's degree preferred. Certifications such as CISSP, CISA, or CRISC are highly valued. The position is onsite at Fidelity and does not offer immigration sponsorship.
Required Qualifications
- 5 -7 years' experience in information technology risk, controls, or audit roles
- Bachelor's degree in computer science, technology, or a related field of study
- Demonstrated technical abilities in multiple areas (e.g., technology infrastructure and application controls, cyber security, access management, network and cloud, resiliency, etc.)
- Working knowledge of Cloud security and controls and cloud technology environments (AWS/Azure, SaaS, PaaS)
- Strong knowledge of information technology processes and controls
- Comprehensive understanding of risk, quality control and assurance functions
- Ability to build and maintain collaborative working relationships with Information Technology and Business personnel to design effective controls
- Process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
- Knowledge of Industry standards, regulations, frameworks and best practices, such as NIST SP 800-53, COBIT, AICPA Trust Principles, ISO27001, SWIFT, HITRUST, and SOX404
- Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer
- Excellent verbal and written communication skills enabling you to prepare and present recommendations to senior management
- 100% onsite presence
- No immigration sponsorship
Desired Qualifications
- Professional technology and associated risk certifications (CISSP, CISA, CRISC, CISM), Certified risk/fraud examiners (CRE, CFE), and/or Cloud Certification(s) (CCSP, CCSK, AWS)
- Experience documenting controls for large scale financial service organizations (cloud, distributed, vendor solutions, mainframe, network environments, and AI)
- ISO9001 and/or ISO27001 certification
- Responsibility to support and participate in ISO peer audit reviews
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.