Information Technology Risk Manager

1 week ago


Seattle, United States Apex Systems Full time

IT Risk and Compliance Analyst

Location: Seattle, WA

FTE Salary Range: $80k - $100k


Job Description:

We are seeking an experienced IT Risk and Compliance Analyst to join our team. In this role, you will support the organization’s IT risk management and compliance programs. This includes identifying, assessing, and mitigating risks to the IT environment and ensuring compliance with relevant regulations, standards, and policies. The role also involves collaborating with various stakeholders to implement and maintain a robust IT governance framework.


Candidate Requirements:

  • Strong understanding of IT systems, controls, security practices, relevant laws, regulations, and industry standards.
  • Excellent analytical and problem-solving skills, with the ability to identify, assess, and mitigate risks effectively.
  • Strong communication and interpersonal skills, with the ability to collaborate with various stakeholders and present complex information clearly.
  • Proven project management and organizational skills, with the ability to manage multiple priorities and meet deadlines.
  • Proficiency in risk management tools and technologies (e.g., GRC software, data analytics tools).
  • Relevant professional certifications (e.g., Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP)) are preferred.
  • 3+ years of experience in IT risk management, IT compliance, or a related field, preferably in the financial services industry.
  • Strong understanding of IT risk management frameworks.
  • Knowledge of regulatory requirements and industry standards relevant to IT risk and compliance.
  • Excellent communication and interpersonal skills, with the ability to effectively interact with stakeholders at all levels of the organization.


Role and Responsibilities:

Risk Management:

  • Develop, support, and maintain an IT risk management framework, including policies, procedures, and control mechanisms, to identify, assess, mitigate, and monitor IT risks across the organization.
  • Conduct regular risk assessments, gap analyses, and control testing to evaluate the effectiveness of IT controls and identify potential threats to the IT environment and areas for improvement.
  • Collaborate with IT, business units, and other stakeholders to implement risk mitigation strategies and remediation plans for identified control deficiencies.
  • Provide support with third-party risk management activities and administration, including compliance documentation collection, contract reviews, contract negotiation, and technology cost analysis.
  • Monitor and report on the effectiveness of risk management activities
  • Design, build, and maintain key risk indicators and key performance indicators to help measure the department’s effectiveness in managing technology risk and service delivery.


Compliance:

  • Ensure IT processes adhere to and maintain compliance with relevant laws, regulations, and industry standards (e.g., FFIEC, GLBA, SOX, etc.), data privacy regulations (e.g., CCPA), and cybersecurity frameworks (e.g., NIST).
  • Stay current with changes in relevant laws, regulations, and industry best practices and ensure the organization remains compliant.
  • Perform regular compliance audits and assessments.
  • Help manage the IT audit process, including coordinating with internal and external auditors, providing necessary documentation, and helping IT control owners address audit findings.
  • Facilitate the reviews of IT Audit Management Responses with the IT Leadership team.
  • Develop and maintain IT compliance documentation, including policies, procedures, and guidelines.


Governance:

  • Assist in the development and maintenance of the IT governance framework.
  • Monitor adherence to IT governance policies and procedures and report non-compliance.
  • Develop and deliver training programs to educate employees on IT risk management and compliance practices.


Incident Management:

  • Assist in the investigation of IT security incidents and breaches.
  • Coordinate with the IT and Information Security teams to implement corrective actions and preventive measures.
  • Conduct Post Incident Reviews and follow up on remediation activities and reporting.


Internal Controls:

  • Evaluate and enhance internal controls over IT systems and processes.
  • Work with internal and external auditors during audits and reviews.
  • Ensure that IT controls are effectively designed and operating as intended.


Reporting and Documentation:

  • Prepare and present risk and compliance reports to senior management and relevant committees, providing insights and recommendations for continuous improvement.
  • Maintain detailed records of risk assessments, compliance audits, and incident investigations.
  • Provide documentation and support for external audits and regulatory inquiries.


  • seattle, United States Apex Systems Full time

    IT Risk and Compliance AnalystLocation: Seattle, WAFTE Salary Range: $80k - $100kJob Description:We are seeking an experienced IT Risk and Compliance Analyst to join our team. In this role, you will support the organization’s IT risk management and compliance programs. This includes identifying, assessing, and mitigating risks to the IT environment and...


  • Seattle, Washington, United States Apple Full time

    Job SummaryThe Enterprise Risk Manager - Technology is responsible for leading a team that develops and coordinates the overall technology risk management framework for the company, performs assessments to identify and manage risks, and creates a sustainable technology risk program and related activities. The Enterprise Risk Manager is also responsible for...


  • Seattle, Washington, United States Apple Full time

    Job SummaryThe Enterprise Risk Manager - Technology is responsible for leading a team that develops and coordinates the overall technology risk management framework for the company. This includes performing assessments to identify and manage risks, creating a sustainable technology risk program, and aggregating risk data for submission to management and...


  • Seattle, Washington, United States The Nature Conservancy Full time

    Job SummaryThe Information Security Analyst will play a key role in supporting information security and risk management activities centered around external party information and application security. This position is part of the Information Security Risk Management Team, which helps safely implement systems and integrate third party organizations into TNC's...


  • Seattle, Washington, United States Apple Full time

    Job SummaryWe are seeking an experienced Enterprise Risk Manager to lead our technology risk management program. The successful candidate will have a strong background in risk management, technology risk, and governance, with a proven track record of developing and implementing effective risk management frameworks.Key Responsibilities* Develop and implement...


  • Seattle, United States Starbucks Full time

    Now Brewing - information security manager, risk management! #tobeapartner From the beginning, Starbucks set out to be a different kind of company. One that not only celebrated coffee and the rich tradition, but that also brought a feeling of connection. At Starbucks, our mission is to inspire and nurture the limitless possibilities of human connection –...


  • Seattle, United States Starbucks Full time

    Now Brewing - information security manager, risk management! #tobeapartner From the beginning, Starbucks set out to be a different kind of company. One that not only celebrated coffee and the rich tradition, but that also brought a feeling of connection. At Starbucks, our mission is to inspire and nurture the limitless possibilities of human connection –...


  • Seattle, United States Starbucks Full time

    Now Brewing - information security manager, risk management! #tobeapartner From the beginning, Starbucks set out to be a different kind of company. One that not only celebrated coffee and the rich tradition, but that also brought a feeling of connection. At Starbucks, our mission is to inspire and nurture the limitless possibilities of human connection –...


  • Seattle, United States Starbucks Full time

    Job DescriptionNow Brewing - information security manager, risk management! #tobeapartnerFrom the beginning, Starbucks set out to be a different kind of company. One that not only celebrated coffee and the rich tradition, but that also brought a feeling of connection. At Starbucks, our mission is to inspire and nurture the limitless possibilities of human...


  • Seattle, Washington, United States Global Information Technology Full time

    Job Title: Director of TechnologyGlobal Information Technology is seeking a highly experienced Director of Technology to lead our team of engineers and drive the development of our complex projects.Key Responsibilities:Lead and improve team development principles, reducing dependencies and accelerating production.Develop and implement technical strategies to...


  • Seattle, Washington, United States Sun Recruiting Inc Full time

    About the Role:Sun Recruiting Inc is seeking a highly skilled Senior Technology Risk Advisor to join their team. As a key member of the organization, you will be responsible for providing technical expertise and advisory services to clients worldwide.Key Responsibilities:Evaluate technologies for clients to inform loan decisionsDevelop risk assessments for...


  • Seattle, Washington, United States Africatown Community Land Trust Full time

    About the PositionThe Africatown Community Land Trust is seeking a highly skilled Information Systems and Technology Manager to lead the development and implementation of technology strategies that support the organization's mission and goals. As a key member of the leadership team, the successful candidate will be responsible for planning, managing, and...


  • Seattle, WA, United States Starbucks Full time

    Now Brewing - information security manager, risk management! #tobeapartner From the beginning, Starbucks set out to be a different kind of company. One that not only celebrated coffee and the rich tradition, but that also brought a feeling of connection. At Starbucks, our mission is to inspire and nurture the limitless possibilities of human connection –...


  • Seattle, United States Sony Computer Entertainment America LLC Full time

    Why PlayStation? PlayStation isn't just the Best Place to Play - it's also the Best Place to Work. Today, we're recognized as a global leader in entertainment producing The PlayStation family of products and services including PlayStation5, PlayStation4, PlayStationVR, PlayStationPlus, acclaimed PlayStation software titles from PlayStation Studios, and more....


  • Seattle, Washington, United States Africatown Community Land Trust Full time

    Job DescriptionAfricatown Community Land Trust (ACLT) is seeking a highly skilled Information Systems and Technology Manager to lead the development and implementation of technology strategies that support the organization's mission and goals. The successful candidate will have a strong background in IT management, excellent communication skills, and the...


  • Seattle, Washington, United States BRESSNER Technology GmbH Full time

    Job Title: Technology Manager, DistributionAt BRESSNER Technology GmbH, we are seeking a highly skilled Technology Manager, Distribution to join our team. As a key member of our organization, you will be responsible for leading a team of architects, project leads, analysts, testers, business stakeholders, and software vendors across multiple work streams...


  • Seattle, United States Insight Global Full time

    IT Project Coordinator 12-month contract with long-term opportunity, Hybrid 60/40 (Onsite/Remote)What we are looking for in an IT Project CoordinatorPartner with the IT Project Manager to gathering IT requirements from the initial phase of the Project Management Life Cycle (PMLC) through end of Design phase. Create and Maintain detailed IT equipment’s...


  • Seattle, Washington, United States Blue Origin Full time

    Job Title: Risk Management SpecialistAt Blue Origin, we are committed to developing reusable, safe, and low-cost space vehicles and systems within a culture of safety, collaboration, and inclusion. We are seeking a highly skilled Risk Management Specialist to join our team of problem solvers and contribute to our mission of making space travel accessible to...


  • Seattle, Washington, United States RSM US LLP Full time

    Job Summary:As a Supervisor of IT Risk Management at RSM US LLP, you will be responsible for consulting with client leadership on the design and optimization of controls. You will utilize your general knowledge of business processes to ensure the effective implementation of risk management strategies.Key Responsibilities:* Collaborate with clients to...


  • Seattle, Washington, United States Apex Systems Full time

    IT Risk and Compliance AnalystWe are seeking a highly skilled IT Risk and Compliance Analyst to join our team at Apex Systems. In this role, you will play a critical part in supporting the organization's IT risk management and compliance programs.Key Responsibilities:Risk Management: Develop and maintain an IT risk management framework, including policies,...