Proven experience in technology risk, operational risk, cybersecurity, or compliance within a regulated or enterprise environment, with expertise in identifying, assessing, and mitigating business and technology risks
Strong knowledge of risk and control frameworks, including ISO 27001, SOC, NIST, COSO, GDPR, and related governance, risk, and compliance practices
Experience managing vulnerability governance processes, validating remediation plans, monitoring control effectiveness, and reducing technology risk exposure
Understanding of application security, secure software development lifecycle (SDLC), security-by-design principles, technical debt management, and infrastructure risk mitigation
Strong analytical, problem-solving, and stakeholder management skills, with the ability to communicate complex technical risks to both technical and non-technical audiences
Experience supporting audits, regulatory compliance activities, customer assurance programs, vendor risk assessments, and GRC platforms such as ServiceNow, Archer, OneTrust, or AuditBoard
Education
Bachelor’s degree in Business, Risk Management, Computer Science, or a related discipline
Professional certifications such as CISA, CRISC, CISSP, Security+, or ISO 27001 Lead Implementor/Auditor are preferred
Responsibilities
Identify, assess, monitor, and report technology, operational, and cybersecurity risks across the Insurance Business Unit to support business objectives and regulatory requirements
Don't want to miss the next one?
Subscribe to daily email alerts for roles matching your interests.
Manage vulnerability governance processes, including remediation tracking, risk treatment validation, escalation management, and control gap closure
Partner with engineering and product teams to embed secure development practices, vulnerability management, secure design principles, and testing standards
Evaluate technology risk drivers, including technical debt, legacy platforms, infrastructure weaknesses, and control deficiencies, while supporting remediation prioritization
Support governance, compliance, and assurance activities through control assessments, issue management, policy reviews, audit coordination, and framework alignment
Contribute to customer assurance and commercial initiatives by supporting RFP responses, vendor assessments, security reviews, and customer due diligence activities
Collaborate with stakeholders across engineering, cybersecurity, legal, compliance, and business teams to strengthen controls and improve risk outcomes
Develop and maintain risk dashboards, metrics, and reporting capabilities that provide actionable insights for decision-making and continuous improvement
About the Team
The Risk Management team within the Insurance Business Unit serves as the first line of defense, driving the adoption of effective risk management practices and fostering a strong culture of risk awareness. Working closely with engineering, product, and business stakeholders, the team proactively manages technology and operational risks, strengthens control environments, supports regulatory and customer expectations, and enables sustainable business growth.
Similar roles you might like
More openings like this one — take a look before you go.