Principal/Senior Technology Risk Analyst

Berkshire Hathaway Specialty Insurance

Boston (MA)

On-site

USD 140,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, Dental, Vision
Disability Insurance
Life Insurance
AD&D Insurance
Flexible Spending Accounts
Health Reimbursement Account
Employee Assistance Program
401(k) match
Paid time off
Tuition Reimbursement
Paid Parental Leave

Job summary

Berkshire Hathaway Specialty Insurance is seeking a Technology Senior Risk Analyst to advance the GRAC program, coordinating risk identification, assessment, and continuous monitoring across enterprise IT risk practices.

The role involves defining and socializing KRIs/KPIs, dashboards, trends, and heat maps, while collaborating with risk owners and senior stakeholders. A strong governance mindset and global collaboration are essential.

Qualifications

  • 10+ years of experience in Technology risk, Technology audit/compliance, or cyber GRC
  • Experience running RCAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholders
  • Strong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plans
  • Effective communication and partnership skills; able to challenge constructively and receive challenge professionally
  • Experience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow-up
  • Solid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise) such as NIST CSF, COSO ERM, COBIT
  • Working knowledge of U.S. Technology regulations (SOX, CCPA/CPRA, PCI, NY-DFS) recommended
  • Familiarity with global regulatory frameworks (GDPR, DORA, MAS, APRA) preferred but not required
  • Ability to work in a team-based environment and communicate effectively domestically and globally
  • AI experience a plus, including understanding of AI risks or regulatory requirements
  • Professional certifications such as CRISC, CISA, CISM, CISSP or ISO/IEC 27001 Lead Implementer/Auditor are a plus

Responsibilities

  • Lead risk identification, risk assessment, and ongoing monitoring

Skills

Technology risk
Risk assessment
RCAs
KRIs/KPIs
Risk dashboards
Vendor risk
SOC 2 analysis
NIST CSF
COSO ERM
Executive communication

Education

CRISC
CISA
CISM
CISSP
ISO 27001 Lead Auditor

Tools

Workiva
AuditBoard
ServiceNow
Drata
Vanta

Job description

Role Overview

Join the Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst to support and mature the Technology Risk Management pillar, ensuring technology risks are proactively identified, assessed, communicated, and monitored across the enterprise.

What You Will Do

Lead risk identification, risk assessment, and ongoing monitoring; drive Risk and Control Self-Assessments (RCAs) with different risk and control owners; define and socialize KRIs/KPIs, risk dashboards, trends, and heat maps.

Why It Might Be a Fit

If you're passionate about elevating enterprise Technology risk practices, driving meaningful change, and growing your career as a key contributor to our evolving global IT risk program, we’re interested in speaking with you.

Requirements
  • 10+ years of experience in Technology risk, Technology audit/compliance, or cyber GRC
  • Experience running RCSAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholders
  • Strong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plans
  • Effective communication and partnership skills; able to challenge constructively and receive challenge professionally
  • Experience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow-up
  • Solid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise), such as NIST CSF, COSO ERM, COBIT, etc.
  • Working knowledge of U.S. Technology regulations (e.g., SOX, CCPA/CPRA, PCI, NY-DFS) is recommended
  • Familiarity with global regulatory frameworks (e.g., GDPR, CBI, DORA, MAS, APRA, BaFin) is preferred but not required
  • Ability to work in a team-based environment and communicate effectively and efficiently with others domestically and globally
  • Experience with GRC tools such as Workiva, AuditBoard, ServiceNow, Drata, Vanta, or similar platforms is a plus
  • AI experience is a plus, including an understanding of AI risks, responsible AI concepts, or emerging AI regulatory requirements
  • Professional certifications such as CRISC, CISA, CISM, CISSP, or ISO/IEC 27001 Lead Implementer/Lead Auditor (or equivalent) are a plus
Benefits
  • Comprehensive Health, Dental and Vision benefits
  • Disability Insurance (both short-term and long-term)
  • Life Insurance (for you and your family)
  • Accidental Death & Dismemberment Insurance (for you and your family)
  • Flexible Spending Accounts
  • Health Reimbursement Account
  • Employee Assistance Program
  • Retirement Savings 401(k) Plan with Company Match
  • Generous holiday and Paid Time Off
  • Tuition Reimbursement
  • Paid Parental Leave
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer
Senior Software Engineer

Link Canada : 2SLGBTQ+ Insurance Network • Boston (MA)

On-site
USD 120,000 - 160,000
Health Insurance
Dental Insurance
Vision Insurance
+11
Principal Technology Risk Analyst - Program & Regulatory Assurance
Principal Technology Risk Analyst - Program & Regulatory Assurance

Fidelity Investments • Merrimack (NH)

On-site
USD 110,000 - 170,000
Senior Lead, Technology Risk & Controls - SOX / SOC Programs
Senior Lead, Technology Risk & Controls - SOX / SOC Programs

Northern Trust • Chicago (IL)

On-site
USD 140,000 - 230,000
Retirement benefits (401k)
Health and welfare benefits
Paid time off
+3
CyberSecurity Specialist - GRC
CyberSecurity Specialist - GRC

TechDigital Group • Phoenix (AZ)

On-site
USD 120,000 - 150,000
Technology Risk Manager (IC), Risk and Control Self-Assessment (RCSA)
Technology Risk Manager (IC), Risk and Control Self-Assessment (RCSA)

Charles Schwab • Phoenix (AZ)

On-site
USD 90,000 - 120,000
401(k) with company match
Paid parental leave
Tuition reimbursement
+1
Technology Risk & Control - Senior Associate - Global Private Bank
Technology Risk & Control - Senior Associate - Global Private Bank

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 120,000 - 170,000
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Senior GRC Analyst
Senior GRC Analyst

United States Digital Space LLC • Boston (MA)

On-site
USD 130,000 - 170,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
Sr Risk and Compliance Manager
Sr Risk and Compliance Manager

ACI Worldwide • Omaha (NE)

Hybrid
USD 130,000 - 190,000