Principal Technology Risk Analyst - Program & Regulatory Assurance

Fidelity

United States

On-site

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Fidelity is seeking a Principal Technology Risk Analyst to join the Enterprise Technology Risk group. You will design and maintain technology controls to support program and regulatory requirements, coordinating with Controls Testing and various risk teams across the enterprise.

Responsibilities include managing control updates, mapping, and testing; developing RCMS/RACMs; and overseeing certification processes while supporting regulatory activities and examinations.

Qualifications

  • Bachelor’s degree in computer science or related field.
  • 5–7 years of IT risk, controls, or audit experience.
  • Certifications: CISSP, CISA, CRISC, CISM preferred.
  • Experience documenting controls for large financial services organizations.
  • Knowledge of cloud security and cloud environments (AWS/Azure).
  • Familiarity with NIST, COBIT, ISO27001, and SOX404 preferred.
  • Strong written and verbal communication for senior management.

Responsibilities

  • Ensure risk and control taxonomy aligns with enterprise standards.
  • Develop and monitor technology controls for security and compliance.
  • Maintain Risk and Control Matrices (RCMs/RACMs).
  • Oversee control certification process.
  • Collaborate with Control Testing to track remediation progress.
  • Support regulatory activities, risk assessments, and examinations.
  • Lead and support SOX 404 compliance, including documentation.
  • Review SOC reports and communicate control gaps.

Skills

IT risk experience
Controls & audit
Regulatory knowledge
Cloud security
Vendor management
SOX/Compliance

Education

Bachelor's degree in computer science or related field

Tools

Archer

Job description

Job Description:

Title: Principal Technology Risk Analyst

Note: Fidelity will not provide immigration sponsorship for this position.

The Role

The Enterprise Technology Risk group is seeking a passionate, driven and experienced professional to contribute to the Technology Risk Program and Regulatory Assurance CoE team. This role is responsible for performing regulatory and program management responsibilities, including designing and maintaining technology controls to support program and regulatory requirements. This role will require networking and relationship management skills to collaborate with the Controls Testing team, and various business units and risk teams across the enterprise. You will be working on:

  • Ensuring risk and control taxonomy aligns with enterprise standards
  • Developing and monitoring technology controls for security and compliance
  • Providing technical support and acting as liaison for technology risk management
  • Managing control updates, annual mapping, and testing requirements
  • Design, document, and maintain Risk and Control Matrices (RCMs/RACMs) across business and IT processes
  • Continuously improve and standardize control documentation and governance practices
  • Overseeing control certification process
  • Partnering with Control Testing team to track progress and remediation
  • Representing ETRA in enterprise control initiatives and special projects
  • Supporting regulatory activities, risk assessments, and examinations
  • Leading and supporting SOX 404 compliance, including control documentation
  • Reviewing SOC reports, assessing CUECs, and communicating control gaps
The Team

The Technology Risk Program and Regulatory Assurance team is responsible for managing controls to support program requirements, monitoring the results of control testing to meet program requirements, and ensuring a consistent risk and control taxonomy is leveraged in accordance with enterprise best practices. Additionally, this team supports regulatory activities such as maintaining application, server, and database inventories by entity. Technology Risk is part of the broader Legal, Risk and Compliance group and partners with Corporate Audit, Enterprise Compliance, and Security to protect the interests of our customers, our employees, and Fidelity's brand. You will also work closely with the Enterprise Technology Risk teams as well as Fidelity technology and business owners, and Operational Risk teams.

The Expertise and Skills You Bring
  • 5 -7 years' experience in information technology risk, controls, or audit roles
  • Bachelor's degree in computer science, technology, or a related field of study preferred
  • Professional technology and associated risk certifications (CISSP, CISA, CRISC, CISM), Certified risk/fraud examiners (CRE, CFE), and/or Cloud Certification(s) (CCSP, CCSK, AWS) preferred
  • Experience documenting controls for large scale financial service organizations (cloud, distributed, vendor solutions, mainframe, network environments, and AI)
  • Demonstrated technical abilities in multiple areas (e.g., technology infrastructure and application controls, cyber security, access management, network and cloud, resiliency, etc.)
  • Working knowledge of Cloud security and controls and cloud technology environments (AWS/Azure, SaaS, PaaS)
  • You have a strong knowledge of information technology processes and controls, and a comprehensive understanding of risk, quality control and assurance functions
  • Your love of solving complex problems, and comfort with ambiguous situations, and your ability to help solution innovative ways to mitigate risk using your advanced analytical and critical thinking skills
  • Your ability to build and maintain collaborative working relationships with Information Technology and Business personnel to design effective controls
  • Your process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
  • Knowledge of Industry standards, regulations, frameworks and best practices, such as NIST SP 800-53, COBIT, AICPA Trust Principles, ISO27001, SWIFT, HITRUST, and SOX404 is preferred
  • ISO9001 and/or ISO27001 certification preferred, with responsibility to support and participate in ISO peer audit reviews.
  • Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferred
  • Your excellent verbal and written communication skills enabling you to prepare and present recommendations to senior management

Note: Fidelity will not provide immigration sponsorship for this position.

Fidelity's Onsite Working Model

Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:

Category:

Information Technology Please be advised that Fidelity's business is g

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Technology Risk Analyst - Controls Testing
Principal Technology Risk Analyst - Controls Testing

Fidelity Investments Inc. • North Carolina

On-site
USD 140,000 - 205,000
Technology Risk Analyst
Technology Risk Analyst

Fidelity Investments Inc. • Roanoke (TX)

On-site
USD 70,000 - 110,000
Senior Technology Risk & SOX Compliance Lead
Senior Technology Risk & SOX Compliance Lead

Fidelity • United States

On-site
USD 120,000 - 180,000
Principal, Cybersecurity Risk
Principal, Cybersecurity Risk

Fidelity Investments • Durham (NC)

On-site
USD 120,000 - 180,000
Director, Technology Management - Software Engineering
Director, Technology Management - Software Engineering

Socket.dev • North Carolina

On-site
USD 180,000 - 260,000
Senior Technology Risk & Controls Testing Lead
Senior Technology Risk & Controls Testing Lead

Fidelity Investments Inc. • North Carolina

On-site
USD 140,000 - 205,000
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Tech Risk & Controls Lead
Tech Risk & Controls Lead

JPMorgan Chase & Co. • New York (NY)

On-site
USD 150,000 - 190,000
ETRA Senior Data Analyst
ETRA Senior Data Analyst

Fidelity Investments • Covington (VA)

On-site
USD 95,000 - 135,000
Principal Systems Analyst
Principal Systems Analyst

Fidelity Investments Inc. • Durham (NC)

On-site
USD 120,000 - 160,000