Sr. Lead Technology Risk Officer (App Domain, SDLC, DevOps & AI) - TX

MSCCN

Irving (TX)

On-site

USD 120,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

MSCCN in Irving, Texas seeks an Application Risk Domain Officer to provide second-line oversight across application domains within Technology Risk Management. You will define risk assessment, monitoring, and reporting approaches, evaluating risk conditions and controls to inform enterprise risk.

The role requires deep technical knowledge of modern engineering practices, including SDLC, CI/CD, IaC, cloud-native architectures, software supply chain security, and AI-enabled workflows.

Qualifications

  • 7+ years of Technology Risk experience.
  • Experience across software engineering, DevSecOps, platform or cloud engineering, or technology risk preferred.

Responsibilities

  • Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls.
  • Own second-line technology risk coverage and provide thought leadership across the application risk domain, partnering with engineering, controls and technology teams to drive consistent oversight.
  • Perform rigorous assessments of source control workflows, branching strategies, build systems, test automation, artifact repositories, package dependencies, deployment orchestration, and runtime platform configurations.

Skills

Technology Risk
DevSecOps
Software Engineering
Cloud Engineering
Application Security
CI/CD
IaC
Kubernetes
Observability

Tools

GitHub/GitLab
Jenkins/Azure DevOps
Terraform
Containers
Kubernetes
Cloud Platforms
Observability
Security Testing

Job description

ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their open roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set, education requirements, and experience, please follow the next steps. All positions are onsite, unless otherwise stated.

About this role:

The Application Risk Domain Officer operates within Technology Risk Management (TRM), part of Corporate Risk, providing independent second line oversight across application domains. The role is a member of the Application Risk Domain Team, which performs domain level evaluation and produces evidence-based views of how application conditions contribute to enterprise risk exposure. The role engages with Technology, including Tech Operations, CIO organizations, to provide challenge and inform risk-based decisions. Outputs from this role support enterprise risk views provided to senior management, risk committees, and regulators.

The Application Risk Domain Officer is responsible for defining and advancing domain-level risk assessment, monitoring, and reporting approaches. This includes evaluating application-related risk conditions, assessing the effectiveness of risk management practices and controls, and developing evidence-based views of how those conditions contribute to enterprise technology risk exposure.

The role requires strong technical understanding of modern application engineering practices, including SDLC, CI/CD, infrastructure as code, cloud-native architectures, developer platforms, software supply chain processes, and AI-enabled engineering workflows. Due to the breadth and complexity of the domain, preference will be given to candidates who have operated, managed, or led one or more technology capabilities for which they will provide independent risk oversight. The successful candidate must be capable of engaging engineering teams with technical credibility, providing effective challenge on complex technology matters, and translating technical observations into clear, decision-ready insights for senior management, risk committees, and regulatory stakeholders.

In this role, you will:

  • Provide expert second-line oversight of modern engineering practices, including application architecture patterns, secure SDLC, CI/CD, DevSecOps, platform engineering, infrastructure as code, containerized workloads, and production release controls.
  • Own second-line technology risk coverage and provide thought leadership across the application risk domain, partnering closely with first-line engineering, controls and technology teams to drive consistent oversight of application architecture, development practices, deployment pipelines, and supporting engineering controls.
  • Perform technically rigorous assessments of source control workflows, branching strategies, build systems, test automation, artifact repositories, package dependencies, deployment orchestration, and runtime platform configurations to identify control weaknesses and systemic risk.
  • Evaluate the integrity of software delivery pipelines end to end, including code provenance, pipeline trust boundaries, secrets handling, approval models, environment segregation, artifact immutability, and rollback or recovery capabilities.
  • Lead deep-dive technical risk reviews of complex delivery environments and modernization programs, converting architecture, pipeline, and operational observations into clear risk statements, root causes, and targeted remediation expectations.
  • Analyze developer ecosystems and engineering tool chains at a practitioner level, including repositories, CI runners, build agents, package managers, IaC frameworks, containers, Kubernetes, cloud services, and observability stacks.
  • Evaluate AI-enabled engineering capabilities, including code assistants, prompt-based development workflows, automated test generation, agentic tooling, and model-integrated developer platforms, with emphasis on data exposure, unsafe code generation, traceability, and human review requirements.
  • Review design and implementation patterns for application and platform controls, such as policy-as-code, secrets management, service identity, environment hardening, logging, monitoring, drift detection, and release gating.
  • Develop technically meaningful risk indicators and challenge metrics for SDLC, DevSecOps, and AI-enabled engineering, such as deployment control exceptions, pipeline bypasses, privileged access patterns, dependency exposure, control coverage gaps, and remediation aging.
  • Serve as a trusted technical risk partner to engineering, security, architecture, and control teams by applying expert discipline knowledge to high-impact decisions and shaping resilient engineering practices across the enterprise.
Required Experience

Required Qualifications:

  • 7+ years of Technology Risk experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.

Job Expectations: This position does not offer sponsorship

Posting End Date:

  • 2 Oct 2026
Preferred Experience

Desired Qualifications:

  • 7+ years of progressive experience in software engineering, DevSecOps, platform or cloud engineering, application security, technology controls, or technology risk. Front-line experience leading or operating technology capabilities is strongly preferred
  • Proven technical depth across modern SDLC and DevSecOps, including source control, CI/CD, automated testing, deployment automation, production change controls, and software supply chain security.
  • Demonstrated ability to lead complex technical risk assessments, evaluate control effectiveness, identify systemic risk, and provide credible challenge across SDLC, DevSecOps, cloud, software supply chain, and AI-enabled engineering environments.
  • Ability to challenge complex technical decisions with credibility by evaluating application architectures, deployment models, engineering evidence, technical standards, and control implementations.
  • Strong command of modern engineering platforms and security toolchains, including GitHub or GitLab, Jenkins or Azure DevOps, Terraform, containers, Kubernetes, cloud platforms, application security testing, and observability tools.
  • Experience implementing or assessing critical engineering controls across secure build and release processes, code provenance, secrets management, privileged automation, infrastructure as code, environment segregation, and runtime security.
  • Understanding of emerging AI engineering risks and controls, including AI coding assistants, automated code generation, agentic workflows, data exposure, traceability, and human oversight.
  • Exceptional judgment, executive communication, and influencing skills, with the ability to translate complex technical risks into clear business impact, actionable remediation, and decision-ready reporting.
  • Knowledge of NIST, SSDF, COBIT, FFIEC guidance, or ISO 27001. Financial services or regulated-industry experience and relevant security, risk, cloud, or software lifecycle certifications are preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Lead Technology Risk Officer (App Domain, SDLC, DevOps & AI) - NC
Sr. Lead Technology Risk Officer (App Domain, SDLC, DevOps & AI) - NC

MSCCN • Charlotte (NC)

On-site
USD 120,000 - 160,000
Compliance and Operational Risk Manager – Application Security and Technology Risk Oversight
Compliance and Operational Risk Manager – Application Security and Technology Risk Oversight

Cybersecurity Jobs • Charlotte (NC)

On-site
USD 120,000 - 180,000
Tech Risk and Controls Lead - Citizen Development Governance User Experience & Support
Tech Risk and Controls Lead - Citizen Development Governance User Experience & Support

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 120,000 - 180,000
Tech Risk and Controls Lead - Infrastructure Platforms
Tech Risk and Controls Lead - Infrastructure Platforms

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 130,000 - 190,000
AI Tech Risk and Controls Lead
AI Tech Risk and Controls Lead

JPMorgan Chase & Co. • Palo Alto (CA)

On-site
USD 140,000 - 210,000
Tech Risk and Controls Lead - Digital Platforms
Tech Risk and Controls Lead - Digital Platforms

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 125,000 - 160,000
Tech Risk and Controls Lead - Citizen Development Governance Project Management and Release Coordination
Tech Risk and Controls Lead - Citizen Development Governance Project Management and Release Coordination

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 140,000 - 200,000
Tech Risk and Controls Lead - Citizen Development Governance & Analytics
Tech Risk and Controls Lead - Citizen Development Governance & Analytics

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 140,000 - 190,000
Technology Risk and Controls Lead
Technology Risk and Controls Lead

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 140,000 - 210,000
AI Tech Risk & Controls Lead
AI Tech Risk & Controls Lead

JPMorgan Chase & Co. • Palo Alto (CA)

On-site
USD 180,000 - 240,000