Sr. Risk Manager, Cyber & Technology Risk Management

Brown Brothers Harriman

Boston (MA)

Hybrid

USD 140,000 - 190,000

Full time

22 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Brown Brothers Harriman (BBH) in Boston/ Jersey City seeks a Senior Risk Manager to lead cyber and technology risk oversight in a high-stakes financial services environment. You will partner with technology, security, and business teams, guiding risk assessments, control design, and remediation efforts to protect critical assets and data.

This role requires a track record of influencing senior stakeholders, deep knowledge of regulatory frameworks, and the ability to translate complex risk

Qualifications

  • Bachelor’s degree, equivalent work experience, specialized training in information technology, cybersecurity, risk management, audit, or related discipline.
  • 10+ years of experience in cyber risk, technology risk, information security, IT audit, operational risk, third-party risk, or a related control function.
  • Demonstrated experience assessing cyber risk programs, cybersecurity controls, and information security governance frameworks within a regulated financial institution or similarly regulated environment.

Responsibilities

  • Partner with technology, security, and operations teams to identify, assess, and manage cyber and technology risks.
  • Provide independent second-line advisory and effective challenge, translating risk considerations into clear, practical guidance.
  • Lead and/or support risk and control assessments, including cyber risk reviews, RCSAs, application risk assessments, external assurance reviews, and related governance activities.
  • Evaluate control gaps, risk acceptances, exceptions, and remediation plans; prioritize actions based on business impact, risk appetite, and regulatory expectations.
  • Analyze new and emerging risks, including regulatory requirements and supervisory guidance; collaborate with control owners on control design, implementation, and measurement.
  • Support the continued build-out of a new IT governance platform to improve integration, transparency, and execution across Cyber & Technology Risk Management programs.

Skills

Cyber risk management
Regulatory frameworks
Information security
Risk assessments
Governance
Communication
Analytical thinking

Education

Bachelor’s degree in IT/cybersecurity

Job description

At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.

Cyber & Technology Risk Management is an independent second-line risk function within Enterprise Risk Management (ERM). The group is aligned to the Firm’s global Systems/Technology organization and provides risk oversight across a complex financial services environment. The Senior Risk Manager will serve as a trusted second-line advisor, leading a team of cyber and technology risk professionals responsible for identifying, assessing, and helping manage cyber and technology risks that impact the Firm. The Senior Risk Manager is expected to bring broad technical knowledge with expertise in cyber risk management and related regulatory frameworks including information security, cyber resilience, data protection, and regulatory compliance across the Firm's technology environment.

This is a senior, highly visible role that partners closely with Systems/Technology management, Application and Data Owners, control owners, Compliance, Internal Audit, Line of Business leadership, and peer leaders across Cyber & Technology Risk Management and ERM to promote sound risk decisions, strong governance, and practical outcomes.

Responsibilities
What You’ll Do
  • Partner with technology, security, and operations teams to identify, assess, and manage cyber and technology risks.
  • Provide independent second-line advisory and effective challenge, translating risk considerations into clear, practical guidance.
  • Lead and/or support risk and control assessments, including cyber risk reviews, RCSAs, application risk assessments, external assurance reviews, and related governance activities.
  • Evaluate control gaps, risk acceptances, exceptions, and remediation plans; assist stakeholders prioritize actions based on business impact, risk appetite, and regulatory expectations.
  • Analyze new and emerging risks, including related regulatory requirements and supervisory guidance to identify risk implications and potential gaps; collaborate with control owners on control design, implementation, and measurement.
  • Support the continued build-out of a new IT governance platform to improve integration, transparency, and execution across Cyber & Technology Risk Management programs.
Qualifications
What You’ll Bring
  • Bachelor’s degree, equivalent work experience, specialized training in information technology, cybersecurity, risk management, audit, or related discipline.
  • 10+ years of experience in cyber risk, technology risk, information security, IT audit, operational risk, third-party risk, or a related control function.
  • Demonstrated experience assessing cyber risk programs, cybersecurity controls, and information security governance frameworks within a regulated financial institution or similarly regulated environment.
  • Ability to analyze complex risk issues, balance business objectives with control expectations, and communicate practical recommendations to both technical and non-technical audiences.
  • Strong understanding of cyber and technology risk concepts, control assessment, issue management, remediation tracking, risk acceptance, and risk reporting practices.
  • Strong knowledge of cybersecurity regulatory requirements and industry frameworks, including NYDFS Part 500, NIST Cybersecurity Framework, ISO 27001, and other applicable cybersecurity or operational resilience standards.
  • Familiarity with DORA, global operational resilience requirements, and other emerging cyber regulatory frameworks.
  • Working knowledge of technology environments, including networks, operating platforms, cloud services, application security, and third-party hosted solutions.
  • Certifications such as CISSP, CISM, and/or CRISC are a plus.

This role can be based in either our Boston or Jersey City locations and will be a hybrid role, with a minimum of three (3) days in office.

Salary Range

NJ / MA: $140,000 - $190,000 base salary + annual target bonus

BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.

We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn’t followed a traditional path, includes alternative experiences, or doesn’t meet every qualification or skill listed in the job description, please do go ahead and apply.

About BBH

Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us.

We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development—so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice—creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another.

We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often—pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to-day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours.

Go to BBH.com to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, age, genetic information, creed, marital status, sexual orientation, gender identity, disability status, protected veteran status, or any other protected status under federal, state or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Risk Manager, Cyber & Technology Risk Management
Sr. Risk Manager, Cyber & Technology Risk Management

Brown Brothers Harriman • Jersey City (NJ)

Hybrid
USD 140,000 - 190,000
Hybrid work model
Competitive compensation
Sr. Risk Manager, Cyber & Technology Risk Management
Sr. Risk Manager, Cyber & Technology Risk Management

Brown Brothers Harriman & Co. • Boston (MA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Hybrid work model
Senior Cyber Threat Analyst
Senior Cyber Threat Analyst

Brown Brothers Harriman • Boston (MA)

On-site
USD 110,000 - 160,000
Annual bonus target
Professional development opportunities
Profit-sharing
Cyber Red Team Operator
Cyber Red Team Operator

Brown Brothers Harriman • Jersey City (NJ)

On-site
USD 120,000 - 160,000
Sr. Cybersecurity Program Analyst
Sr. Cybersecurity Program Analyst

Brown Brothers Harriman • Jersey City (NJ)

On-site
USD 110,000 - 160,000
Senior Risk Analyst
Senior Risk Analyst

Brown Brothers Harriman • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Cyber Incident Response Manager
Cyber Incident Response Manager

Brown Brothers Harriman & Co. • Jersey City (NJ)

On-site
USD 150,000 - 180,000
Discretionary bonuses
Profit-sharing
Professional development opportunities
Web Security Engineer
Web Security Engineer

Brown Brothers Harriman & Co. • Jersey City (NJ), Northern (KY)

On-site
USD 100,000 - 130,000
Cyber Red Team Operator
Cyber Red Team Operator

Brown Brothers Harriman • Philadelphia

On-site
USD 120,000 - 160,000
Cyber Incident Response Manager
Cyber Incident Response Manager

Brown Brothers Harriman • Boston (MA)

On-site
USD 150,000 - 180,000
Discretionary bonuses
Profit-sharing
Professional development opportunities
+1