Principal Technology Risk Analyst

Posted 7 Days Ago
Be an Early Applicant
Boston, MA, USA
In-Office
140K-150K Annually
Senior level
Fintech
The Role
Lead and coordinate external technology audit activities, perform technology risk assessments, develop control strategies for cloud, DevOps, and emerging technologies (AI/ML/Snowflake), document and evaluate ITGC/ITAC controls, track findings, and support audit readiness and remediation efforts.
Summary Generated by Built In
Job Description:

Position Description:

***Applicants are permitted to work remotely from an at-home worksite anywhere in the United States.***

Facilitates all external audit activity related to financial reporting, independent controls attestation, and compliance with regulatory requirements. Performs proactive risk assessments and develops control strategies for emerging technologies, including AI, Machine Learning, and Snowflake data services. Runs external audits and technology risk support for inquiries from technology and operational stakeholders. Supports systems and technology for external audit activity, including attestation and financial statement audits.

Primary Responsibilities:

  • Enhances the external audit program activities focused on key technology areas, including DevOps, Cloud, and Technology Operations.
  • Coordinates external auditor readiness engagements and readiness assessments, and provides timely status updates to management.
  • Plans and coordinates audit cycles with external auditors and internal stakeholders.
  • Facilitates requests from external auditor and monitors the progress to ensure timely completion.
  • Performs technology risk assessments and develops control strategies; including documenting controls, identifying potential gaps and inconsistencies, and making recommendations for improvement and mitigation.
  • Provides technical assistance on risk related systems issues.
  • Serves as a liaison with technology and risk teams to track external audit findings and perform issues follow-up.
  • Consults with other team members to generate action plans and resolve technical issues.
  • Assesses the various information technology risks that the business faces in its operations and implements action plans, policy, and procedural changes for risk avoidance and mitigation.
  • Evaluates control maturity by performing control design and operating effectiveness reviews and

peer reviews.

  • Assists with conducting Cloud Risk assessments and readiness reviews for applications and workloads migrating to the public Cloud environment.

Education and Experience:

Bachelor’s degree in Computer Science, Engineering, Information Technology, Information Systems, Management Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal Technology Risk Analyst (or closely related occupation) performing Information Technology (IT) audits, risk assessments, and cybersecurity control reviews.

Or, alternatively, Master’s degree in Computer Science, Engineering, Information Technology, Information Systems, Management Information Systems,  or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal Technology Risk Analyst (or closely related occupation) performing Information Technology (IT) audits, risk assessments, and cybersecurity control reviews.

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise (“DE”) performing or coordinating external audit engagements (SOC 1, SOC 2, SOC 3, controls attestation reports, financial audits, ISO 27001, or COBIT external IT audit programs) in distributed environments; and maintaining in-scope IT General Control (ITGCs) and IT Application (ITAC) documentation and procedures.
  • DE performing an IT controls assurance program -- identifying and designing new controls, evaluating control procedures and evidence documentation, and conducting control assessments through formal design and operating effectiveness reviews; and establishing control maturity and control/process enhancements using industry control frameworks – AICPA Trust Service Criteria, HiTRUST, ISO 27001 certification standard, or NIST Cybersecurity frameworks.
  • DE performing risk management and IT audits, and implementing ITGC or cybersecurity controls for large-scale, complex IT infrastructures, including mainframe, distributed, network, cloud, and vendor hosted (SaaS/PaaS) infrastructure; reviewing vendor’s independent SOC 1 or SOC 2 audit reports to confirm the appropriate controls are in place for the services provided and to safeguard data; and creating executive communications focusing on risk, impact, and corrective actions, using Governance, Risk, and Compliance (GRC) tools.
  • DE performing risk assessments and IT audits of secure software development lifecycle processes and procedures -- automated build and deployment pipelines in a DevOps solutions framework, using Github, SonarQube, Jenkins, Artifactory, or uDeploy; and assessing software development controls, identifying potential gaps and inconsistencies, and making recommendations for improvement and mitigation.

Salary:  $140,000.00 - $150,000.00/year.

#PE1M2

#LI-DNI

Certifications:

Category:Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Skills Required

  • Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, Management Information Systems, or closely related field and five (5) years of experience as a Principal Technology Risk Analyst performing IT audits, risk assessments, and cybersecurity control reviews.
  • Master's degree in Computer Science, Engineering, Information Technology, Information Systems, Management Information Systems, or closely related field and three (3) years of experience as a Principal Technology Risk Analyst performing IT audits, risk assessments, and cybersecurity control reviews.
  • Demonstrated expertise performing or coordinating external audit engagements (SOC 1, SOC 2, SOC 3, controls attestation reports, financial audits, ISO 27001, or COBIT external IT audit programs).
  • Experience maintaining in-scope IT General Controls (ITGCs) and IT Application Controls (ITAC) documentation and procedures.
  • Experience executing an IT controls assurance program: identifying/designing controls, evaluating procedures and evidence, conducting design and operating effectiveness reviews, and assessing control maturity using AICPA Trust Service Criteria, HiTRUST, ISO 27001, or NIST frameworks.
  • Experience performing risk management and IT audits and implementing ITGC or cybersecurity controls for large-scale, complex IT infrastructures (mainframe, distributed, network, cloud, vendor hosted SaaS/PaaS); reviewing vendor SOC reports and using GRC tools; creating executive risk communications.
  • Experience performing risk assessments and IT audits of secure software development lifecycle processes and automated build and deployment pipelines in a DevOps framework using GitHub, SonarQube, Jenkins, Artifactory, or uDeploy.
  • Experience developing control strategies and performing risk assessments for emerging technologies, including AI, Machine Learning, and Snowflake data services.

Fidelity Investments Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Fidelity Investments and has not been reviewed or approved by Fidelity Investments.

  • Strong & Reliable Incentives Bonuses, commissions, and profit-sharing are presented as generous and meaningful components of total compensation, with certain roles achieving high total earnings through multiple pay streams. Variable pay is consistently framed as a positive contributor beyond base salary.
  • Retirement Support A 401(k) match up to 7% alongside additional profit-sharing up to 10% materially enhances long-term compensation. These retirement features are highlighted as standout strengths of the overall package.
  • Parental & Family Support Generous paid parental leave (16 weeks maternity, 12 weeks parental), backup dependent care, and adoption assistance provide robust family support. Hybrid work and caregiving resources further ease family responsibilities.

Fidelity Investments Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
58,848 Employees
Year Founded: 1946

What We Do

At Fidelity, our goal is to make financial expertise broadly accessible and effective in helping people live the lives they want. We do this by focusing on a diverse set of customers: - from 23 million people investing their life savings, to 20,000 businesses managing their employee benefits to 10,000 advisors needing innovative technology to invest their clients’ money. We offer investment management, retirement planning, portfolio guidance, brokerage, and many other financial products. Privately held for nearly 70 years, we’ve always believed by providing investors with access to the information and expertise, we can help them achieve better results. That’s been our approach- innovative yet personal, compassionate yet responsible, grounded by a tireless work ethic—it is the heart of the Fidelity way.

Similar Jobs

Citizens Logo Citizens

Data, AI and Emerging Technology Risk Principal Analyst

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees
138K-200K Annually
In-Office
Boston, MA, USA
58848 Employees
130K-137K Annually

Citizens Logo Citizens

Senior Technology Risk Analyst – Monitoring and Testing

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account