Technology Risk & Continuity Analyst

Posted 8 Days Ago
Be an Early Applicant
Boston, MA, USA
Hybrid
100K-125K Annually
Mid level
Financial Services
The Role
The Technology Risk & Continuity Analyst supports security risk, business continuity, incident management programs, and performs risk functions including audits and access reviews.
Summary Generated by Built In
Company Profile
 
Founded in 1977, GMO is a global investment manager committed to delivering superior long-term investment performance and advice to our clients. We offer investment strategies and solutions where we believe we are positioned to add the greatest value for our investors. These include multi-asset class, equity, fixed income and alternative offerings.
 
We manage approximately $80bn for a client base that includes many of the world’s most sophisticated institutions, financial intermediaries, and private clients. Industry-wide, we are well known for our focus on valuation-based investing, willingness to take bold positions when conditions warrant, and candid and academically rigorous thought leadership. Jeremy Grantham, GMO’s Co-Founder and Long-Term Investment Strategist, is renowned as an expert in identifying speculative investment bubbles and also as a leading climate investor and advocate.
 
GMO is privately owned and employs over 430 people worldwide. We are headquartered in Boston, with additional offices in Europe, Asia and Australia. Our company-wide culture emphasizes commitment to clients, intellectual curiosity, and open debate. We celebrate and respect our differences, while embracing and valuing what each of us brings to work, as we know that diverse teams in an inclusive, caring environment achieve higher engagement and better client results.
 
Please follow the prompts included in this job posting to apply. The application window for this role is anticipated to remain open until the job is filled, or as otherwise determined by GMO.
 

Overview:

As a key member of the Security Risk & Audit team, the Technology Risk & Continuity Analyst supports the firm’s security risk, business continuity, and incident management programs, contributing across prevention, preparedness, and response activities.

This role performs core security risk functions such as risk and control support, audit readiness, access review coordination, and security awareness enablement. It also supports the development, maintenance, and testing of business continuity and incident response plans, including coordinating exercises and tracking remediation activities.

The analyst monitors threats and incidents, supports resilience and training platforms, and contributes to audit and due diligence efforts. Working closely with technology, risk, and business stakeholders, this role provides broad organizational exposure while helping ensure the firm is prepared for operational disruptions and cyber events, and continually improving its security posture.

We value individuals who are reliable, curious, collaborative, proactive, and strong communicators—professionals who enjoy problem-solving and are eager to build hands-on experience across security risk management, continuity planning, and incident management.

Primary Responsibilities:

Business Continuity

  • Work with all areas of the firm to map critical service dependencies and document recovery strategies through the BIA process, gathering recovery requirements, and identifying single points of failure
  • Support maintenance of Business Continuity and Incident Response Plans through regular reviews and exercises, with a focus on continuous improvement
  • Maintain program documentation including incident and exercise reporting, program metrics and reports for a variety of stakeholders
  • Develop and maintain BCP standards and templates.
  • Participate in Business Continuity and risk forums
  • Identify emerging risks (e.g., regulatory changes, natural and man-made risk) and perform risk assessments.
  • Administer and maintain the Riskonnect Resilience platform including monitoring platform updates, attending vendor training, and managing the vendor relationship

Security & Risk Management

  • Monitor IT incidents and document significant events
  • Prepare incident summaries for internal tracking and reporting
  • Coordinate security awareness programs via Learning Pool, including onboarding, annual training, and phishing simulations
  • Support internal and external audits by collecting evidence, documenting control activities, and maintaining audit artifacts
  • Assist with annual program reviews and audit readiness activities
  • Respond to client due diligence requests and RFPs, leveraging knowledge bases and SMEs as needed
  • Participate in vendor risk assessments, onboarding reviews, and ongoing monitoring of critical vendors

Job Requirements:

    • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Continuity, or a related field (or equivalent experience)
    • 2–5 years of experience in cybersecurity, business continuity, disaster recovery, operational risk, or IT risk management

Core Skills & Knowledge:

    • Interest in business continuity and operational resilience practices (BIAs, recovery strategies, dependency mapping, exercises, and issue remediation)
    • Familiarity with resilience or GRC platforms (e.g., Riskonnect or similar tools)
    • Ability to master learning management systems and security awareness training programs (e.g., Learning Pool)
    • Understanding of incident management frameworks and IT service management tools (e.g., ServiceNow)
    • Knowledge of client and third-party due diligence processes
    • Familiarity with threat intelligence sources and relevant frameworks/standards (e.g., NIST, ISO 22301, ITIL) is a plus

Professional Skills:

    • Strong written and verbal communication skills, with the ability to clearly document plans, exercises, and incidents
    • Excellent organizational skills and attention to detail, with the ability to manage multiple concurrent workstreams
    • Ability to collaborate across technology, risk, compliance, and business teams
    • Comfort facilitating discussions (e.g., tabletop exercises, walkthroughs), capturing outcomes, and driving follow-through
    • Continuous improvement mindset with the ability to learn, document, measure, and iterate

Certifications (Preferred):

    • ABCP, CBCP, Security+, or similar certifications are a plus

GMO is committed to the recruitment, employment, and promotion of all candidates equally, regardless of an individual's gender, race, color, national origin, ancestry, age, religion, pregnancy, marital status, sexual orientation, gender identity or expression, military or veteran status, genetic information, physical or mental disability (except where such disability is a bona fide occupational disqualification) or any other classification protected under federal, state or local law.

GMO will not offer visa sponsorship for this opportunity.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Continuity, or related field
  • 2-5 years of experience in cybersecurity, business continuity, disaster recovery, operational risk, or IT risk management
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
960 Employees
Year Founded: 1977

What We Do

For more than 40 years, GMO has partnered with a broad range of sophisticated institutions, financial intermediaries, and families to provide the investment expertise they need to meet their goals and fulfill their missions. Investing on behalf of our clients is GMO’s sole focus. Across asset classes and around the world, our investment teams identify and exploit long-term opportunities and develop solutions that both anticipate and respond to client needs. GMO is comprised of a collection of investment teams with focused specialties. All are grounded in a long-term, valuation-based investment philosophy – an approach we believe provides the best risk-adjusted returns. GMO partners with an impressive roster of sophisticated clients worldwide, delivering innovative investment solutions and tailored client service. Our clients benefit from our diverse expertise, intellectual curiosity, and open culture of debate, as well as from our ability and willingness to take advantage of contrarian market opportunities. For important disclosure information please visit: https://www.gmo.com/americas/terms-and-conditions/

Similar Jobs

PwC Logo PwC

Supply Chain Consulting - Relex Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
18 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
60 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

Data Engineer

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
65 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

Cybersecurity, Privacy and Forensics - Cyber Incident Response - Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
7 Locations
370000 Employees
99K-232K Annually

Similar Companies Hiring

Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account