Job offer
Lead - Technology Risk and Control Self-Assessment
The position of Lead for Technology Risk and Control Self-Assessment at Northeastern University in Chicago (hybrid) involves leading the IT risk assessment program and developing governance models and reporting structures. This full-time position requires a bachelor’s degree in IT or a related field, as well as experience in IT risk management, with a salary ranging from $65,000 to $145,000.
Tasks
- Support for the implementation and ongoing operation of the Technology Risk & Control Self-Assessment (CRSA) program within the Global Technology division
- Ensuring consistent reporting at the corporate level, monitoring, and reporting to senior management and risk committees, including alignment with enterprise risk management standards and relevant stakeholders
- Collaborate with technology leaders, control officers, CIOs, and compliance and audit teams to strengthen risk controls, identify risks, and escalate vulnerabilities
- Collaborate with risk and compliance teams to raise the profile of and increase awareness about enterprise risk management, as well as to assess the integrity of information
- Assessment of governance models and risks related to enterprise-wide technology risk areas, emerging risks, end-to-end controls, and the alignment of regulatory and vendor risk management
- Develop and oversee reporting metrics, dashboards, and management dashboards that support various strategic plans for future initiatives
- Maintain clear communication with business partners and maintain a central database for high-risk activities, including risk takers, control officers, and risk scores
- Optimizing risk quality, reporting capabilities, and the status of risk resolution, as well as maintaining a robust risk management framework
- Providing risk assessments and prioritizing vulnerabilities for risk assessment, trend analysis, and maintenance
- Maintaining and communicating the escalation to IT leadership to mitigate, resolve, or write off risks
- Support the proactive risk management cycle and ensure that technology risk management complies with industry best practices and regulatory requirements
- Ensuring that control objectives are met in all business processes and applications
- Development and Maintenance of the TRCA Methodology and Framework
- Coordination and implementation of TRCA assessments with key stakeholders
- Analysis and interpretation of TRCA results; identification of key risks and areas for improvement
- Providing recommendations and guidelines to senior management in the area of technology risk management
- Maintenance and updating of TRCA documentation and reporting
- Collaborate with IT, security, and compliance teams to ensure alignment and consistency
- Presentation of the TRCA results and findings to senior leadership and the Board of Directors
- Monitoring Industry Trends and New Technology Risks
Requirements
- Bachelor's degree in Information Technology, Cybersecurity, Information Security, Risk Management, or a related field
- Proven experience in technology risk or a related field
- Expertise in the risk function, including active IT-based tasks
- At least 5 years of experience in IT risk management, security, or compliance
- Proven experience in conducting risk assessments and developing risk mitigation strategies
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Ability to work both independently and as part of a team
- Familiarity with risk management frameworks such as COBIT, NIST, or ISO 27
Job details