Sr. Technology Risk Analyst

Jersey City, United States

Brown Brothers Harriman

At Brown Brothers Harriman, we serve the most sophisticated individuals and institutions with expertise through our focused business lines: Investor Services, which offers custody, accounting, administration, capital market services, and...

View all jobs at Brown Brothers Harriman

Apply now Apply later

At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships.  We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.

Join us as a Sr. Technology Risk Analyst!

Brown Brothers Harriman is currently recruiting Sr. Technology Risk Analyst to join our Technology Risk Management team. 

The Sr. Technology Risk Analyst will drive the risk management through control analysis and risk assessments for the Systems organization.  The Sr. Technology Risk Analyst will coordinate and conduct IT risk and vulnerability assessments and supports the design and implementation of controls to mitigate risks.  This position is responsible for supporting and offering insight to IT and the Business into the risk identification, assessment, mitigation and reporting activities that help reduce operational IT risk. 

Some of your key responsibilities include:   

  • Risk Assessment and Management:
    • Identify and evaluate IT risks related to application development, application production support, database administration, data movement, middleware, distributed technologies, mainframe, data storage, desktop support, end-user computing and other infrastructure components.
    • Monitor technology risks for new and emerging initiatives and recommend proactive measures to address them.
    • Assess current technology control inventory and identify where a key control is needed or where a redundant control can be removed
    • Partner with fellow Risk Managers and Risk Governance team to identify and test controls to assess control effectiveness
    • Partner with senior risk managers to help conduct Risk and Control Self-Assessments (RCSAs) in specific Systems domains
    • Develop and implement risk management strategies to mitigate identified risks.
  • Policy and Compliance:
    • Ensure compliance with regulatory requirements such as NY-DFS and industry standards (DORA) related to IT risk management.
    • Develop, implement, and enforce IT risk management policies and procedures.
    • Partner with Risk Governance team to conduct annual refresh of Systems standards and Procedures
    • Collaborate with internal and external auditors to address compliance issues and audit findings.
  • Application Development Oversight:
    • Assess risks associated with new and existing applications, ensuring secure development practices.
    • Work with development teams to implement best practices for application security and data protection.
    • Evaluate third-party applications for security risks and compliance with bank policies.
    • Gauge the level of risk associated with risk exception requests by liaising with application development teams.
  • Database (DB) Security:
    • Conduct annual DB user access attestations to ensure continued compliance with standards
    • Oversee the security and integrity of the bank's databases, ensuring data is protected from unauthorized access.
    • Collaborate with database administrators to implement robust data protection measures.
    • Partner with cyber monitoring team to monitor database activities and address vulnerabilities and incidents promptly.
    • Gauge the level of risk associated with risk exception requests by liaising with database administration teams
  • Incident Response and Management:
    • Carry out post-incident response to IT security incidents by mapping incident root cause to controls and optimize as needed
    • Partner with the Business Continuity Planning (BCP) team to maintain and update the bank's IT incident response plan in compliance with industry regulations.
  • Collaboration and Communication:
    • Work closely with IT, compliance, and risk management teams to align technology risk management with overall risk strategy.
    • Communicate IT risk management strategies and policies to stakeholders across the organization.

Qualifications include:

  • Bachelor’s degree in systems or related discipline or specialized training required
  • 8+ years of relevant  technology risk,, cyber audit or related Cyber or Core Infrastructure experience (engineering, cyber, technology control assurance, Technology Operations)
  • 3+ years’ experience in the financial services industry preferred
  • Strong interpersonal and relationship management skills with a demonstrated ability to work in a changing Application Development environment, and produce results although the ask can often be ambiguous
  • Experience with IT risk and threat assessment methodologies
  • Knowledge of Cyber security protocols and industry best practices
  • Knowledge of operating platforms, database and sub-system platforms and products
  • Basic knowledge of IT regulatory and compliance requirements
  • Experience with standard desktop tools, including Microsoft Office
  • Ability to weigh business needs against risk concerns and articulate issues to management
  • Ability to handle multiple priorities, while meeting deadlines
  • Strong problem solving, organizational and project management skills
  • Strong written and verbal communication skills
  • Preferably holds one or more of the following or equivalent certifications: CISSP, CISM, CISA, CIA, CRISC, CGEIT CIAC, ISO
  • Experience with industry standard GRC Tools

This role is based in our Jersey City location and is a hybrid role, with three days per week in office.

   

Salary Range

$120k - $150k base salary + annual bonus target

BBH’s compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being. 


 

We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn’t followed a traditional path, includes alternative experiences, or doesn’t meet every qualification or skill listed in the job description, please do go ahead and apply.

About BBH:

Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us.

We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development—so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice—creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. 

We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often—pushing the boundaries of innovation.  As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours.

Go to BBH.com to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, age, genetic information, creed, marital status, sexual orientation, gender identity, disability status, protected veteran status, or any other protected status under federal, state or local law.
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Application security CIA CISA CISM CISSP Compliance CRISC Governance Incident response Mainframe Monitoring Risk assessment Risk management Strategy Vulnerabilities

Perks/benefits: Career development Competitive pay Salary bonus

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.