At Fidelity, we are focused on making our financial expertise broadly accessible and effective in helping people live the lives they want. We are a privately held company that places a high degree of value in creating and nurturing a work environment that attracts the best talent and reflects our commitment to our associates. We are proud of our diverse and inclusive workplace where we respect and value our associates for their unique perspectives and experiences. For information about working at Fidelity, visit FidelityCareers.com. Fidelity Investments is an equal opportunity employer.
Principal Technology Risk Analyst
Location
United States
Posted
5 days ago
Salary
$140K - $150K / year
Job Description
Job Description:
Position Description:
***Applicants are permitted to work remotely from an at-home worksite anywhere in the United States.***
Facilitates all external audit activity related to financial reporting, independent controls attestation, and compliance with regulatory requirements. Performs proactive risk assessments and develops control strategies for emerging technologies, including AI, Machine Learning, and Snowflake data services. Runs external audits and technology risk support for inquiries from technology and operational stakeholders. Supports systems and technology for external audit activity, including attestation and financial statement audits.
Primary Responsibilities:
- Enhances the external audit program activities focused on key technology areas, including DevOps, Cloud, and Technology Operations.
- Coordinates external auditor readiness engagements and readiness assessments, and provides timely status updates to management.
- Plans and coordinates audit cycles with external auditors and internal stakeholders.
- Facilitates requests from external auditor and monitors the progress to ensure timely completion.
- Performs technology risk assessments and develops control strategies; including documenting controls, identifying potential gaps and inconsistencies, and making recommendations for improvement and mitigation.
- Provides technical assistance on risk related systems issues.
- Serves as a liaison with technology and risk teams to track external audit findings and perform issues follow-up.
- Consults with other team members to generate action plans and resolve technical issues.
- Assesses the various information technology risks that the business faces in its operations and implements action plans, policy, and procedural changes for risk avoidance and mitigation.
- Evaluates control maturity by performing control design and operating effectiveness reviews and
peer reviews.
- Assists with conducting Cloud Risk assessments and readiness reviews for applications and workloads migrating to the public Cloud environment.
Education and Experience:
Bachelor’s degree in Computer Science, Engineering, Information Technology, Information Systems, Management Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal Technology Risk Analyst (or closely related occupation) performing Information Technology (IT) audits, risk assessments, and cybersecurity control reviews.
Or, alternatively, Master’s degree in Computer Science, Engineering, Information Technology, Information Systems, Management Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal Technology Risk Analyst (or closely related occupation) performing Information Technology (IT) audits, risk assessments, and cybersecurity control reviews.
Skills and Knowledge:
Candidate must also possess:
- Demonstrated Expertise (“DE”) performing or coordinating external audit engagements (SOC 1, SOC 2, SOC 3, controls attestation reports, financial audits, ISO 27001, or COBIT external IT audit programs) in distributed environments; and maintaining in-scope IT General Control (ITGCs) and IT Application (ITAC) documentation and procedures.
- DE performing an IT controls assurance program -- identifying and designing new controls, evaluating control procedures and evidence documentation, and conducting control assessments through formal design and operating effectiveness reviews; and establishing control maturity and control/process enhancements using industry control frameworks – AICPA Trust Service Criteria, HiTRUST, ISO 27001 certification standard, or NIST Cybersecurity frameworks.
- DE performing risk management and IT audits, and implementing ITGC or cybersecurity controls for large-scale, complex IT infrastructures, including mainframe, distributed, network, cloud, and vendor hosted (SaaS/PaaS) infrastructure; reviewing vendor’s independent SOC 1 or SOC 2 audit reports to confirm the appropriate controls are in place for the services provided and to safeguard data; and creating executive communications focusing on risk, impact, and corrective actions, using Governance, Risk, and Compliance (GRC) tools.
- DE performing risk assessments and IT audits of secure software development lifecycle processes and procedures -- automated build and deployment pipelines in a DevOps solutions framework, using Github, SonarQube, Jenkins, Artifactory, or uDeploy; and assessing software development controls, identifying potential gaps and inconsistencies, and making recommendations for improvement and mitigation.
Salary: $140,000.00 - $150,000.00/year.
#PE1M2
#LI-DNI
Certifications:
Category:
Information TechnologyMost roles at Fidelity are Hybrid, requiring associates to work onsite every other week (all business days, M-F) in a Fidelity office. This does not apply to Remote or fully Onsite roles. Some roles may have unique onsite requirements. Please consult with your recruiter for the specific expectations for this position.
Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.
Related Guides
Related Categories
Related Job Pages
More Risk Jobs
Risk Analyst 1
CorpayCorpay is an Equal Opportunity Employer. Corpay provides equal employment opportunities to all qualified applicants without regard to race, color, gender (including pregnancy), religion, national origin, ancestry, disability, age, sexual orientation, gender identity or expression, marital status, language, ancestry, genetic information and/or military status or any other group status protected by federal or local law. If you require reasonable accommodation for the application and/or interview process, please notify a representative of the Human Resources Department. This salary range is provided for locations which require such disclosure. Where a position or applicant may fall in a particular wage range varies depending on a number of factors, including but not limited to skill sets, experience, training, licensure and certifications (if applicable), and other business and organization needs. The disclosed range has not been adjusted for the applicable geographic markets. At Corpay, it is not typical for an individual to be hired at or near the top of the range for their role, and compensation decisions are dependent on the facts and circumstances of each case. For more information about our commitment to equal employment opportunity and pay transparency, please click the following links: EEO and Pay Transparency .
Corpay is currently looking to hire a Risk Analyst within our Comdata division. This position falls under our Corporate Payments line of business and is located in Brentwood, TN. In this role, you will: Investigate risk-related cases Identify fraud trends Support internal teams w...
Industry Principal - Governance, Risk & Compliance (GRC)
Workiva Inc.Workiva is committed to working with and providing reasonable accommodations to applicants with disabilities. To request assistance with the application process, please email earlycareer@workiva.com. Workiva employees are required to undergo comprehensive security and privacy training tailored to their roles, ensuring adherence to company policies and regulatory standards. Workiva supports employees in working where they work best - either from an office or remotely from any location within their country of employment.
This role involves operationalizing practitioner insights from Governance, Risk & Compliance (GRC) to inform and drive marketing and sales strategies for Workiva solutions, collaborating across multiple departments to scale the dissemination of this expertise. The Industry Principal acts as a subject matter expert and influencer, guiding product marketing, sales enablement, and product roadmap development based on deep GRC practitioner experience.
This role will conduct Property Risk Assessment surveys and service at complex applicant and written business to determine overall risk. In addition, a unique opportunity exists to train and mentor field staff, as well as serve as a technical property resource for Risk Engineerin...
The Senior Risk Management Professional identifies and analyzes potential sources of loss to minimize risk. The Senior Risk Management Professional work assignments involve moderately complex to complex issues where the analysis of situations or data requires an in-depth evaluati...