> Markdown version of [/jobs/ext/1207357-lead-it-risk](https://www.wearedevelopers.com/jobs/ext/1207357-lead-it-risk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead, IT Risk - **Company:** Gemini Trust Company, LLC. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $99,400.0 - $142,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Data Governance, PCI Data Security Standards, Real-Time Operating Systems, Smartsuite - **Published:** July 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4350067f131a65fb ## About the Role * Bachelor's or advanced degree in Information Security, Risk Management, or related field. * 8+ years of experience in IT internal audit, IT risk management, or related roles in highly regulated industries with strong knowledge of IT risk, cybersecurity, operational risk, and third-party/vendor risk. * Proven experience in implementing risk management frameworks, control testing, and data governance. * Familiarity with regulatory requirements (NYDFS, SOC2, PCI DSS). * Excellent communication and stakeholder engagement skills., * Previous experience working at a digital asset institution. * At least one relevant industry certification (e.g., CISSP, CISM, CRISC, CISA). * Experience with GRC tools (e.g., AuditBoard, Archer). * Strong executive presence with ability to drive enterprise-wide alignment. ## Description The Lead of Technology Risk position is predominantly focused on helping the overall risk management group and different areas of technology to come together. This role will be helping establish areas from a risk and control perspective and working as a bridge between IT and security stakeholders, the business and the risk management department., Risk Assessment & Monitoring * Execute the IT Risk Management Framework, including risk identification, analysis, and reporting. * Conduct annual IT risk assessments, including RCSAs, targeted risk reviews, and new product/key initiative assessments. * Maintain the IT risk register; ensure timely updates and accurate reporting of exposures. * Perform post-mortem risk reviews for critical incidents and support operational loss reviews with ORM. Governance & Frameworks * Assist the Head of IT Risk in maintaining risk policies, standards, and procedures that align with Gemini's enterprise risk management program and regulatory expectations (NYDFS, DFS, OCC, CFTC). * Coordinate with Technology and Security teams to ensure policies and controls are properly implemented and followed. * Help prepare materials for risk committees, regulators, and senior leadership. Controls & Testing * Partner with Internal Audit, IT, Security, and BCM to assess design and operating effectiveness of IT and cyber controls. * Support control testing for internal/external audits, RCSAs, and regulatory examinations. * Track remediation and validate closure of issues using GRC tool(s). Collaboration & Stakeholder Management * Serve as a liaison between IT Risk and other functional areas, facilitating risk awareness and control adoption. * Provide guidance to IT teams on risk and control considerations for new projects, initiatives, and system changes. * Contribute to risk awareness training and initiatives across the organization. Reporting & Metrics * Assist in the development of periodic risk dashboards and key risk indicators (KRIs). * Support the Head of IT Risk in communicating IT risk posture to senior leadership. * Support development of IT & Security dashboards; ensure metric accuracy and timely updates. Business Continuity & Resilience * Execute and maintain the Business Continuity Management (BCM) program, including governance artifacts, testing, audits, and issue remediation. * Assess and manage business continuity risks, including people dependencies, facilities, physical security, and third-party operational resilience. * Drive crisis response and regulatory notifications (e.g., NYDFS), including escalation, documentation, and external stakeholder coordination. * Validate vendor BCM compliance and define and monitor business impact thresholds (RTOs, RPOs, tolerances), supporting ongoing impact assessments and reporting. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [AI beyond the code: Master your organisational AI implementation.](https://www.wearedevelopers.com/videos/1248-ai-beyond-the-code-master-your-organisational-ai-implementation) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Why SmartGit Is More Than a Git Client](https://www.wearedevelopers.com/magazine/689-why-smartgit-is-more-than-a-git-client) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 161: Gemini 2.5, AI killing search, EU A11Y Act](https://www.wearedevelopers.com/magazine/569-dev-digest-161-gemini-2-5-ai-killing-search-eu-a11y-act) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)