> Markdown version of [/jobs/ext/1581631-sr-it-risk-manager-risk-portfolio](https://www.wearedevelopers.com/jobs/ext/1581631-sr-it-risk-manager-risk-portfolio). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr IT Risk Manager - Risk Portfolio - **Company:** Early Warning Services, LLC. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $144,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Antivirus Softwares, Control Objectives for Information and Related Technology (COBIT), Information Leak Prevention, Multi-Factor Authentication, Information Technology Audit, Intrusion Detection Systems, Virtual Private Networks (VPN), PCI Data Security Standards, Security Information and Event Management, Firewalls (Computer Science), Information Technology, Vulnerability Analysis - **Published:** July 16, 2026 - **Apply:** https://earlywarning.wd5.myworkdayjobs.com/earlywarningcareers/job/San-Francisco/Sr-IT-Risk-Manager---Risk-Portfolio_REQ2026695 ## About the Role * Education and/or experience typically obtained through completion of a bachelor's degree in Computer Science, Business Administration, Finance or Accounting or equivalent experience. * 7 or more years of related experience. * Familiarity with ISO 27000, PCI DSS, NIST 800-53a, COBIT, FFIEC handbook, SOC2 Type II, GLBA, FCRA, FISMA. * Effective communication, organization, and presentation skills. * Background and drug screen., * 7+ years work experience in security, governance, compliance, IT audit, information technology, or related. * Certification in one of CISA, CISSP, CCSP, CRISC, or equivalent or ability to sit for one of the certifications within the first 12 months of hire. * Experience with security-related technologies including firewalls, IDS, SIEM, vulnerability scanners, anti-virus, data leak prevention, two factor authentication, and VPN. * Experience in implementing cloud transformational and operational risks and controls. * Experience in managing business continuity and disaster recovery initiatives. * Additional related education and/or experience preferred. ## Description At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like ZelleĀ®, Paze , and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship. Provide risk leadership in support of technology portfolios including supporting issues management (self identified, audit, regulatory and second line of defense observations). Provide program management support for large/complex risk remediation Develop and deliver executive level communication including risk updates, strategy materials and execution-focused presentations tailored to both technical and non-technical audiences. Translate complex risk matters into actionable plans. Working knowledge of Technical/Data/Security industry frameworks and regulatory requirements (FFIEC, NIST, ISO) Overview This position is responsible for execution of a Technology first-line of defense (LOD1) risk and internal control program for Early Warning. The role will be required to execute with the company's Enterprise Risk Management Leadership around the structure of the three lines of defense program to ensure the consistency in the implementation and operationalization across the enterprise. Essential Functions * Develop and maintain technology policies, standards, procedures, and guidelines. * Ensure that the policy approval process is followed. * Analyze policy and standard changes across the enterprise to identify impacts and solutions for Technology teams. * Maintain Technology's process inventory and internal control environment inventory. * Act as point of contact for technology focused external and internal audits and assessments (SOC2, PCI DSS, & others). * Effectively communicate technology and security related risks and vulnerabilities. * Validate solutions being implemented are in line with currently approved policy, in conjunction with Technology and Security teams. * Act as business-line liaison to Enterprise Risk Management and Operational Risk Management. * Perform control testing of technology controls for correct implementation and operation. * Create, facilitate, and manage risk identification and remediation processes. * Ensure risk remediation plans exist and are sufficient; track remediation plans to completion and ensure remediation is on-time and sustainable; ensure action plans and remediation of issues by Risk Owner. * Driving improvements in confidentiality, integrity, and availability. * Identify and implement processes improvement efforts. * Work with process and control owners to better define and implement control performance requirements. * Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data, Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers. Incumbents will follow instructions and perform other related duties as assigned by their supervisor. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume)