Senior Technical Risk Analyst

U.S. Navy
Vienna, VA, United States
about 1 month ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$114,500.0 - $179,500.0
Working hours
Regular working hours

Tech stack

Cloud Computing Cyber Security Disaster Recovery Information Technology Audit IT Management Network Architecture Smartsuite IT General Controls (ITGC) Information Technology Servicenow

Job description

Responsible for assessing and managing technical risks across the organization’s IT and operational environments. Works closely with cross-functional teams to identify and analyze emerging technology risks, implement risk management strategies, and maintain compliance with industry standards and regulations. Plays a key role in developing frameworks for risk identification, reporting, mitigation, and control. Responsible for understanding the technological landscape, implementing risk management frameworks, and ensuring that the organization adheres to industry standards and regulatory requirements. Work under minimal supervision and use complete understanding of business needs and objectives to support projects that have impact on the achievement of operational goals. Advanced skill set and proficiency with procedures and techniques., * Lead efforts to identify technical risks related to IT infrastructure, applications, systems, and data

  • Perform detailed risk assessments of IT projects, vendors, and systems to identify vulnerabilities and potential threats
  • Analyze new technologies and business processes to determine associated risks
  • Stay informed about emerging cybersecurity threats and vulnerabilities that could affect the organization
  • Develop and implement risk management frameworks, policies, and procedures
  • Prioritize risks based on business impact, and work with stakeholders to design and implement mitigation strategies
  • Work with IT and business teams to embed risk management into technology projects, operational processes, and product development
  • Manage the remediation of technical vulnerabilities and track risk reduction efforts
  • Ensure that risk management processes align with internal policies, regulatory requirements, and industry standards (e.g., ISO 27001, NIST, GDPR, SOX, etc.)
  • Lead internal and external audits by providing risk assessments, compliance reports, and documentation
  • Partner with compliance and legal teams to monitor adherence to regulatory changes impacting technology risks
  • Lead or assist in investigating technical incidents and breaches, conducting root cause analyses, and recommending corrective actions
  • Collaborate with security and IT teams to develop response strategies for cybersecurity incidents
  • Prepare and present post-incident reports and lessons learned to management
  • Prepare and present regular reports to senior management and stakeholders on the status of technical risks, trends, and mitigation efforts
  • Maintain accurate and comprehensive documentation of all risk assessments, controls, and mitigation strategies
  • Assist in the creation of technical risk dashboards for ongoing monitoring
  • Act as a subject matter expert on technical risk and provide guidance to other teams across the organization
  • Facilitate workshops and training sessions to enhance risk awareness and promote best practices
  • Collaborate with internal teams such as IT, cybersecurity, compliance, legal, and audit to ensure a cohesive approach to risk management
  • Continuously evaluate and enhance risk management frameworks and tools
  • Monitor the evolving threat landscape and emerging technologies to update risk strategies and frameworks accordingly
  • Promote a culture of risk awareness and proactive risk management throughout the organization

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, Risk Management, or a related field or equivalent combination of training, education and experience
  • 8+ years of experience in IT audit, internal/external audit, risk management, or security controls testing
  • Strong experience with IT General Controls (ITGCs), control frameworks, and audit methodologies (SOX or internal audit)
  • Complete knowledge and understanding of business area/specialization
  • Experience in technical risk management, cybersecurity, or IT governance
  • Hands-on experience with risk assessments, risk frameworks, and mitigation strategies
  • Proven experience in managing and mitigating cybersecurity risks
  • Advanced knowledge of risk management principles, frameworks (e.g., ISO, NIST, COSO), and regulatory compliance requirements
  • Advanced understanding of IT systems, network architecture, cloud technologies, and cybersecurity
  • Excellent analytical, problem-solving, and decision-making skills
  • Strong interpersonal and communication skills, with the ability to convey complex risk concepts to non-technical stakeholders
  • Experience in working with incident management, disaster recovery, and business continuity planning
  • Ability to work in a fast-paced environment with tight deadline, * Master’s Degree in related field or equivalent combination of training, education and experience
  • Professional certifications such as CISA, CISSP, CRISC, CPA, or similar
  • Experience with GRC tools such as ServiceNow or LogicManager
  • Knowledge of Enterprise Risk Management (ERM) frameworks and risk taxonomy
  • Experience leading cross-functional projects and mentoring team members
  • Experience supporting regulatory exams or acting as a primary liaison for auditors
  • Experience improving audit efficiency and standardizing testing approaches

Benefits & conditions

  • 2026 Handshake Early Talent Award * Newsweek America’s Greatest Workplaces for Culture, Belonging and Community 2026 From Fortune Magazine. 2026 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune 100 Best Companies to Work For are registered trademarks of Fortune Media IP Limited and are used under license. Fortune Magazine, Fortune Media (USA) Corporation, and its affiliates are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union. Equal Employment Opportunity: All qualified applicants will receive consideration for employment without regard to age, race, sex, color, religion, national origin, disability, veteran status, pregnancy, sexual orientation, genetic information, gender identity or any other basis protected by applicable law. Accommodations: If you need accommodation or assistance for a qualifying condition to complete the online application (or during any stage of the hiring process)

About the company

Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks. Our approach to careers is simple yet powerful: Make our mission your passion. * FORTUNE 100 Best Companies to Work For 2026 * Yello and WayUp Top 100 Internship Programs 2025 * Computerworld Best Places to Work in IT 2026 * Most Loved Workplace - America’s Top Most Loved Workplaces 2025 * 2025 PEOPLE Companies That Care * Newsweek Most Trustworthy Companies in America 2026 * Military Times 2025 Best for Vets Employers * Forbes 2026 America’s Best Large Employers * Forbes 2025 America’s Best Employers for New Grads * Forbes 2025 America’s Best Employers for Tech Workers * 2025 RippleMatch Campus Forward Award Winner for Overall Excellence * Military.com Top Military Spouse Employers 2025

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

Videos

See all

Related articles

See all