Jobs · Virginia

Enterprise Manager, Technology & Cybersecurity Risk

Genworth · Richmond, VA · 2 wk ago
$109k–$169k/yrFull-time

About the role

The Enterprise Manager, Technology & Cybersecurity Risk is a senior individual contributor responsible for leading risk identification, assessment, and mitigation activities across the organization’s technology environment, with a strong emphasis on technology and cybersecurity risk management and supporting oversight of third-party risk.

This role serves as a subject matter expert in technology risk, partnering closely with Technology, Cybersecurity, and Business teams to ensure risks are effectively managed, controls are appropriately designed, and regulatory and industry expectations are met. This role operates with minimal supervision, significant independent judgment, and cross-functional influence, contributing to enterprise risk objectives and strengthening the organization’s overall risk posture.

Responsibilities

  • Lead and execute enterprise-wide technology risk assessments across applications, infrastructure, cloud platforms, and data environments.

  • Identify, evaluate, and prioritize risks related to system availability, security, resilience, and data integrity.

  • Maintain and manage the technology risk register, including risk identification, scoring, and remediation tracking.

  • Evaluate and challenge the design and effectiveness of IT general controls (ITGCs) and application controls.

  • Align risk and control frameworks to industry standards (e.g., NIST, ISO 27001, COBIT, SOC 2, CIS Controls).

  • Partner with Technology and Security teams to drive control improvements and remediation of identified risk.

  • Support risk appetite and tolerance definition, including development and monitoring of key risk indicators (KRIs).

  • Provide oversight and challenge to ensure risks are properly identified and managed within technology initiatives, projects, and change efforts.

  • Support regulatory, audit, and compliance activities by providing documentation, evidence, and subject matter expertise.

  • Monitor emerging technology risks (e.g., cloud, AI, cyber threats) and translate them into actionable mitigation strategies.

Cybersecurity Risk Oversight

  • Lead cybersecurity risk assessments across enterprise environments (on-prem, cloud, hybrid).

  • Partner with Information Security leadership to identify and prioritize cyber risks.

  • Evaluate cybersecurity controls across key domains: Identity & Access Management (IAM), Data protection & encryption, Network and endpoint security, Incident response capabilities.

  • Assess alignment to frameworks (NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls).

  • Oversee vulnerability management, penetration testing, and remediation tracking.

  • Support cyber incident readiness (tabletop exercises, post-incident reviews).

  • Evaluate risks in emerging areas (cloud, AI, ransomware, supply chain threats).

  • Monitor evolving threat landscape and regulatory expectations.

  • Develop cybersecurity KRIs and executive reporting.

  • Provide independent risk challenge to security initiatives and control designs.

  • Contribute to AI / generative AI cybersecurity risk management.

Risk Reporting & Insights

  • Develop and deliver clear, concise risk reporting for leadership, including risk summaries, key issues, and trends.

  • Support development of risk dashboards and reporting artifacts.

  • Translate complex technology risks into business-relevant narratives for executive stakeholders.

  • Contribute to risk committee materials and presentations.

Ai Enablement

  • Leverage AI and Generative AI tools to enhance reporting, summarization, and analysis.

  • Implement continuous improvement initiatives to increase efficiency and reduce cycle time.

  • Support responsible use of AI by identifying and mitigating associated risks (e.g., data privacy, bias, accuracy).

Qualifications

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business, or a related field.

  • 5+ years of experience in: Technology Risk / IT Risk, Cybersecurity Risk, IT Audit / Controls, Risk Management / GRC.

  • Strong experience conducting technology risk assessments and control evaluations.

  • Familiarity with IT control frameworks and regulatory expectations.

  • Deep understanding of: IT General Controls (ITGCs), Application controls, Cybersecurity principles and practices.

  • Strong understanding of risk identification, assessment, and mitigation methodologies.

  • Ability to clearly communicate technical risks to non-technical stakeholders.

  • Experience with frameworks such as: NIST, ISO 27001, COBIT, SOC 2, CIS Controls.

  • Professional certifications such as: CISA, CRISC, CISM, CISSP.

  • Experience with GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust).

  • Experience in cloud risk management (AWS, Azure, GCP).

  • Exposure to third-party risk management frameworks and practices.

Skills

  • Strong communication skills.

  • Experience preparing executive-level risk summaries and presentations.

Benefits

Genworth offers competitive compensation and total rewards, including:

  • Competitive Compensation & Total Rewards

  • Incentive compensation based on individual and company performance.

  • Healthcare coverage, multiple 401(k) savings plans, auto enrollment in employer-directed retirement account feature (100% employer-funded!), disability, life, and long-term care insurance.

  • Tuition reimbursement, student loan repayment, and training & certification support.

  • Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management).

  • Caregiver and mental health support services.

Similar jobs