Technology Risk Analyst Sr
Location: Troy, MI 48098
About the Role
The Technology Risk Analyst Sr. is responsible for creating, maintaining, assessing, and reporting on the status of information technology and information security threats, risks, and controls. This position identifies and documents potential gaps, tests and validates control adherence, and recommends and validates risk mitigation. Additionally, this role performs enterprise-wide cyber and technology risk assessments, creates formal risk assessment reports, and communicates findings to senior leadership.
Responsibilities
- Govern and risk assess technology and security programs, including policies, standards, controls, procedures, and testing requirements for the technology and security organization in line with NIST 800-53, NIST 800-37, Secure Controls Framework, and industry best practices.
- Design, validate, track, and report risk mitigation strategies in line with the company risk appetite. Communicate results to stakeholders, including executive leadership.
- Perform complex enterprise-wide risk assessments, including mapping out threats and controls, identifying gaps, and determining inherent and residual risk ratings in adherence with the enterprise Risk Governance Framework. Create formal risk assessment reports and present to executive leadership.
- Assist stakeholders in business lines and technology in understanding risk and control requirements to ensure risk responsibilities are understood and followed throughout the enterprise. Mentor junior associates on complex technical concepts and best practices.
- Use independent judgment and discretion to make decisions and analyze and resolve problems.
- Perform special projects and additional duties as required.
- Consistently adhere to regulatory and compliance policies and standards linked to the job and complete required compliance trainings. Maintain compliance with applicable federal, state, and local laws and regulations.
Requirements
- Education: High School diploma, GED, HiSET, TASC, or foreign equivalent.
- Minimum experience: 4+ years in Technology Audit, Information Technology, or Information Security.
- Certification: Security+, CISA, CRISC, CISSP, or equivalent.
Skills
- Strong understanding of internal/external processes and deadlines.
- Expertise in technology and security risk mitigation.
- Expertise in risk assessment and control development.
- Experience designing risk and control programs aligned to FFIEC, NIST 800-53, NIST 800-37, and financial services regulatory requirements.
- Knowledge of technology organization business processes and systems.
- Experience creating and maintaining threat and risk registers and explaining residual risk to non-technical audiences.
- Expertise in creating and maintaining KPIs and KRIs.
- Prior experience implementing or overseeing cross-functional, enterprise-wide projects and technologies.
- Well-rounded understanding of technology, operations, and key business processes.
- Strong ability to build and maintain effective relationships with stakeholders through clear communication, proactive collaboration, and leveraging cross-functional insights.
- Aligns relationship-building efforts with enterprise goals to accelerate performance and drive strategic results.
- Builds trusted client relationships by identifying needs and delivering tailored solutions to enhance the overall client experience.
- Fosters or supports a positive work culture and productive work environment, emphasizing effective relationships with customers and stakeholders.
Travel
Less than 10% travel required.
Physical Demands
No unusual physical exertion is involved.
Pay
Pay Range: $79,537.50 - $129,179.00
Benefits
Flagstar provides teammates access to a variety of benefits, including medical, dental, vision, life, and disability insurance, as well as a comprehensive leave program. For detailed information, visit Benefits | Flagstar Bank.