×
Register Here to Apply for Jobs or Post Jobs. X

Principal​/Senior Technology Risk Analyst

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: Berkshire Hathaway Specialty Insurance
Full Time position
Listed on 2026-09-20
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 140000 - 170000 USD Yearly USD 140000.00 170000.00 YEAR
Job Description & How to Apply Below

Role Overview

Join the Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst to support and mature the Technology Risk Management pillar, ensuring technology risks are proactively identified, assessed, communicated, and monitored across the enterprise.

What You Will Do

Lead risk identification, risk assessment, and ongoing monitoring; drive Risk and Control Self-Assessments (RCAs) with different risk and control owners; define and socialize KRIs/KPIs, risk dashboards, trends, and heat maps.

Why It Might Be a Fit

If you're passionate about elevating enterprise Technology risk practices, driving meaningful change, and growing your career as a key contributor to our evolving global IT risk program, we’re interested in speaking with you.

Requirements
  • 10+ years of experience in Technology risk, Technology audit/compliance, or cyber GRC
  • Experience running RCSAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholders
  • Strong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plans
  • Effective communication and partnership skills; able to challenge constructively and receive challenge professionally
  • Experience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow-up
  • Solid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise), such as NIST CSF, COSO ERM, COBIT, etc.
  • Working knowledge of U.S. Technology regulations (e.g., SOX, CCPA/CPRA, PCI, NY-DFS) is recommended
  • Familiarity with global regulatory frameworks (e.g., GDPR, CBI, DORA, MAS, APRA, BaFin) is preferred but not required
  • Ability to work in a team-based environment and communicate effectively and efficiently with others domestically and globally
  • Experience with GRC tools such as Workiva, Audit Board, Service Now, Drata, Vanta, or similar platforms is a plus
  • AI experience is a plus, including an understanding of AI risks, responsible AI concepts, or emerging AI regulatory requirements
  • Professional certifications such as CRISC, CISA, CISM, CISSP, or ISO/IEC 27001 Lead Implementer/Lead Auditor (or equivalent) are a plus
Benefits
  • Comprehensive Health, Dental and Vision benefits
  • Disability Insurance (both short-term and long-term)
  • Life Insurance (for you and your family)
  • Accidental Death & Dismemberment Insurance (for you and your family)
  • Flexible Spending Accounts
  • Health Reimbursement Account
  • Employee Assistance Program
  • Retirement Savings 401(k) Plan with Company Match
  • Generous holiday and Paid Time Off
  • Tuition Reimbursement
  • Paid Parental Leave
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary