Senior Technology Governance Consultant - IT Asset Risk Classification Governance
Listed on 2026-08-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Consultant
Language Fluency: English (Required)
Work Shift: 1st shift (United States of America)
Job Grade: 112
Please review the following job description:
The IT Asset Risk Classification (ITARC) Governance Lead is responsible for the design, governance, and continuous improvement of the enterprise technology asset risk classification methodology. This role partners across Cybersecurity, Operational Resilience, Data Governance, Technology Risk, and business stakeholders to establish risk-based criteria, define scoring models, and ensure consistent assessment of technology assets based on their inherent and residual risk characteristics.
The position leads the development and maintenance of a comprehensive risk scoring framework that incorporates cybersecurity, resilience, data sensitivity, business criticality, and regulatory considerations into a consolidated ITARC score. The individual is responsible for defining risk indicators, establishing weighting methodologies, validating scoring outcomes, and providing governance oversight to ensure the methodology remains accurate, auditable, and aligned with enterprise risk management objectives.
This role requires a strong understanding of technology governance, risk management, cybersecurity, resilience, and data management principles, along with the analytical skills necessary to translate complex risk factors into meaningful and actionable risk classifications. The successful candidate will support executive reporting, risk prioritization, audit and regulatory inquiries, and strategic decision-making by providing reliable and defensible technology risk insights across the enterprise.
ESSENTIAL DUTIES AND RESPONSIBILITIESFollowing is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
- 1. Implements and continuouslyimprovestechnologygovernanceframeworks, policies, and procedures.
- 2. Provides detailed andtimelyreporting on technology risk posture and compliance to senior management and regulatory bodies.
- 3. Collaborates with cross-functional teams to integrategovernanceinto technology projects, operations, and governance processes.
- 4. Supports internal and external reporting by preparing documentation, responding to inquiries,andmayfacilitaecontrol testing.
- 5. Monitors emerging technology risks and regulatory changes, recommending proactive adjustments togovernancestrategies.
- 6. Manages large, complex technologygovernanceprojects and assignments and provides guidance and coaching to junior professionals and project teams within the technologygovernancedomain.
- 7. Drives risk awareness andcomplianceculture across technology teams through training and communication initiatives.
- 8. Directs comprehensive technologygovernanceassessments and control testing toidentifyvulnerabilities and ensure effective risk mitigation.
Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- 1. Bachelor’s degree in Information Technology, Information Security, Engineering, or related field.
- 2. Minimum of 7 years of professional experience in technologygovernance.
- 3. Strong knowledge of regulatory requirements and compliance frameworks.
- 4. Experience applyinggovernanceassessment methodologies and control frameworks.
- 1. Master’s degree in a relevant technical or business discipline.
- 2. Experience in the financial services industry.
- 3. Professional certifications such as CRISC, COBIT, CGEIT, CISM3, or equivalent.
- 4. Strong knowledge of cybersecurity capabilities and frameworks and financial industry regulations.
- 5. Proven ability to manage complex technology governance projects, programs, and initiatives.
All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).