Senior Manager Technology Risk
Listed on 2026-09-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About Our Company
We’re a diversified financial services leader with more than $1.5 trillion in assets under management, administration and advisement as of year-end 2024. Our team of 22,000 people across 19 countries, serves more than 3.5 million individual, small business and institutional clients. We are a longstanding leader in financial planning and advice, a global asset manager and an insurer. Our unwavering focus on our clients and strong financial foundation connects each of our unique businesses – Ameriprise Financial, Columbia Threadneedle Investments and River Source Insurance and Annuities.
Here, we foster meaningful careers, invest in the future, and make a difference for clients, institutions and communities around the world.
The Senior Manager, Technology Risk is a Second Line of Defense (2
LOD) role reporting to the VP, Technology Risk Office. Responsible for leading technology and cyber risk oversight activities across assigned business areas, providing independent review and credible challenge of technology risk management practices, and supporting adherence to enterprise risk management standards. This role partners closely with Technology, Information Security, and business leaders to identify, assess, and mitigate risk while fostering a strong risk culture across the organization.
- Lead risk oversight activities for assigned technology and cyber domains.
- Provide credible challenge to first line risk management practices, ensuring alignment with enterprise standards.
- Identify emerging risk themes and escalates concerns appropriately.
- Support governance forums and risk committees through preparation of materials, risk reporting, and follow-up actions.
- Lead execution and review of Risk and Control Self-Assessments within assigned areas.
- Challenge risk and control assessments to ensure completeness and consistency.
- Support implementation and ongoing enhancement of ORM methodologies and standards.
- Review and challenge management responses to technology and cyber risk events.
- Ensure issues are appropriately documented, escalated, and remediated.
- Analyze trends and recommend proactive actions to reduce future risk exposure.
- Assess technology and business changes for potential risk impact.
- Partner with stakeholders to evaluate controls associated with significant initiatives and transformations.
- Support governance processes related to strategic technology change.
- Develop risk reporting, dashboards, and management information.
- Analyze risk trends and provide insights to support decision-making.
- Recommend improvements to risk management practices, reporting, and monitoring capabilities.
- Serve as a subject matter expert and trusted advisor to business and technology stakeholders.
- Mentor junior team members and provide guidance on risk methodologies and best practices.
- Contribute to team initiatives, process improvements, and strategic objectives.
- Bachelor's degree or equivalent experience required. Advanced degree preferred.
- 7–10+ years of experience in technology risk, cyber risk, operational risk, audit, information security, or related discipline.
- Strong knowledge of IT operational processes, technology controls, cybersecurity practices, and risk management frameworks.
- Working knowledge of NIST, COBIT, ISO
27000, FFIEC, and related regulatory standards. - Ability to independently assess risk exposures and provide effective challenge.
- Strong analytical and problem‑solving skills.
- Ability to influence stakeholders across multiple levels of the organization.
- Strong written and verbal communication skills.
- Experience utilizing GRC/eGRC platforms and reporting tools.
- Ability to manage multiple priorities and work independently.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).