Principal/Senior Technology Risk Analyst

Berkshire Hathaway Specialty Insurance

Boston, MA

JOB DETAILS
SKILLS
Accidental Death and Dismemberment (AD&D), Analysis Skills, Artificial Intelligence (AI), Auditing, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Committee of Sponsoring Organizations of the Treadway Commission (COSO), Communication Skills, Control Objectives for Information and related Technology (COBIT), Documentation, Hyperion Pillar, ISO (International Organization for Standardization), Insurance, International Electro-Technical Commission (IEC), Life Insurance, PCI, Performance Metrics, Process Improvement, Regulations, Reimbursement, Reporting Dashboards, Risk, Risk Analysis, Risk Management, Sarbanes-Oxley Act (SOX), ServiceNow, Team Player, Technical Leadership, Technology Analysis, Testing, U.S. National Institute of Standards and Technology (NIST), Vision Plan
LOCATION
Boston, MA
POSTED
Today

Role Overview Join the Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst to support and mature the Technology Risk Management pillar, ensuring technology risks are proactively identified, assessed, communicated, and monitored across the enterprise.What You Will Do Lead risk identification, risk assessment, and ongoing monitoring; drive Risk and Control Self-Assessments (RCAs) with different risk and control owners; define and socialize KRIs/KPIs, risk dashboards, trends, and heat maps.Why It Might Be a Fit If you're passionate about elevating enterprise Technology risk practices, driving meaningful change, and growing your career as a key contributor to our evolving global IT risk program, we're interested in speaking with you.Requirements 10+ years of experience in Technology risk, Technology audit/compliance, or cyber GRCExperience running RCSAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholdersStrong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plansEffective communication and partnership skills; able to challenge constructively and receive challenge professionallyExperience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow-upSolid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise), such as NIST CSF, COSO ERM, COBIT, etc.Working knowledge of U.S. Technology regulations (e.g., SOX, CCPA/CPRA, PCI, NY-DFS) is recommendedFamiliarity with global regulatory frameworks (e.g., GDPR, CBI, DORA, MAS, APRA, BaFin) is preferred but not requiredAbility to work in a team-based environment and communicate effectively and efficiently with others domestically and globallyExperience with GRC tools such as Workiva, AuditBoard, ServiceNow, Drata, Vanta, or similar platforms is a plusAI experience is a plus, including an understanding of AI risks, responsible AI concepts, or emerging AI regulatory requirementsProfessional certifications such as CRISC, CISA, CISM, CISSP, or ISO/IEC 27001 Lead Implementer/Lead Auditor (or equivalent) are a plusBenefits Comprehensive Health, Dental and Vision benefitsDisability Insurance (both short-term and long-term)Life Insurance (for you and your family)Accidental Death & Dismemberment Insurance (for you and your family)Flexible Spending AccountsHealth Reimbursement AccountEmployee Assistance ProgramRetirement Savings 401(k) Plan with Company MatchGenerous holiday and Paid Time OffTuition ReimbursementPaid Parental Leave#J-18808-Ljbffr

About the Company

B

Berkshire Hathaway Specialty Insurance