Job Summary
We are seeking an experienced Risk Manager to provide risk management oversight for Microsoft 365 applications and services. The role will focus on application risk governance, continuous monitoring, risk assessments, control reviews, remediation tracking, and technology risk management within a highly regulated enterprise environment.
Key Responsibilities
Manage application risk activities for Microsoft 365 platforms and related technologies.
Coordinate continuous monitoring activities and ensure compliance with enterprise risk standards.
Perform risk assessments, control reviews, gap analyses, and remediation tracking.
Partner with technology teams, application owners, information security teams, and risk organizations to identify and mitigate risks.
Facilitate risk reviews, issue management activities, and governance reporting.
Monitor and track risk findings through closure, ensuring appropriate documentation and stakeholder communication.
Support audit, regulatory, and compliance activities related to application controls and technology governance.
Evaluate security and compliance controls within Microsoft 365 environments.
Maintain documentation related to risk exceptions, control effectiveness, and remediation efforts.
Provide status updates to leadership regarding risk posture, open findings, and mitigation plans.
Work closely with internal governance teams to ensure adherence to evolving risk standards and policies.
Required Qualifications
5+ years of experience in technology risk management, operational risk, cybersecurity risk, or application governance.
Experience performing risk assessments, issue management, control reviews, and continuous monitoring activities.
Strong understanding of technology risk frameworks and governance processes.
Experience with risk remediation tracking and risk lifecycle management.
Ability to communicate effectively with technical teams, risk partners, auditors, and senior leadership.
Experience supporting highly regulated enterprise environments.
Preferred Qualifications
Familiarity with RISE and other internal risk tracking platforms.
Understanding of GIS risk processes and risk governance standards.
Experience supporting Microsoft 365 technologies and security controls.
Knowledge of Microsoft Purview, Conditional Access Policies, Tenant Restrictions, Information Protection, Identity Governance, and related M365 security capabilities.
Experience working with audit, compliance, and regulatory review processes.
Technical Skills
Microsoft 365
Microsoft Purview
Conditional Access
Tenant Restrictions
Identity and Access Management
Information Protection
Data Governance
Compliance Controls
Risk Monitoring and Reporting
Security Governance