POSITION TITLEManager, Technology & Cybersecurity Risk / Risk Data Analyst
POSITION LOCATIONRichmond, VA
This position is available to Virginia residents as Richmond, Virginia in-office applicants
*A Hybrid schedule of both Remote and In-Office days is required. In office days are Tuesday, Wednesday and Thursday with working hours targeting our core business hours of 9am-5pm EST.
YOUR ROLEThe Enterprise Manager, Technology and Cybersecurity Risk / Risk Data Analyst is a senior individual contributor responsible for identifying, assessing, monitoring, and reporting risks across technology, cybersecurity, and third-party domains, while leading risk data analytics, reporting, and automation efforts.
This role combines strong expertise in technology, cybersecurity, and third-party risk management with advanced capabilities in data analytics, executive storytelling, and automation, leveraging tools such as Power BI, Power Automate, PowerPoint, and AI-enabled solutions to modernize risk management processes and deliver actionable insights to leadership.
At the Manager level, this role operates with minimal supervision, significant independent judgment, and cross-functional influence, contributing to key organizational risk objectives.
What you will be doing1. Technology Risk Management
- Lead and execute enterprise-wide technology risk assessments across applications, infrastructure, cloud platforms, and data environments.
- Identify, evaluate, and prioritize risks related to system availability, security, resilience, and data integrity.
- Maintain and manage the technology risk register, including risk identification, scoring, and remediation tracking.
- Evaluate and challenge the design and effectiveness of IT general controls (ITGCs) and application controls.
- Align risk and control frameworks to industry standards (e.g., NIST, ISO 27001, COBIT, SOC 2, CIS Controls).
- Partner with Technology and Security teams to drive control improvements and remediation of identified risks.
- Support risk appetite and tolerance definition, including development and monitoring of key risk indicators (KRIs).
- Provide oversight and challenge to ensure risks are properly identified and managed within technology initiatives, projects, and change efforts.
- Support regulatory, audit, and compliance activities by providing documentation, evidence, and subject matter expertise.
- Monitor emerging technology risks (e.g., cloud, AI, cyber threats) and translate them into actionable mitigation strategies.
2. Cybersecurity Risk Oversight
- Lead cybersecurity risk assessments across enterprise environments (on-prem, cloud, hybrid)
- Partner with Information Security leadership to identify and prioritize cyber risks
- Evaluate cybersecurity controls across key domains:
- Identity & Access Management (IAM)
- Data protection & encryption
- Network and endpoint security
- Incident response capabilities
- Assess alignment to frameworks (NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls)
- Oversee vulnerability management, penetration testing, and remediation tracking
- Support cyber incident readiness (tabletop exercises, post-incident reviews)
- Evaluate risks in emerging areas (cloud, AI, ransomware, supply chain threats)
- Monitor evolving threat landscape and regulatory expectations
- Develop cybersecurity KRIs and executive reporting
- Provide independent risk challenge to security initiatives and control designs
3. Contribute to
AI / generative AI cybersecurity risk management3. Risk Data Analytics & Reporting
- Collect, validate, and analyze risk data from multiple sources (GRC tools, security platforms, vendor systems).
- Develop and maintain Power BI dashboards (risk registers, KRIs, vendor risk metrics, trend analysis).
- Produce executive-level PowerPoint presentations with clear, compelling risk narratives.
- Identify trends, anomalies, and emerging risks through advanced data analysis.
- Support data-driven decision-making through actionable insights and visualization.
- Ensure data accuracy, governance, and repeatability of reporting processes.
4. Automation & AI Enablement
- Design and implement Power Automate workflows to streamline risk processes (e.g., assessments, approvals, reporting).
- Identify and eliminate manual processes through automation and process optimization.
- Leverage AI and Generative AI tools to enhance reporting, summarization, and analysis.
- Implement continuous improvement initiatives to increase efficiency and reduce cycle time.
- Support responsible use of AI by identifying and mitigating associated risks (e.g., data privacy, bias, accuracy).
What you bringExperience
- 5+ years of experience in one or more of the following: Technology / Cyber Risk, Risk Management / GRC, or Risk Data Analytics.
- Experience conducting risk assessments and managing remediation activities.
- Familiarity with industry risk and control frameworks (e.g., NIST, ISO, SOC).
Technical & Analytical Skills
- Strong proficiency in Power BI (dashboarding, data modeling).
- Advanced Microsoft Excel skills for analytics and data manipulation.
- Advanced PowerPoint skills for executive presentations.
- Experience building dashboards, reports, and risk analytics.
- Ability to translate data into insights and actionable recommendations.
Automation & AI
- Experience using Power Automate or similar workflow automation tools.
- Familiarity with AI / Generative AI tools to improve productivity and analysis.
- Experience in leveraging API's to access, share and aggregate data.
Communication Skills
- Strong written and verbal communication skills.
- Proven ability to create executive-level storytelling and presentations.
- Ability to translate technical concepts into business-friendly language.
Education
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Business, Risk Management, Finance, or a related field.
Nice to have- Professional certifications such as CISA, CRISC, CISM, CISSP, CTPRP, or PMP.
- Master's degree (MBA, MS Cybersecurity, or related field).
- Experience with GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust).
- Knowledge of cloud platforms (AWS, Azure, GCP).
- Experience with scripting or data tools (SQL, Python, PowerShell).
- Experience presenting to senior leadership or risk committees.
COMPENSATIONNational Range: $109,000 - 169,000
Disclaimer: This role is aligned to a national market-based pay range. Actual compensation will vary based on geographic location, experience, skills, and other job-related factors. In addition to base salary, this role is eligible to participate in a bonus incentive plan. Incentive compensation is based on individual and company performance and is not guaranteed.
ADDITIONAL - This role is not eligible for employment visa sponsorship.
Employee Benefits & Well-BeingGenworth employees make a difference in people's lives every day. We're committed to making a difference in our employees' lives.
- Competitive Compensation & Total Rewards Incentives
- Comprehensive Healthcare Coverage
- Multiple 401(k) Savings Plan Options
- Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded!)
- Generous Paid Time Off - Including 12 Paid Holidays, Volunteer Time Off and Paid Family Leave
- Disability, Life, and Long Term Care Insurance
- Tuition Reimbursement, Student Loan Repayment and Training & Certification Support
- Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management)
- Caregiver and Mental Health Support Services