Principal/Senior IT Risk Analyst

Berkshire Hathaway Specialty Insurance

$160K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in IT risk, audit/compliance, or cyber GRC.
  • Experience with Risk and Control Self-Assessments (RCSAs) and risk presentation to senior leaders.
  • Strong documentation, including risk narratives and control designs.
  • Effective communication and constructive challenge skills.
  • Vendor risk review experience, including SOC 2 analysis.
  • Knowledge of risk/control frameworks like NIST CSF and COSO ERM.
  • Working knowledge of U.S. regulations (e.g., SOX, CCPA/CPRA) and familiarity with global frameworks.

Responsibilities

  • Lead risk identification and monitoring, maintaining the IT risk register.
  • Drive RCSAs and advise on control designs across multiple domains.
  • Define and communicate risk indicators and dashboards to stakeholders.
  • Collaborate with Vendor Risk Management on assessments and control remediation.
  • Track risk issues and validate remediation actions.
  • Support global offices in IT risk obligations and requests.
  • Assess AI use cases for compliance and governance, ensuring documentation.
  • Educate teams on risk expectations and embed risk thinking into operations.

Benefits

  • Comprehensive Health, Dental, and Vision benefits.
  • Disability Insurance (short-term and long-term).
  • Life and Accidental Death & Dismemberment Insurance.
  • Flexible Spending Accounts and Health Reimbursement Account.
  • Employee Assistance Program.
  • 401(k) Retirement Savings Plan with Company Match.
  • Generous Paid Time Off and holidays.
  • Tuition Reimbursement and Paid Parental Leave.
Full Job Description
Job Opportunity:

Berkshire Hathaway Specialty Insurance (BHSI) has an exciting opportunity for a new team member to join their Boston-based IT Governance Risk Audit & Compliance (GRAC) team as an IT Senior Risk Analyst. In this newly created role, the IT Senior Risk Analyst will support and mature the IT Risk Management pillar, ensuring technology risks are proactively identified, assessed, communicated, and monitored across the enterprise. This role will build strong partnerships with Technology leadership and collaborate closely with teams across BHSI to evaluate our IT risk posture, provide independent challenge, and recommend practical risk-reducing actions aligned with our established risk appetite. If you're passionate about elevating enterprise IT risk practices, driving meaningful change, and growing your career as a key contributor to our evolving global IT risk program, we're interested in speaking with you.

Duties & Responsibilities:

  • Lead risk identification, risk assessment, and ongoing monitoring; maintain the IT risk register and ensure risks map to business objectives and risk appetite/tolerances.
  • Drive Risk and Control Self-Assessments (RCAs) with different risk and control owners; advise on control design for identity & access, change/release, resiliency/DR, cloud security, data protection, and vulnerability management.
  • Define and socialize KRIs/KPIs, risk dashboards, trends, and heat maps; deliver clear status to Technology leadership, and key stakeholders.
  • Partner with Vendor Risk Management Team to evaluate critical vendors (including AI-enabled services), review SOC reports/certifications, assess control gaps, and track remediation/compensating controls through closure.
  • Track risk issues, action plans, and target dates; validate remediation and retest where needed; participate in lessons-learned and scenario exercises.
  • Provide support to our offices from both a U.S. and global perspective (i.e., Asia, Middle East, UK, Europe, Australasia, etc.) regarding the fulfillment of IT risk related requests and obligations.
  • Assess AI/automation use cases for explainability, privacy, security, and bias risk; ensure appropriate documentation, monitoring, and governance are in place.
  • Educate teams on risk expectations, evidence quality, and the "why" behind controls; help embed risk thinking into delivery and operations.
  • Attend/participate in e-learning training sessions to increase background knowledge of the ever-evolving IT regulatory landscape.


Qualifications, Skills and Experience:

  • 10+ years of experience in IT risk, IT audit/compliance, or cyber GRC.
  • Experience running RCSAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholders.
  • Strong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plans.
  • Effective communication and partnership skills; able to challenge constructively and receive challenge professionally.
  • Experience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow-up.
  • Solid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise), such as NIST CSF, COSO ERM, COBIT, etc.
  • Working knowledge of U.S. IT regulations (e.g., SOX, CCPA/CPRA, PCI, NY-DFS) is recommended.
  • Familiarity with global regulatory frameworks (e.g., GDPR, CBI, DORA, MAS, APRA, BaFin) is preferred but not required.


  • Ability to work in a team-based environment and communicate effectively and efficiently with others domestically and globally.
  • Experience with GRC tools such as Workiva, AuditBoard, ServiceNow, Drata, Vanta, or similar platforms is a plus.
  • AI experience is a plus, including an understanding of AI risks, responsible AI concepts, or emerging AI regulatory requirements.
  • Professional certifications such as CRISC, CISA, CISM, CISSP, or ISO/IEC 27001 Lead Implementer/Lead Auditor (or equivalent) are a plus.


BHSI Offers:

  • A competitive package and exciting growth opportunities for career-oriented teammates.
  • A dynamic, action oriented, and thoughtful environment centered on always doing the right thing for our customers, teammates and our other stakeholders.
  • A purposely non-bureaucratic organization that embraces simplicity over complexity and emphasizes individual excellence in a team framework.
  • Benefits that support your life and well-being, which include:
    • Comprehensive Health, Dental and Vision benefits.
    • Disability Insurance (both short-term and long-term).
    • Life Insurance (for you and your family).
    • Accidental Death & Dismemberment Insurance (for you and your family).
    • Flexible Spending Accounts.
    • Health Reimbursement Account.
    • Employee Assistance Program.
    • Retirement Savings 401(k) Plan with Company Match.
    • Generous holiday and Paid Time Off.
    • Tuition Reimbursement.
    • Paid Parental Leave.


The base salary range for this position in Boston is $160,000.00 to $180,000.00, along with annual bonus eligibility. Total compensation for a candidate is determined by their relevant skills, location, and experience. We value our teammates - both their capabilities and character - as demonstrated by our amazing culture.

NOTE: Compensation will be commensurate with experience. This job description is not intended to be all-inclusive. Team Member may perform other related duties as negotiated to meet the ongoing needs of the organization.

Similar Jobs

More Jobs at Berkshire Hathaway Specialty Insurance

More Information Technology Jobs

Find similar Principal/Senior IT Risk Analyst jobs: