Navy Federal Credit Union

Principal Technical Risk Analyst

Navy Federal Credit Union$110K — $130K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or master's degree in Cybersecurity, Information Technology, Risk Management or related field.
  • Significant experience leading risk assessments for business initiatives in regulated environments.
  • Familiarity with the First, Second, and Third Lines of Defense (1LOD, 2LOD, 3LOD).
  • Strong background in Information Security and cybersecurity risk management.
  • Experience evaluating fraud and physical security risks in technology projects.
  • Proven ability to influence stakeholders across multiple functions and departments.
  • Demonstrated expertise in process improvement methodologies like Lean or Six Sigma.

Responsibilities

  • Lead and conduct New Business Initiative Assessments (NBIAs) for new or changing initiatives.
  • Determine assessment scope and necessary stakeholders based on initiative risks.
  • Facilitate cross-functional risk discussions with stakeholders across various departments.
  • Assess risks associated with cybersecurity, fraud, and operational processes.
  • Identify control gaps and conditions for implementation or launch of initiatives.
  • Document clear assessment records and maintain governance compliance for audits.
  • Track assessment actions and escalate significant concerns through governance.

Benefits

  • Comprehensive healthcare and wellness programs.
  • Retirement savings plan with company match.
  • Generous paid time off and leave options.
  • Professional development and training opportunities.
  • Flexible work environment promoting work-life balance.
Full Job Description
Job Description

Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.

Responsible for leading and performing New Business Initiative Assessments (NBIAs) for proposed and changing products, services, technologies, processes, partnerships, and business capabilities. The role evaluates risk across the initiative lifecycle, identifies material concerns and control needs, and helps business and risk partners reach well-informed, timely decisions. It requires practical experience working across the First, Second, and Third Lines of Defense (1LOD, 2LOD, and 3LOD), with clear understanding of each line's responsibilities, independence, and role in effective challenge and assurance.

The Principal Tech Risk Analyst partners with initiative owners and key stakeholders across Information Security, Fraud, Physical Security, Technology, Enterprise Risk, Compliance, Legal, Privacy, Procurement and Vendor Management, Internal Audit, and other relevant functions. The role translates complex technical and operational risks into clear business language, facilitates cross-functional assessments, documents decisions and evidence, and drives issues through resolution. The analyst also applies process improvement and Lean Six Sigma methods to improve NBIA intake, scoping, assessment, handoffs, cycle time, data quality, reporting, and stakeholder experience. Work is performed independently on complex, high-impact initiatives, with the individual serving as a recognized subject matter expert and trusted advisor.

Responsibilities

  • Lead and perform NBIAs for new or materially changing products, services, technologies, processes, third-party relationships, and business capabilities.
  • Determine assessment scope, applicable risk domains, required stakeholders, evidence needs, decision points, and escalation paths based on the nature and risk of the initiative.
  • Partner effectively across 1LOD, 2LOD, and 3LOD, respecting role clarity, ownership, effective challenge, independent oversight, and assurance responsibilities.
  • Facilitate cross-functional risk discussions with initiative owners and stakeholders in Information Security, Fraud, Physical Security, Technology, Enterprise Risk, Compliance, Legal, Privacy, Procurement and Vendor Management, Internal Audit, and other relevant areas.
  • Assess risks related to cybersecurity, data protection, fraud, physical security, technology resilience, third parties, regulatory obligations, operational processes, and control design.
  • Identify risk themes, control gaps, dependencies, unresolved decisions, and conditions that must be satisfied before implementation or launch.
  • Evaluate whether proposed controls are clearly defined, appropriately owned, supported by evidence, and designed to reduce risk to an acceptable level.
  • Provide credible, constructive challenge and translate technical, security, fraud, and operational concerns into plain business language for both technical and non-technical audiences.
  • Develop clear assessment records, risk statements, recommendations, action plans, approvals, exceptions, decision rationales, and evidence trails that support governance and audit needs.
  • Track assessment actions and dependencies through closure, coordinating with accountable owners and escalating overdue or material concerns through established governance channels.
  • Prepare concise, decision-ready reporting for senior leaders and governance forums, including material risk, open issues, required actions, ownership, and readiness considerations.
  • Apply Lean Six Sigma and other process improvement methods to identify waste, reduce handoff delays, simplify intake and assessment steps, improve data quality, and strengthen the consistency and timeliness of NBIA outcomes.
  • Develop and maintain NBIA procedures, templates, tools, decision criteria, training materials, metrics, dashboards, and stakeholder guidance.
  • Promote early engagement and risk-informed decision-making by educating business and technology teams on when an NBIA is required and how to prepare for an efficient assessment.
  • Monitor emerging threats, regulatory expectations, and business changes that could affect NBIA methodology, assessment criteria, or stakeholder participation.


Qualifications

  • Bachelor's or master's degree in Cybersecurity, Information Technology, Risk Management, Business, Engineering, Criminal Justice, Process Improvement, or a related field, or an equivalent combination of training, education, and experience.
  • Significant experience performing or leading risk assessments for new business initiatives, products, services, technologies, processes, or third-party relationships in a complex or regulated organization.
  • Demonstrated familiarity and hands-on experience working with the First, Second, and Third Lines of Defense (1LOD, 2LOD, and 3LOD), including business ownership, independent risk oversight and challenge, and audit or assurance activities.
  • Significant background or experience in Information Security, with working knowledge of cybersecurity risk, data protection, identity and access, resilience, vulnerability management, and security control concepts.
  • Experience evaluating fraud risks, fraud prevention considerations, or financial crime-related impacts associated with business and technology change.
  • Experience evaluating Physical Security risks or partnering with Physical Security stakeholders on facilities, people, assets, access, safety, or related operational considerations.
  • Proven ability to coordinate and influence a broad group of stakeholders across business, technology, risk, security, compliance, legal, privacy, procurement, vendor management, and audit functions.
  • Strong understanding of risk and control concepts, including inherent risk, residual risk, risk appetite, control design, evidence, issues, exceptions, remediation, and governance reporting.
  • Ability to analyze complex and incomplete information, identify the most important risks and dependencies, and form clear, well-supported conclusions and recommendations.
  • Experience applying Process Improvement, Lean, Lean Six Sigma, or comparable methods to streamline workflows, reduce defects and delays, improve quality, and establish measurable outcomes.
  • Ability to facilitate structured working sessions, resolve ambiguity, manage competing viewpoints, and drive decisions and actions to closure without losing necessary independence or challenge.
  • Excellent written and verbal communication skills, including the ability to convert technical and risk information into concise, plain-language materials for executives, governance bodies, and non-technical partners.
  • Strong documentation and organizational skills, with the ability to maintain complete, accurate, and audit-ready assessment records.
  • Significant experience in financial services or another highly regulated industry preferred.


Desired Qualifications
  • Desired certifications may include CISSP, CRISC, CISA, PMP, Certified Fraud Examiner (CFE), Physical Security Professional (PSP), Lean Six Sigma Green Belt or Black Belt, or comparable credentials.

Additional Information

Hours:
  • Monday - Friday, 8:00AM - 4:30PM


Location:
  • 820 Follin Lane, Vienna, VA 22180


About Navy Federal Credit Union

Navy Federal Credit Union is a credit union that serves members of the military and their families. The credit union offers a range of financial products and services, including checking and savings accounts, loans, and credit cards. Navy Federal Credit Union was founded in 1933 and is headquartered in Vienna, Virginia. The credit union has more than 9 million members and operates more than 300 branches across the United States and around the world.
Learn more about Navy Federal Credit Union
Size
18,000 employees
Industry
Founded
1933

Similar Jobs

More Jobs at Navy Federal Credit Union

More Finance & Insurance Jobs

Find similar Principal Technical Risk Analyst jobs: