Navy Federal Credit Union

Senior Technical Risk Analyst

Navy Federal Credit Union$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Experience with IT audit practices/frameworks
  • Solid understanding of business area/specialization
  • Background in technical risk management, cybersecurity, or IT governance
  • Hands-on experience with risk assessments and frameworks
  • Proven track record in managing cybersecurity risks
  • Thorough knowledge of risk management principles and regulatory compliance
  • Familiarity with IT systems and network architecture
  • Excellent analytical and problem-solving skills
  • Strong communication skills for conveying complex concepts
  • Experience in incident management and business continuity planning
  • Bachelor's degree in a related field or equivalent experience

Responsibilities

  • Facilitate and communicate requests for information from ETS Service Areas
  • Act as the primary contact for the audit process, overseeing management's responses
  • Attend various audit-related meetings including kick-offs and status updates
  • Lead reviews of audit findings ensuring responses are comprehensive
  • Maintain professional communication with business partners and internal customers
  • Identify and evaluate technical risks in IT infrastructure and applications
  • Conduct detailed risk assessments for IT projects and systems
  • Analyze new technologies for associated risks
  • Stay updated on emerging cybersecurity threats
  • Develop and implement risk management frameworks and policies
  • Prioritize technical risks based on business impact and collaborate on mitigation strategies
  • Integrate risk management into tech projects and operational processes
  • Manage remediation of vulnerabilities and track risk reductions
  • Ensure alignment of risk management processes with compliance and industry standards
  • Lead internal and external audits by providing risk assessments and documentation
  • Collaborate with compliance teams to monitor regulatory changes
  • Assist in investigating technical incidents, root causes, and corrective actions
  • Prepare regular management reports on risk status and trends
  • Maintain documentation of risk assessments and mitigation strategies
  • Facilitate risk awareness training sessions across the organization
  • Continuously enhance risk management frameworks and tools
  • Monitor the threat landscape to update risk strategies accordingly
  • Promote a culture of risk awareness within the organization

Benefits

  • Comprehensive health, dental, and vision insurance plans
  • Retirement savings plan with employer match
  • Generous paid time off and holidays
  • Opportunities for career advancement and professional development
  • Employee assistance programs and wellness initiatives
Full Job Description
Job Description

Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.

Responsible for assessing and managing technical risks across the organization's IT and operational environments. Works closely with cross-functional teams to identify and analyze emerging technology risks, implement risk management strategies, and maintain compliance with industry standards and regulations. Plays a key role in developing frameworks for risk identification, reporting, mitigation, and control. Responsible for understanding the technological landscape, implementing risk management frameworks, and ensuring that the organization adheres to industry standards and regulatory requirements. Work under minimal supervision and use complete understanding of business needs and objectives to support projects that have impact on the achievement of operational goals. Advanced skill set and proficiency with procedures and techniques.

Responsibilities

  • Facilitate and communicate requests for information and evidence from ETS Service Areas
  • Serve as a primary point of contact regarding the overall audit process including the drafting and routing of management's responses.
  • Attend audit related meetings including kick off meetings, process walk-throughs, status meetings, and end of fieldwork meetings.
  • Lead ETS management with the review of and response to audit findings and recommendations, ensuring that responses are accurate, comprehensive, and accurately reflect internal ETS processes and procedures.
  • Exemplify professional and tactful communication in all interactions, to include verbal and written communications with business partners, leadership, and internal customers.
  • Lead efforts to identify technical risks related to IT infrastructure, applications, systems, and data
  • Perform detailed risk assessments of IT projects, vendors, and systems to identify vulnerabilities and potential threats
  • Analyze new technologies and business processes to determine associated risks
  • Stay informed about emerging cybersecurity threats and vulnerabilities that could affect the organization
  • Develop and implement risk management frameworks, policies, and procedures
  • Prioritize risks based on business impact, and work with stakeholders to design and implement mitigation strategies
  • Work with IT and business teams to embed risk management into technology projects, operational processes, and product development
  • Manage the remediation of technical vulnerabilities and track risk reduction efforts
  • Ensure that risk management processes align with internal policies, regulatory requirements, and industry standards (e.g., ISO 27001, NIST, GDPR, SOX, etc.)
  • Lead internal and external audits by providing risk assessments, compliance reports, and documentation
  • Partner with compliance and legal teams to monitor adherence to regulatory changes impacting technology risks
  • Lead or assist in investigating technical incidents and breaches, conducting root cause analyses, and recommending corrective actions
  • Collaborate with security and IT teams to develop response strategies for cybersecurity incidents
  • Prepare and present post-incident reports and lessons learned to management
  • Prepare and present regular reports to senior management and stakeholders on the status of technical risks, trends, and mitigation efforts
  • Maintain accurate and comprehensive documentation of all risk assessments, controls, and mitigation strategies
  • Assist in the creation of technical risk dashboards for ongoing monitoring
  • Act as a subject matter expert on technical risk and provide guidance to other teams across the organization
  • Facilitate workshops and training sessions to enhance risk awareness and promote best practices
  • Collaborate with internal teams such as IT, cybersecurity, compliance, legal, and audit to ensure a cohesive approach to risk management
  • Continuously evaluate and enhance risk management frameworks and tools
  • Monitor the evolving threat landscape and emerging technologies to update risk strategies and frameworks accordingly
  • Promote a culture of risk awareness and proactive risk management throughout the organization


Qualifications

  • Experience with IT audit practices/framework
  • Complete knowledge and understanding of business area/specialization
  • Experience in technical risk management, cybersecurity, or IT governance
  • Hands-on experience with risk assessments, risk frameworks, and mitigation strategies
  • Proven experience in managing and mitigating cybersecurity risks
  • Advanced knowledge of risk management principles, frameworks (e.g., ISO, NIST, COSO), and regulatory compliance requirements
  • Advanced understanding of IT systems, network architecture, cloud technologies, and cybersecurity
  • Excellent analytical, problem-solving, and decision-making skills
  • Strong interpersonal and communication skills, with the ability to convey complex risk concepts to non-technical stakeholders
  • Experience in working with incident management, disaster recovery, and business continuity planning
  • Ability to work in a fast-paced environment with tight deadlines
  • Bachelor's degree in Information Technology, Computer Science, Risk Management, or a related field or equivalent combination of training, education and experience

Desired Qualifications
  • Master's Degree in related field or equivalent combination of training, education and experience
  • Relevant certifications (e.g., CISSP, CISM, CRISC, CISA) preferred


Additional Information

Hours:
  • Monday - Friday, 8:00AM - 4:30 PM


Locations:
  • 820 Follin Lane, Vienna, VA 22180
  • 5550 Heritage Oaks Dr Pensacola, FL 32526

About Navy Federal Credit Union

Navy Federal Credit Union is a credit union that serves members of the military and their families. The credit union offers a range of financial products and services, including checking and savings accounts, loans, and credit cards. Navy Federal Credit Union was founded in 1933 and is headquartered in Vienna, Virginia. The credit union has more than 9 million members and operates more than 300 branches across the United States and around the world.
Learn more about Navy Federal Credit Union
Size
18,000 employees
Industry
Founded
1933

Similar Jobs

More Jobs at Navy Federal Credit Union

More Information Technology Jobs

Find similar Senior Technical Risk Analyst jobs: