Job DescriptionWho are we looking for? Are you a second-line technology risk and control assurance specialist who provides independent oversight of controls, rather than building or operating them and can challenge, test and mature a control environment? We're seeking an experienced
Senior Technology Risk Advisor (Applications, Platforms & Data) to provide independent, second-line (2LoD) assurance across application platforms, data and AI services, software development, domain and DNS management, and the online and web ecosystem, strengthening the control environment that protects GHD and its clients.
In this senior, independent advisory role, you'll partner with and constructively challenge technology leaders, platform owners and governance stakeholders to assess control design and operating effectiveness, govern remediation to closure, and deliver insights that support informed, risk-based decisions across the business.
As a senior technology risk professional, you will:- Lead risk-based assurance reviews across application platforms, data, AI services, web technologies, and software development environments
- Assess the design and effectiveness of technology controls and identify opportunities to strengthen risk management practices
- Develop and maintain technology control frameworks aligned with industry standards and regulatory requirements
- Conduct thematic reviews on topics such as AI governance, data access controls, software development practices, web application security, and DNS/domain management
- Partner with technology teams to embed controls by design and improve operational resilience
- Validate evidence, manage findings, track remediation activities, and escalate material risks when required
- Deliver executive-level reporting, including control effectiveness ratings, risk heat maps, key risk indicators, trend analysis and material issues for senior leadership and governance committees
- Support client assessments, audits, and compliance activities with defensible evidence and subject matter expertise
- Provide second-line oversight of AI risk management, data protection controls, and technology governance initiatives
- Monitor emerging regulatory requirements and industry trends, ensuring the control environment evolves appropriately
What You'll BringWe're looking for an independent, second-line mindset, someone who pairs control assurance rigour with enough technical understanding of application, data, AI, web and platform environments to challenge first-line teams credibly, communicate clearly with executives, and drive remediation.
You'll be a strong fit if you've owned or independently assured a gated secure development lifecycle (SDLC) control framework, including threat modelling, secure pipelines, software bill of materials (SBOM), static testing and dynamic testing, and can challenge delivery teams on control evidence across cloud, container and SaaS platforms.
It's likely not a fit if your background is primarily hands-on security engineering, software development, or one-off internal audit.
Required Experience- 5 to 10 years in technology or IS risk and control assurance, including demonstrable second-line independent assurance over technology control environments, as distinct from first-line security operations or one-off internal audit
- Experience designing, testing, or assessing technology controls and risk management frameworks
- Strong knowledge across application, platform, data, cloud, and web and DNS environments, with the ability to assess and challenge controls without needing to operate them
- Experience working with executive stakeholders and presenting complex information in a clear, actionable way
- Demonstrated ability to manage multiple assurance activities and drive remediation outcomes
Technical KnowledgeExperience with some or all of the following is highly desirable:
- ISO/IEC 27001 and 27002
- NIST frameworks and security controls
- CMMC and client security requirements
- Risk and control assurance methodologies
- Data governance and protection controls
- AI governance and model risk management
- Software development lifecycle (SDLC) controls
- Web application and digital platform security
- Domain, DNS, and online ecosystem governance
Qualifications- Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related field
- Relevant certifications such as CRISC, CISA, CGRC, CISSP, or similar are advantageous
Benefits: - 401K - Employees are eligible to participate on the first day of the month following 3 months of service
- Paid time off - Our PTO benefit is designed to provide eligible employees with a period of rest and relaxation, sick, and personal time throughout the year. PTO starts at 16 days per year and increases with years of service
- Holiday Pay - Holiday pay is provided for eligible employees. GHD observes 9 holidays per year. Holiday pay will be based on the regular set schedule for the employee
- Wellness Benefit- Regular full-term employees are eligible to participate in the wellness reimbursement program. GHD will reimburse 50% of the cost of the following to maximum of $250.00 reimbursement annually for such items as: Health club membership fees, Home exercise equipment purchases, Bicycles, Race, run & marathon entrance fees, Smoking cessation programs, Weight loss programs (i.e.-Weight Watchers, Jenny Craig), Fitbits and Fitness Tracking devices
Salary range: $87,97500 - $146,625.00 based on experience and location
Interested? Apply Now.#LI-JW1