Brown Brothers Harriman

Sr. Risk Manager, Cyber & Technology Risk Management

Brown Brothers Harriman$140K — $190K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent in IT, cybersecurity, risk management, audit, or related fields.
  • 10+ years of experience in cyber risk, technology risk, or related control functions.
  • Experience assessing cyber risk programs and information security governance frameworks within regulated environments.
  • Ability to analyze complex risk issues and communicate effectively to both technical and non-technical audiences.
  • Strong understanding of cybersecurity regulatory requirements and industry frameworks, including NIST and ISO standards.
  • Familiarity with emerging cyber regulatory frameworks like DORA.
  • Certifications such as CISSP, CISM, or CRISC are a plus.

Responsibilities

  • Partner with technology and operations teams to manage cyber and technology risks.
  • Provide independent, practical guidance on risk considerations.
  • Lead risk assessments, including cyber risk reviews and application risk assessments.
  • Evaluate control gaps and assist stakeholders in prioritizing actions based on risk appetite.
  • Analyze new and emerging risks and collaborate on control design and implementation.
  • Support the development of an IT governance platform to enhance transparency and execution of risk programs.

Benefits

  • Comprehensive health benefits including medical and dental care.
  • Professional development opportunities for ongoing growth.
  • Flexible work environment with hybrid remote options.
  • Long-term savings and income protection plans.
Full Job Description
Cyber & Technology Risk Management is an independent second-line risk function within Enterprise Risk Management (ERM). The group is aligned to the Firm's global Systems/Technology organization and provides risk oversight across a complex financial services environment. The Senior Risk Manager will serve as a trusted second-line advisor, leading a team of cyber and technology risk professionals responsible for identifying, assessing, and helping manage cyber and technology risks that impact the Firm. The Senior Risk Manager is expected to bring broad technical knowledge with expertise in cyber risk management and related regulatory frameworks including information security, cyber resilience, data protection, and regulatory compliance across the Firm's technology environment.

This is a senior, highly visible role that partners closely with Systems/Technology management, Application and Data Owners, control owners, Compliance, Internal Audit, Line of Business leadership, and peer leaders across Cyber & Technology Risk Management and ERM to promote sound risk decisions, strong governance, and practical outcomes.

RESPONSIBILITIES

What You'll Do
  • Partner with technology, security, and operations teams to identify, assess, and manage cyber and technology risks.
  • Provide independent second-line advisory and effective challenge, translating risk considerations into clear, practical guidance.
  • Lead and/or support risk and control assessments, including cyber risk reviews, RCSAs, application risk assessments, external assurance reviews, and related governance activities.
  • Evaluate control gaps, risk acceptances, exceptions, and remediation plans; assist stakeholders prioritize actions based on business impact, risk appetite, and regulatory expectations.
  • Analyze new and emerging risks, including related regulatory requirements and supervisory guidance to identify risk implications and potential gaps; collaborate with control owners on control design, implementation, and measurement.
  • Support the continued build-out of a new IT governance platform to improve integration, transparency, and execution across Cyber & Technology Risk Management programs.


QUALIFICATIONS

What You'll Bring
  • Bachelor's degree, equivalent work experience, specialized training in information technology, cybersecurity, risk management, audit, or related discipline.
  • 10+ years of experience in cyber risk, technology risk, information security, IT audit, operational risk, third-party risk, or a related control function.
  • Demonstrated experience assessing cyber risk programs, cybersecurity controls, and information security governance frameworks within a regulated financial institution or similarly regulated environment.
  • Ability to analyze complex risk issues, balance business objectives with control expectations, and communicate practical recommendations to both technical and non-technical audiences.
  • Strong understanding of cyber and technology risk concepts, control assessment, issue management, remediation tracking, risk acceptance, and risk reporting practices.
  • Strong knowledge of cybersecurity regulatory requirements and industry frameworks, including NYDFS Part 500, NIST Cybersecurity Framework, ISO 27001, and other applicable cybersecurity or operational resilience standards.
  • Familiarity with DORA, global operational resilience requirements, and other emerging cyber regulatory frameworks.
  • Working knowledge of technology environments, including networks, operating platforms, cloud services, application security, and third-party hosted solutions.
  • Certifications such as CISSP, CISM, and/or CRISC are a plus.


This role can be based in either our Boston or Jersey City locations and will be a hybrid role, with a minimum of three (3) days in office.

Salary Range

NJ / MA: $140,000 - $190,000 base salary + annual target bonus

BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.

We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply.

About Brown Brothers Harriman

Brown Brothers Harriman & Co. (BBH) is the oldest and largest private bank in the United States. Founded in 1818, BBH has been a leader in the financial industry for over 200 years. The company provides a wide range of financial services to individuals, families, and institutions, including wealth management, investment management, and private banking. BBH has offices in the United States, Europe, and Asia, and manages over $1.6 trillion in assets.
Learn more about Brown Brothers Harriman
Size
7,000 employees
Industry

Similar Jobs

More Jobs at Brown Brothers Harriman

More Finance & Insurance Jobs

Find similar Sr. Risk Manager, Cyber & Technology Risk Management jobs: