Posted on: 24/09/2026
JD for Ameriprise Financial - Technical Lead IT Risk - GRC
Key Responsibilities :
- Apply the Technology Control Framework to establish and maintain effective governance, risk, and compliance practices across Technology Infrastructure.
- Drive implementation and monitoring of technology controls, risk assessments, and compliance activities aligned with organizational policies, regulatory obligations, and industry standards.
- Lead governance and oversight activities supporting technology risk management, control testing, issue management, audit readiness, and regulatory compliance.
- Partner with infrastructure teams, control owners, auditors, and business stakeholders to ensure consistent execution of controls and compliance requirements.
- Evaluate the effectiveness of technology controls and identify opportunities to improve operational resilience, risk management, and compliance maturity.
- Coordinate and support internal and external audits, including evidence validation, issue tracking, remediation planning, and management reporting.
- Assess audit observations, control deficiencies, compliance gaps, and risk exposures while ensuring corrective actions are implemented and sustained.
- Develop and maintain governance artifacts including control documentation, testing procedures, process flows, operational standards, and remediation records.
- Translate business, audit, and regulatory requirements into practical governance solutions, process improvements, and technology-enabled workflows.
- Monitor key risk indicators, compliance metrics, control performance measures, and remediation activities to provide actionable insights to leadership.
Required Key Skills :
- Strong understanding of Technology Governance, Risk & Compliance (GRC) principles and control frameworks.
- Experience managing technology audits, control testing, compliance assessments, and remediation activities.
- Working knowledge of Technology Infrastructure domains including Cloud, IAM, Networking, Servers, Databases, and Vulnerability Management.
- Experience with ServiceNow GRC/IRM or similar risk and compliance platforms.
- Strong stakeholder management, communication, and leadership skills.
- Ability to analyze risks, assess control effectiveness, and drive remediation actions.
- Experience developing governance metrics, dashboards, and management reporting.
- Good understanding of industry standards and frameworks such as ISO 27001, NIST, COBIT, PCI DSS, and SOC 1/SOC 2.
- Strong analytical, problem-solving, and decision-making capabilities.
Preferred Skills :
- Experience working with ServiceNow GRC/IRM, including Risk Management, Policy & Compliance, Audit Management, or Issue Management modules.
- Exposure to control automation, workflow design, reporting dashboards, or governance analytics to improve operational efficiency and transparency.
- Experience supporting technology transformation, process improvement, or GRC platform enhancement initiatives within a complex enterprise environment.
In-Office Collaboration :
- We are a client-centric, relationship-based business. Working together, in-person, is foundational to how we achieve results.
- By fostering a culture of face-to-face collaboration, idea sharing, productivity and personal connection, we deliver for our stakeholders - clients, advisors, employees and shareholders.
- Our employees work in the office at least three (3) days per week, with flexibility to work from home two (2) days per week.
- Some roles may require additional in-office time or different in-office expectations, and specific requirements will be discussed during the hiring process.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1674480