Jobs and Careers
NA

Senior Technical Risk Analyst (Asset Risk Assessment)

Navy Federal Credit Union
United Statesfull_timeVerifiedPosted 31 Mar 2025

About the role

Support Security Governance & Risk (SG&R) in a lead role with high multi-facet Business and IT insight to ensure Navy Federal Credit Union’s (NFCU) Security Division in effectively managing the enterprise’s Security risks and overall program through technical implementation. 

This position will be responsible for implementing focused risk management strategy and methodology within NFCU enterprise anchor platform. Iterative annual enhancements and modernizations as well as overall maintenance and ad hoc adjustments corresponding to the IT technical needs of the program. This role straddles both functionalities pertaining to first and second lines of defense functionality for security risk management and governance of the Asset Risk Assessment (ARA) Program

This role will collaborate heavily with Enterprise Risk Management (ERM) and Enterprise Technology Services (ETS) partners, NFCU asset Business and IT owners, and Business Unit risk management delegates across the enterprise to identify and assess Inherent Risk, Control Effectiveness, and Residual Risk compiling the generation of not only risk prioritization, reporting and dashboards, but also high value attribute data population serving to facilitate data integrity and credibility to the enterprise asset inventory/repository.

Individual will use extensive IT, risk management, and cyber security industry best practices and applied real-world experience to lead the Program iteratively through greater security governance and risk identification, developing pragmatic solutions to address NFCU established risk appetites. Ensure security governance and risk management activities align with strategic business/project initiatives from NFCU Senior Leadership Team, achieve business and quality objectives, streamline, and automate where possible to enhance operating procedures. Promote operational efficiency and service excellence through appropriate risk controls, process improvements and training. 

This position is eligible for the TalentQuest employee referral program. If an employee referred you for this job, please apply using the system-generated link that was sent to you.

  • Scale vertically and horizontally across the enterprise driving asset Inherent and Residual Risk for Security within an enterprise gateway assessment.
  • Ensure the effective identification of best practice resource tools which supports NFCU Standards and Control Procedure mapping to mitigate risk for asset owner population within the Enterprise Source of Record/Inventory Repository.  Provide experienced guidance and advice to partner ETS organization on updates to the enterprise GRC platform related to compliance. Work closely with ETS governance committees for data integrity.
  • Identify iterative areas to monitor due to annual regulation changes and examination feedback. 
  • As applicable, articulate data context definitions of Inherent, Control Effectiveness and Residual Risk attributes related to reporting and dashboard metrics.
  • Inform the Business and IT in a federated accountability fashion of asset ARA output.
  • Inform the Control Assurance Team(s) and other downstream impacted programs for testing frequency of assets. Maintain working relationship within end-to-end workflow to obtain an overall calculated, validated and evidenced residual risk per asset.
  • Team player with participation in Security-related special projects, councils, committees, working groups, etc. as a Risk SME
  • Bachelor’s degree in information technology, Computer Science, Risk Management, or a related field or equivalent combination of training, education and experience
  • A minimum of 10 years of experience leading technical programming initiatives and/or operational risk/compliance related activities in regional, national or global financial services or other relevant industry
  • Extensive knowledge as a Security technical system administrator configuring core processes such as ITAM, ITSM, ITBM, CMDB, PPM, IAM, Cyber Security best practices for control mitigation, Vulnerability Management, Business Continuity, Third Party Risk Management, Data Loss Prevention, Network and Cloud Security, etc.
  • Extensive technical knowledge of risk GRC platform such as ServiceNow, OpenPages, Archer
  • Extensive technical experience in large scale strategic project SDLC development and implementation of risk management frameworks within enterprise eGRC Tool 
  • Advanced verbal, written, interpersonal skills to communicate clearly and concisely technical and non-technical information to all levels of management and a strong EQ
  • Advanced knowledge of information technology systems, project processes, and application development with the ability to directly work with clients through workshops, development, UAT improvements, and production deployment.
  • Adva

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Navy Federal Credit Union

View company profile →