Senior Engineer– Digital Risk Management
Quick Summary
1. IT Risk Governance & Framework Management Design, implement,
Bachelor's Degree in Computer Science, or related field. Minimum 8-10 years in IT risk management, audit, or cyber governance. Strong knowledge of risk frameworks (NIST, ISO 27001, COBIT),
Responsibilities
~2 min read1. IT Risk Governance & Framework Management
- →Design, implement, and maintain the IT Risk Management Framework aligned with Carrier based Digital Risk Framework which is derived from NIST CSF and ISO 27001.
- →Define IT risk taxonomy, thresholds, and escalation protocols for consistent enterprise-wide adoption.
- →Serve as the primary liaison for IT risk matters across Carrier's global business units, infrastructure, and application teams.
- →Serve as the primary record creator for risks in ServiceNow GRC application.
Key person contributing to the design, configuration, and rollout of the ServiceNow GRC framework, covering the Policy, Risk, Issue, Compliance and Exception Management modules end-to-end.2. Risk Identification, Assessment & Prioritization
- →Conduct and oversee IT risk assessments (inherent and residual) across critical applications, infrastructure, and projects.
- →Guide IT Risk Analysts in executing risk analysis, evidence collection, and scoring processes.
- →Facilitate scenario-based and targeted risk assessments for high-impact areas including cloud migrations, system upgrades, and M&A.
- →Maintain and update risk registers, scoring models, and risk heatmaps using GRC tools - ServiceNow IRM
3. Control Management & Monitoring
- →Define and implement key risk indicators (KRIs) and key control indicators (KCIs) for ongoing risk monitoring.
- →Supervise IT Risk Analysts in evaluating control effectiveness and documenting evidence.
- →Develop action plans for control deficiencies, monitor remediation, and report control maturity metrics.
4. Exception & Deviation Handling
- →Lead the end-to-end management of risk exceptions, waivers, and deviations from IT policy.
- →Oversee the workflows managed by analysts and ensure that exceptions are timely reviewed and approved by appropriate stakeholders.
- →Automate exception workflows and integrate them with CMDB and audit logs for traceability.
5. Stakeholder Engagement & Risk Reporting
- →Prepare and present monthly/quarterly risk dashboards to senior leadership, Risk Council, and DCC.
- →Conduct regular stakeholder sessions to capture risk concerns, share insights, and promote risk ownership.
- →Provide risk insights to inform IT strategic decisions, budget allocations, and project prioritization.
6. Awareness, Training & Culture Building
- →Develop and deliver IT risk training modules to application owners, support teams, and project managers.
- →Promote a risk-aware culture through playbooks, campaigns, and collaborative learning sessions.
- →Partner with HR and L&D to integrate IT risk content into employee training journeys.
- →Mentor and coach IT Risk Analysts to build operational maturity and grow internal expertise.
Requirements
~1 min read- Bachelor's Degree in Computer Science, or related field.
- Minimum 8-10 years in IT risk management, audit, or cyber governance.
- Strong knowledge of risk frameworks (NIST, ISO 27001, COBIT), internal controls, and security policies.
- Hands-on experience with GRC platforms, specifically ServiceNow IRM / GRC (Risk, Issue, and Exception Management modules), RSA Archer or any other platforms.
- Demonstrated ability to coordinate and interact frequently with internal SME teams and external stakeholders to drive risk topics and strengthen the risk management portfolio.
- Working knowledge of AI risk frameworks (NIST AI RMF, ISO/IEC 42001) and hands-on ability to leverage AI tools — including building lightweight risk-reporting apps, dashboards, or chatbots — to automate risk triage, scoring, monitoring and stakeholder queries.
Nice to Have
~1 min read- CRISC.
- Strategic thinking with tactical execution.
- Strong interpersonal, influencing, and negotiation skills.
- Analytical mindset with the ability to simplify complex risk narratives for business audiences.
- Proven ability to lead cross-functional teams and manage multi-country risk engagements.
- Strong coordination skills, with the ability to build and maintain effective working relationships across internal SME teams and external stakeholders for effective risk management outcomes.
What We Offer
~1 min readClick on this link to read the Job Applicant's Privacy Notice
Location & Eligibility
Listing Details
- Posted
- September 24, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 64%
- Scored at
- September 28, 2026
Signal breakdown
Similar Risk Management jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.