Principal Technology Risk Analyst - Controls Testing

Fidelity InvestmentsDurham, NC
Onsite

About The Position

Are you passionate about strengthening technology controls and influencing risk outcomes at enterprise scale? Do you thrive in complex environments where your judgment, expertise, and leadership help shape enterprise risk decisions? As a Principal Technology Risk Analyst, you will play a critical role in advancing Fidelity's technology risk management capabilities. This role offers the opportunity to lead highly complex initiatives, provide strategic risk guidance to senior stakeholders, and drive continuous improvement across the technology risk landscape.

Requirements

  • Extensive experience in technology risk, controls, cybersecurity, or audit functions within complex organizations
  • Ability to lead large-scale assessments and influence outcomes across diverse stakeholder groups
  • Deep knowledge of technology risk frameworks and control evaluation methodologies
  • Comfort advising senior leaders on complex risk matters
  • Effective communication skills
  • Ability to navigate ambiguity
  • Leverage data-driven insights to support sound risk decisions
  • Bachelor's degree in computer science, technology, or a related field
  • 8 or more years of experience in technology risk, IT, cybersecurity, cloud, analytics, audit, or related risk management roles
  • Experience leading complex control assessments and evaluating control maturity across diverse technology environments
  • Advanced knowledge of industry frameworks such as NIST, COBIT, AICPA Trust Services Criteria, ISO 27001, HITRUST, or similar
  • Familiarity with cloud security models (AWS, Azure, SaaS, PaaS) and GRC platforms such as Archer

Nice To Haves

  • Master's degree
  • Professional certifications such as CISA, CISSP, CRISC, CISM, or similar certifications

Responsibilities

  • Leading highly complex technology risk and controls assessments supporting audit, regulatory, certification, and enterprise risk management objectives
  • Evaluating control design and operating effectiveness across complex, distributed, cloud, and vendor-hosted environments while identifying emerging risks and systemic control concerns
  • Partnering with senior leaders across technology, risk, compliance, and audit organizations to influence risk decisions and drive remediation of significant control gaps
  • Applying advanced risk expertise, analytical thinking, and professional judgment to resolve complex technology risk and control challenges
  • Driving enhancements to testing methodologies, risk assessment practices, automation capabilities, and reporting processes
  • Providing leadership, coaching, and strategic direction across workstreams while contributing to the development of team capabilities and risk management practices
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service