Senior Manager Technology Risk and Governance

TruStage
$135,500 - $203,300Hybrid

About The Position

At TruStage, we’re on a mission to make a brighter financial future accessible to everyone. We put people first, and work hand in hand with employees and customers to create a diverse and inclusive environment. Passionate about building insurance and financial services solutions, we push the boundaries of what’s possible. We need you to help us shape what’s next. You’ll be encouraged to share your experiences, ideas and skills to help others take control of their financial future. Join a team that has received numerous awards for being a top place to work: TruStage awards and recognition Job Summary The Senior Manager, Technology Compliance is responsible for coordinating technology-related compliance and assurance activities and customer due diligence requests across the Enterprise Information and Technology organization. This role acts as the primary conduit between internal and external assurance stakeholders (e.g., Internal Audit, regulators, external auditors, customer due diligence teams) and the technology teams accountable for providing evidence, operating controls, and remediating identified gaps. This role establishes and manages a structured operating model for: • Coordination of technology audits and examinations; • Responses to customer and third-party due diligence inquiries; • Governance and reporting for accepted technology risks; • Monitoring and escalation of remediation activities tied to assurance findings; • Support for ongoing technology compliance transparency. The role provides centralized coordination, oversight, reporting, and process discipline to improve consistency, timeliness, and accountability across technology compliance obligations. It is responsible for coordination, governance, tracking, and reporting of technology compliance and assurance activities.

Requirements

  • Bachelor’s degree in information technology, cybersecurity, risk management, accounting, business, or related field, or equivalent combination of education and/or related professional work experience.
  • 7+ years of experience in one or more of the following areas: Technology risk management; IT compliance or IT audit; Information Security governance; Operational risk; Issue management or compliance coordination; Technology control functions.
  • Demonstrated experience coordinating internal/external audits, regulatory exams, or customer due diligence requests.
  • Strong understanding of technology control environments, including areas such as identity and access management, vulnerability management, change management, infrastructure operations, third-party technology services, backup/recovery, and incident response.
  • Experience in a regulated industry such as financial services, insurance, healthcare, or utilities.
  • Familiarity with common control and regulatory frameworks such as: NIST Cybersecurity Framework, COBIT, ISO 27001, SOC 1 / SOC 2, FFIEC, NYDFS, PCI DSS, OSFI B-13, COSO or other relevant technology risk/compliance standards.
  • Experience developing metrics, dashboards, managing issue portfolios and governance reporting for technology risk and compliance activities.
  • Strong organizational and program management skills with the ability to manage multiple concurrent requests and deadlines.
  • Excellent written and verbal communication skills, including the ability to synthesize technical input into executive-ready reporting.
  • Proven ability to work cross-functionally through indirect influence of contributing teams.

Nice To Haves

  • Professional certifications such as CGRC, CRISC, CISM, CISSP or CIA are a plus.
  • Experience with Governance, Risk, and Compliance (GRC) platforms or audit management tools.

Responsibilities

  • Serve as the central coordination point for internal audit, external audit, regulatory review, and other assurance activities impacting technology.
  • Manage intake, prioritization, and organization of Technology related audit/examination requests and route them to the appropriate accountable technology teams.
  • Establish and enforce clear timelines, deliverables, and governance mechanisms for evidence collection and response protocols for audit engagements.
  • Review evidence submitted by accountable technology teams for completeness, consistency, and quality before final delivery to auditors or examiners.
  • Maintain a centralized repository of audit documentation, evidence, responses, findings, and remediation commitments.
  • Track open issues and remediation actions resulting from audits or exams and provide status reporting to technology leadership.
  • Drive consistency in how technology responds to assurance requests across infrastructure & operations, engineering & application support, operations, information security, architecture, Automation/AI and data teams.
  • Coordinate responses to customer data, security, and technology due diligence requests, including questionnaires, supporting documentation, and follow-up clarifications.
  • Partner with Information Security, Privacy, Legal, Risk, Procurement, and Technology teams to gather and validate required responses as appropriate.
  • Maintain a library of standard responses, reusable evidence artifacts, and approved language to improve response efficiency and consistency.
  • Identify recurring themes or gaps from customer due diligence requests or evidence gaps and recommend process, control, or documentation improvements.
  • Support sales, account management, procurement, and functions with timely and accurate technology assurance information.
  • Administer and maintain a centralized inventory and dashboard of accepted technology risks, including key attributes such as risk articulation, technology approver, business approver, risk owner, business justification, compensating controls, duration, expiration dates and review cycle.
  • Ensure accepted risks are documented consistently and reviewed in accordance with policy and governance requirements.
  • Monitor risk acceptance reviews, acceptance durations, expirations and revalidation requirements.
  • Track upcoming expirations, re-approvals, and overdue reviews, and escalate as needed.
  • Provide reporting and insights on risk acceptance trends, concentration and exposures.
  • Facilitate governance routines for risk acceptance review and escalation.
  • Provide transparency into risk acceptance decisions without assuming ownership of the underlying risks.
  • Track remediation commitments associated with audit findings, assessments, customer issues, and compliance reviews.
  • Monitor progress against action plans and escalate delays, unclear ownership, or inadequate closure evidence.
  • Facilitate issue governance routines, including status reviews, risk escalation.
  • Help ensure findings and remediation actions are traceable, auditable, and aligned to enterprise issue-management standards.
  • Ensure appropriate documentation and evidence support for issue closure.
  • Design and maintain repeatable processes, procedures, templates, and playbooks for audit coordination, due diligence response management, and risk acceptance reporting.
  • Define metrics and dashboards related to cycle time, issue aging, evidence quality, response timeliness, and remediation performance.
  • Identify opportunities to streamline assurance interactions, reduce redundancy, and improve stakeholder experience.
  • Support the maturity of technology compliance practices by strengthening documentation discipline, intake workflows, and executive reporting.
  • Build and maintain strong relationships across Technology, Information Security, Enterprise Risk, Legal, Privacy, Internal Audit, Finance and business stakeholders.
  • Communicate complex technical control and compliance information into clear and concise status updates and actionable insights for leadership.
  • Prepare executive summaries, dashboards, and briefing materials.
  • Escalate material risks, delays, or recurring control concerns in a timely and objective manner.

Benefits

  • medical
  • dental
  • vision
  • employee assistance program
  • life insurance
  • disability plans
  • parental leave
  • paid time off
  • 401k
  • tuition reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service