Senior Technology Governance Analyst

Geode CapitalBoston, MA
Hybrid

About The Position

Geode Capital Management, LLC is seeking a highly skilled Senior Technology Governance Analyst to oversee our technology governance framework and lifecycle management processes. In this role, you will design, implement, and maintain IT standards, policies, and procedures while ensuring all technology assets are tracked from procurement to retirement. Utilizing your background in technology audit, risk management, and information security, you will bridge the gap between technical operations and compliance, ensuring our infrastructure remains secure, resilient, and fully aligned with regulatory requirements. This role is based in our office in Boston, Massachusetts. You are required to follow the firm’s policy on in-office attendance. Our current policy requires in-office attendance on Tuesday, Wednesday, and Thursday, and then provides an option to work remotely on Monday and Friday. Please note that Geode may alter this policy at any time.

Requirements

  • 5-8 years of experience in IT governance, technology audit, information security, or IT risk management
  • Bachelor’s or Master’s degree in Computer Science, Information Systems, Cyber Security, or a related field
  • Deep knowledge of NIST, ISO/IEC 27001, COBIT, and ITIL frameworks
  • Hands-on experience with ITAM/ITSM tools (e.g., ServiceNow, Jira, Flexera)
  • Solid understanding of internal audit standards, risk testing, and control validation
  • Exceptional ability to translate complex technical concepts into clear, written policy language
  • Strong problem-solving skills with high attention to regulatory and procedural details
  • Experience implementing review and approval processes within a Secure Software Development Lifecycle (SSDLC), including use of modern fully integrated and automated processes within the CI/CD pipeline
  • Excellent verbal and written communication skills
  • Strong relationship building, organization, and critical thinking skills

Nice To Haves

  • Certified Information Systems Auditor (CISA) or Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Security Professional (CISSP)

Responsibilities

  • Draft, review, and update comprehensive IT policies, procedures, and technical standards
  • Align IT frameworks with industry best practices and standards such as ISO, COBIT, NIST, and ITIL
  • Drive organization-wide adoption of technology standards through training and documentation
  • Evaluate existing technology governance, compliance and risk processes regularly to identify gaps, inefficiencies, and areas for governance improvement
  • Manage the end-to-end lifecycle of hardware, software, and enterprise applications
  • Track asset health, support status, and obsolescence risks to prevent operational disruptions
  • Collaborate with Engineering, Finance, Vendor Risk management groups to identify, track and plan upgrades, migrations, and decommissioning of legacy systems, and act as vendor relationship manager for selected vendor partners.
  • Maintain the definitive software asset management (SAM) and hardware configuration management database (CMDB)
  • Conduct technical risk assessments on existing infrastructure and newly proposed technologies
  • Identify vulnerability patterns and ensure security baselines are integrated into the deployment lifecycle
  • Partner with Information Security team to validate that policies meet strict data protection regulations
  • Develop risk mitigation strategies and maintain the details of known risks, mitigation plans, risk acceptance criteria, periodic renewal & closure of risks, in partnership with Enterprise Risk Technology & Internal Audit
  • Act as a liaison for internal and external technology audit teams during reviews
  • Gather, validate, and organize audit evidence to demonstrate continuous compliance
  • Track audit findings and remediation plans, ensuring technical teams resolve deficiencies on schedule
  • Perform pre-audit readiness assessments to proactively identify and fix compliance gaps
  • Assist in the ongoing execution and enhancement of Access Management processes, including maintaining and updating job profiles and supporting the user community with access-related requests
  • Provide support for periodic access reviews for both user and service/operational accounts, ensuring completeness and accuracy

Benefits

  • comprehensive health coverage
  • 401(k) matching
  • annual profit sharing
  • paid parental leave
  • generous time off
  • tuition and certification reimbursement
  • student loan support
  • fitness reimbursement
  • commuter subsidy
  • charitable donation matching
  • family care assistance including a backup care benefit
  • adoption and surrogacy support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service