Bbh

Sr. Risk Manager, Cyber & Technology Risk Management

Boston, United StatesFull timeManager$140,000 - $190,000 / yearPosted 1 day ago
Apply on Bbh →

Sign in to see who you know at Bbh.

At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships.  We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.Cyber & Technology Risk Management is an independent second-line risk function within Enterprise Risk Management (ERM). The group is aligned to the Firm’s global Systems/Technology organization and provides risk oversight across a complex financial services environment. The Senior Risk Manager will serve as a trusted second-line advisor, leading a team of cyber and technology risk professionals responsible for identifying, assessing, and helping manage cyber and technology risks that impact the Firm. The Senior Risk Manager is expected to bring broad technical knowledge with expertise in cyber risk management and related regulatory frameworks including information security, cyber resilience, data protection, and regulatory compliance across the Firm's technology environment.This is a senior, highly visible role that partners closely with Systems/Technology management, Application and Data Owners, control owners, Compliance, Internal Audit, Line of Business leadership, and peer leaders across Cyber & Technology Risk Management and ERM to promote sound risk decisions, strong governance, and practical outcomes.RESPONSIBILITIESWhat You’ll DoPartner with technology, security, and operations teams to identify, assess, and manage cyber and technology risks. Provide independent second-line advisory and effective challenge, translating risk considerations into clear, practical guidance.Lead and/or support risk and control assessments, including cyber risk reviews, RCSAs, application risk assessments, external assurance reviews, and related governance activities.Evaluate control gaps, risk acceptances, exceptions, and remediation plans; assist stakeholders prioritize actions based on business impact, risk appetite, and regulatory expectations.Analyze new and emerging risks, including related regulatory requirements and supervisory guidance to identify risk implications and potential gaps; collaborate with control owners on control design, implementation, and measurement.Support the continued build-out of a new IT governance platform to improve integration, transparency, and execution across Cyber & Technology Risk Management programs.QUALIFICATIONSWhat You’ll BringBachelor’s degree, equivalent work experience, specialized training in information technology, cybersecurity, risk management, audit, or related discipline.10+ years of experience in cyber risk, technology risk, information security, IT audit, operational risk, third-party risk, or a related control function.Demonstrated experience assessing cyber risk programs, cybersecurity controls, and informatio...