Experience Level : 6-9 Years
Position Overview
We are seeking a skilled and motivated Application Risk Manager, responsible for leading the strategy, oversight, and execution of risk management practices related to enterprise applications. This role ensures that application development, deployment, and operations align with the organization’s risk appetite, regulatory requirements, and resilience objectives. The leader will partner with engineering, architecture, cybersecurity, and compliance teams to proactively identify, assess, and mitigate technology risks across the application lifecycle.
Key Responsibilities
- Develop and maintain a comprehensive application risk framework aligned with enterprise risk management standards.
- Lead risk assessments for new and existing applications, including cloud-native, legacy, and third-party platforms.
- Oversee control design and effectiveness reviews for application development, testing, deployment, and change management.
- Collaborate with DevOps and engineering teams to embed risk controls into CI / CD pipelines and agile workflows.
- Monitor and report on key risk indicators (KRIs) and risk OKRs related to application performance, reliability, and compliance.
- Partner with cybersecurity to address application-level vulnerabilities, secure coding practices, and threat modeling.
- Drive incident response readiness for application-related outages, data integrity issues, and third-party failures.
- Support internal and external audit activities, ensuring timely remediation of findings.
- Lead risk governance forums and present risk posture updates to senior leadership and board committees.
Required Skills & Experience
8+ years of experience in technology risk, application security, or IT governance.Deep understanding of application architecture, SDLC, DevOps, and cloud platforms (e.G., AWS, Azure, GCP).Familiarity with regulatory frameworks (e.G., SOX, GDPR, HIPAA) and industry standards (e.G., NIST, ISO 27001).Strong leadership, communication, and stakeholder management skills.Experience with risk tools (e.G., Archer, ServiceNow GRC) and monitoring platforms (e.G., Splunk, AppDynamics).Degree in Computer Science, Information Systems, Risk Management, or related field.Nice to Have Skills
Certifications such as CRISC, CISM, CISSP, or PMP.Experience in financial services, insurance, or other regulated industries.Proven ability to influence cross-functional teams and drive risk-aware culture.What We Offer
Opportunity to work closely with teams of information security professionals, data engineers, and business leaders to bring actionable insights to the business via enhanced metrics and innovative solutions.Collaborative work environment with global teams.Competitive salary and comprehensive benefits.Continuous learning and professional development opportunities.