Job Description:

Fidelity will not provide immigration sponsorship for this position.

The Role

Are you passionate about strengthening technology controls and influencing risk outcomes at enterprise scale? Do you thrive in complex environments where your judgment, expertise, and leadership help shape enterprise risk decisions? As a Principal Technology Risk Analyst, you will play a critical role in advancing Fidelity's technology risk management capabilities. This role offers the opportunity to lead highly complex initiatives, provide strategic risk guidance to senior stakeholders, and drive continuous improvement across the technology risk landscape.

Core responsibilities include:

  • Leading highly complex technology risk and controls assessments supporting audit, regulatory, certification, and enterprise risk management objectives
  • Evaluating control design and operating effectiveness across complex, distributed, cloud, and vendor-hosted environments while identifying emerging risks and systemic control concerns
  • Partnering with senior leaders across technology, risk, compliance, and audit organizations to influence risk decisions and drive remediation of significant control gaps
  • Applying advanced risk expertise, analytical thinking, and professional judgment to resolve complex technology risk and control challenges
  • Driving enhancements to testing methodologies, risk assessment practices, automation capabilities, and reporting processes
  • Providing leadership, coaching, and strategic direction across workstreams while contributing to the development of team capabilities and risk management practices

The Expertise and Skills You Bring

You bring extensive experience in technology risk, controls, cybersecurity, or audit functions within complex organizations, along with the ability to lead large-scale assessments and influence outcomes across diverse stakeholder groups. You possess deep knowledge of technology risk frameworks and control evaluation methodologies and are comfortable advising senior leaders on complex risk matters. You communicate effectively, navigate ambiguity, and leverage data-driven insights to support sound risk decisions.

Key qualifications include:

  • Bachelor's degree in computer science, technology, or a related field (Master's degree preferred)
  • 8 or more years of experience in technology risk, IT, cybersecurity, cloud, analytics, audit, or related risk management roles
  • Experience leading complex control assessments and evaluating control maturity across diverse technology environments
  • Advanced knowledge of industry frameworks such as NIST, COBIT, AICPA Trust Services Criteria, ISO 27001, HITRUST, or similar
  • Familiarity with cloud security models (AWS, Azure, SaaS, PaaS) and GRC platforms such as Archer (preferred)
  • Professional certifications such as CISA, CISSP, CRISC, CISM, or similar certifications preferred

The Team

We are part of Fidelity's Enterprise Technology Risk organization, embedded within the broader Legal, Risk, and Compliance function. Our Technology Risk Controls Testing team exists to provide independent, objective assurance over the effectiveness of technology controls protecting our clients, employees, and brand. We work closely with Corporate Audit, Enterprise Compliance, Information Security, Operational Risk, and technology and business partners across Fidelity.

Our team is built on collaboration, accountability, and a relentless commitment to risk excellence. We value diverse perspectives, continuous learning, and strong partnerships that help Fidelity remain resilient in an evolving technology landscape. We are committed to fostering an inclusive culture where our people are empowered to grow, contribute, and make a meaningful impact.

Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:

Category:

Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.