Principal Technical Risk Analyst
Fa Etbx Saasfaprod1 · Vienna, VA, United States
About The Role
Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.
Responsible for leading and performing New Business Initiative Assessments (NBIAs) for proposed and changing products, services, technologies, processes, partnerships, and business capabilities. The role evaluates risk across the initiative lifecycle, identifies material concerns and control needs, and helps business and risk partners reach well-informed, timely decisions. It requires practical experience working across the First, Second, and Third Lines of Defense (1LOD, 2LOD, and 3LOD), with clear understanding of each line's responsibilities, independence, and role in effective challenge and assurance.
The Principal Tech Risk Analyst partners with initiative owners and key stakeholders across Information Security, Fraud, Physical Security, Technology, Enterprise Risk, Compliance, Legal, Privacy, Procurement and Vendor Management, Internal Audit, and other relevant functions. The role translates complex technical and operational risks into clear business language, facilitates cross-functional assessments, documents decisions and evidence, and drives issues through resolution. The analyst also applies process improvement and Lean Six Sigma methods to improve NBIA intake, scoping, assessment, handoffs, cycle time, data quality, reporting, and stakeholder experience. Work is performed independently on complex, high-impact initiatives, with the individual serving as a recognized subject matter expert and trusted advisor.
- Lead and perform NBIAs for new or materially changing products, services, technologies, processes, third-party relationships, and business capabilities.
- Determine assessment scope, applicable risk domains, required stakeholders, evidence needs, decision points, and escalation paths based on the nature and risk of the initiative.
- Partner effectively across 1LOD, 2LOD, and 3LOD, respecting role clarity, ownership, effective challenge, independent oversight, and assurance responsibilities.
- Facilitate cross-functional risk discussions with initiative owners and stakeholders in Information Security, Fraud, Physical Security, Technology, Enterprise Risk, Compliance, Legal, Privacy, Procurement and Vendor Management, Internal Audit, and other relevant areas.
- Assess risks related to cybersecurity, data protection, fraud, physical security, technology resilience, third parties, regulatory obligations, operational processes, and control design.
- Identify risk themes, control gaps, dependencies, unresolved decisions, and conditions that must be satisfied before implementation or launch.
- Evaluate whether proposed controls are clearly defined, appropriately owned, supported by evidence, and designed to reduce risk to an acceptable level.
- Provide credible, constructive challenge and translate technical, security, fraud, and operational concerns into plain business language for both technical and non-technical audiences.
- Develop clear assessment records, risk statements, recommendations, action plans, approvals, exceptions, decision rationales, and evidence trails that support governance and audit needs.
- Track assessment actions and dependencies through closure, coordinating with accountable owners and escalating overdue or material concerns through established governance channels.
- Prepare concise, decision-ready reporting for senior leaders and governance forums, including material risk, open issues, required actions, ownership, and readiness considerations.
- Apply Lean Six Sigma and other process improvement methods to identify waste, reduce handoff delays, simplify intake and assessment steps, improve data quality, and strengthen the consistency and timeliness of NBIA outcomes.
- Develop and maintain NBIA procedures, templates, tools, decision criteria, training materials, metrics, dashboards, and stakeholder guidance.
- Promote early engagement and risk-informed decision-making by educating business and technology teams on when an NBIA is required and how to prepare for an efficient assessment.
- Monitor emerging threats, regulatory expectations, and business changes that could affect NBIA methodology, assessment criteria, or stakeholder participation.
- Bachelor's or master’s degree in Cybersecurity, Information Technology, Risk Management, Business, Engineering, Criminal Justice, Process Improvement, or a related field, or an equivalent combination of training, education, and experience.
- Significant experience performing or leading risk assessments for new business initiatives, products, services, technologies, processes, or third-party relationships in a complex or regulated organization.
- Demonstrated familiarity and hands-on experience working with the First, Second, and Third Lines of Defense (1LOD, 2LOD, and 3LOD), including business ownership, independent risk oversight and challenge, and audit or assurance activities.
- Significant background or experience in Information Security, with working knowledge of cybersecurity risk, data protection, identity and access, resilience, vulnerability management, and security control concepts.
- Experience evaluating fraud risks, fraud prevention considerations, or financial crime-related impacts associated with business and technology change.
- Experience evaluating Physical Security risks or partnering with Physical Security stakeholders on facilities, people, assets, access, safety, or related operational considerations.
- Proven ability to coordinate and influence a broad group of stakeholders across business, technology, risk, security, compliance, legal, privacy, procurement, vendor management, and audit functions.
- Strong understanding of risk and control concepts, including inherent risk, residual risk, risk appetite, control design, evidence, issues, exceptions, remediation, and governance reporting.
- Ability to analyze complex and incomplete information, identify the most important risks and dependencies, and form clear, well-supported conclusions and recommendations.
- Experience applying Process Improvement, Lean, Lean Six Sigma, or comparable methods to streamline workflows, reduce defects and delays, improve quality, and establish measurable outcomes.
- Ability to facilitate structured working sessions, resolve ambiguity, manage competing viewpoints, and drive decisions and actions to closure without losing necessary independence or challenge.
- Excellent written and verbal communication skills, including the ability to convert technical and risk information into concise, plain-language materials for executives, governance bodies, and non-technical partners.
- Strong documentation and organizational skills, with the ability to maintain complete, accurate, and audit-ready assessment records.
- Significant experience in financial services or another highly regulated industry preferred.
Desired Qualifications
- Desired certifications may include CISSP, CRISC, CISA, PMP, Certified Fraud Examiner (CFE), Physical Security Professional (PSP), Lean Six Sigma Green Belt or Black Belt, or comparable credentials.
Additional Information
Hours
- Monday - Friday, 8:00AM - 4:30PM
Location
- 820 Follin Lane, Vienna, VA 22180
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
