
Technology Risk Professional- Senior Manager
- Gurgaon, Haryana
- Permanent
- Full-time
- Provide independent oversight, assurance, and strategic guidance for technology risk, including infrastructure, application, AI technologies, cloud platforms, networks, servers, desktop, and mobile environments.
- Identify, assess, and effectively communicate complex technology risks - including deployment and integration of legacy and modern systems - translating these risks into actionable tasks for technical teams.
- Lead oversight of risks associated with integrating new and legacy technology systems, ensuring robust controls to manage potential exposures.
- Establish clear governance and approval mechanisms for AI tools and integrations, evaluating risks related to data privacy, cyber threats, accuracy, bias, and compliance.
- Collaborate with development teams to embed risk management, AI-specific controls, and security best practices throughout the software and AI model development lifecycles.
- Conduct independent thematic reviews and assurance audits of technology systems (including AI), legacy system risks, and infrastructure security, ensuring vulnerabilities are addressed promptly.
- Ensure compliance with relevant regulations and align technology risk management strategies with frameworks such as NIST, ISO 27001, and MITRE ATT&CK.
- Oversee change testing initiatives, including penetration testing, code analysis, and vulnerability assessments of both traditional and AI-driven application
- Ensure Business Continuity and Disaster Recovery plans account for risks arising from legacy system dependencies and integration with modern infrastructure and processes.
- Proven experience in a technology-focused second-line risk management role, emphasising technology infrastructure, legacy system integration, and AI-specific risk oversight, alongside cybersecurity.
- Deep understanding of technology architecture, legacy systems, modern cloud platforms (AWS/Azure), network infrastructure, servers, desktop environments, mobile devices, and AI technologies.
- Strong familiarity with AI risk management, including AI governance frameworks, risk assessments, bias management, privacy considerations, and regulatory implications.
- Extensive experience overseeing integration risks between legacy and modern technology systems, with the ability to identify and mitigate compatibility, security, and operational risks.
- In-depth knowledge of frameworks such as NIST, ISO 27001, MITRE ATT&CK, and emerging best practices specific to AI security and governance.
- Demonstrated ability to audit complex technology environments, identify vulnerabilities in legacy and new systems, and implement effective risk treatment plans.
- Hands-on experience with secure software development practices, security testing methodologies, and risk assessment within agile SDLC environments.
- Excellent communication skills, able to translate complex technology risks clearly and concisely for executive-level stakeholders and technical teams alike.
- 6+ years of experience in technology-focused second-line risk management role, emphasising technology infrastructure, legacy system integration, and AI-specific risk oversight, alongside cybersecurity.
- Advanced knowledge of technology security fundamentals including NIST frameworks, ISO 27001, vulnerability management, and secure configurations.
- Specialist expertise in infrastructure security (EDR, DLP, penetration testing) and specific experience managing AI technology risks.
- Practical experience managing technology risk in cloud environments (AWS/Azure), including legacy and hybrid infrastructures.
- Relevant professional certifications:
- Risk Management: ISACA CRISC, ISACA CISA, SANS GCCCSecurity: CISSP, CISM, CEH, ISO 27001 Lead Auditor
- Cloud Security: CCSP, AWS Certified Security Specialty, or similar certifications
- AI/ML-specific certifications (optional, beneficial), e.g., Certified AI Risk Practitioner, AI Governance Professional.