Skip to content
  • Home
  • Talent
    • Job Seekers
    • Employers
  • Resources
    • Blog
    • Webinar library
  • About
    • Who we are
    • News
  • Contact
  • Sr. Manager, Information Technology and Information Security Risk

    Sr. Manager, Information Technology and Information Security Risk
    Hybrid Work Schedule- 3 days onsite in Reston, VA

    SUMMARY OF POSITION:

    The Information Technology and Information Security Risk (IT/IS) Sr. Manager plays a critical enterprise-wide role in overseeing cybersecurity, technology, data, AI and information security risk governance. This role partners with the Chief Risk Officer (CRO) and the Enterprise Risk Management team in identifying, assessing, and monitoring the organization’s technology and cybersecurity risk profile to ensure alignment with the our client’s strategic objectives, risk appetite, and regulatory expectations.

    This role has broad ownership and visibility across the enterprise and serves as a key second-line risk partner to senior leadership, business lines, IT, Information Security, Compliance, and third-party vendors. The Senior Manager will help ensure adherence to regulatory expectations from agencies such as FHFA, FFIEC, OCC, FDIC, SEC, and FINRA. This person will partner with business lines, IT, and compliance teams to maintain a strong security posture and reduce exposure across critical financial systems and third-party relationships, strengthening the organization’s overall cyber resilience and operational risk management framework.

    Core Responsibilities 

    • Evaluate and provide independent challenge regarding the alignments of the organization’s IT and IS strategy with enterprise business objectives, risk appetite, and regulatory expectations.
    • Review and assess the adequacy of information technology and security risk assessments across applications, infrastructure, and business processes.
    • Partner with IT project teams to influence decisions related to technology architecture, cybersecurity controls, system implementations, and operational risk mitigation strategies
    • Evaluate new and existing systems, platforms, and SAAS integrations for cybersecurity risks and regulatory compliance impacts.
    • Conduct third party and vendor security risk assessments, including review of SOC 1/SOC 2 reports, SIG questionnaires, penetration testing results, and remediation plans to ensure vendor information security practices align with OF expectations.
    • Provide effective second-line oversight and credible challenge related to cybersecurity incidents, operational disruptions, and emerging technology risks, including analysis of potential impacts to customer data, financial systems, and regulatory obligations.
    • Collaborate with business units and technology teams to identify, document, and monitor risks, ensuring remediation activities meet regulatory timelines and internal risk appetite.
    • Oversee the implementation of information technology and security risk management policies and the Cyber-Security Incident Response Plan
    • Conduct cyber security awareness training and education through periodic email phishing tests, in-person and computer-based training, presentations to employees, and security related tabletop exercises.
    • Monitor the status of remediation for IT and IS related issues and ensure that the remediation documentation is complete and adequate.
    • Monitor cybersecurity and financial sector threat intelligence; communicate emerging risks to leadership.
    • Oversee IT and IS key risk indicators (KRIs) and maintain clear and accurate dashboards and reporting metrics for senior management, risk committees, and regulators
    • Ability to analyze complex technical environments and communicate risk in business-focused terms.
    • Strong knowledge of information security frameworks including NIST CSF, NIST 800‑53, ISO 27001, CIS Controls.
    • Effective communication skills for interacting with auditors, examiners, and senior management.

    PREFERRED SKILLS AND EXPERIENCE:

    • Bachelor’s degree in Information Security, Cybersecurity, Risk Management, or related fields (or equivalent work experience) preferred.
    • 8–10 years of relevant experience in information security or risk management roles with experience in financial services, banking, payments, fintech, or related regulatory environments preferred.
    • Experience with data analytics and visualization tools (e.g., Power BI, Tableau, or Python).
    • Experience working in a regulated financial services or technology environment.
    • CRISC, CISSP, CISM, Security+ or CGEIT or similar certifications 
    July 6, 2026
  • Software Engineer – Java17+ and Spring Boot

    SUMMARY OF POSITION

    The Software Engineer will bring a strong technical and analytical mindset required to transform the current suite of applications in use into modern APIs and services. A successful candidate will work on an empowered scrum team to design and implement solutions to improve product capabilities and implement business efficiencies through a mix of process automation and innovation.

    This position serves a crucial role in support of the mission critical areas of debt issuance, debt servicing, and combined financial reporting, which depend on the accuracy and the availability of the highly customized IT environment for the successful operation of the organization. 

    NATURE AND SCOPE

    The Software Engineer is expected to have an understanding of agile software engineering and DevSecOps principles and practices. This includes the development of container-based microservices, automated testing, and leveraging CI/CD pipelines to support the continuous delivery of services and APIs.

    The Software Engineer will have ownership of execution and flexibility to determine technical implementation and design of the modernization efforts and process automation. The Software Engineer will stay on top of tech trends, mentoring other team members, sharing accountability, and experimenting with and learning new technologies. The Software Engineer will require quality and know what it means to ship high-quality code with minimal manual testing.

    PRINCIPAL RESPONSIBILITIES

    Contribute to changes and improvements to business services through a mix of application, automation, and engineering activities.
    Develop secure, scalable services, sophisticated platforms, and APIs essential for financial systems.
    Analyze highly complex system and technical issues to implement features and enhancements in an iterative way that align with strategic technical direction.
    Participate in an environment rapidly transforming into the Agile methodology, adhering to best practicesand collaborating effectively with your teammates.
    Work together with other teams to ensure service quality, availability and reliability.
    Work with the project team and the appropriate stakeholders to convert business requirements to written technical specifications that adhere to the OF’s architectural guidelines and industry best practices.
    Support application end-users by addressing and resolving application-related problems 
    Develop and maintain application support end user documentation.


    PRINCIPAL REQUIREMENTS

    Bachelor’s degree in Computer Science, Information Systems, or related field, or relevant work experience.
    5-7 years expertise in Spring Boot and Java17+.
    Integrated Development Environments: Intellj and Maven
    Solid experience with core Java technologies and concepts
    Strong unit, mock, and behavioral testing background using tools like Junit 5, Mockito, and Cucumber
    Knowledge of multi-tier web application development using standard presentation layer technologies; and
    Understanding of source code management principles in a team environment.

    Preferred 
    Deep understanding of Java performance tuning (GC, threading, memory)
    Source control system: Git
    Advanced SQL skills (Liquibase is a plus)
    Working knowledge of financial services and mortgage industries, including related rules and regulations; and
    Ability to develop UNIX or RHEL-based scripts.
    Knowledge of object-oriented design and programming concepts including design patterns.
    Experience in microservices and RESTful service design and development.
    Proficiency with Circuit breakers, retries, idempotency strategies.
    Experience with transaction management, messaging, thread safety, and data integrity.
    Experience with load testing and tuning.
    Proficiency with Continuous Integration/Continuous Delivery process and tools; Jenkins and pipeline as code a plus.
    Experience with front-end technologies such as Angular, TypeScript or similar technologies.
    Familiarity with Docker/Kubernetes.
    Familiarity with OpenShift stack.
    Familiarity JMS queue/topic development/usage.
    Actively working on projects using agile/lean methodologies and practices; Jira/Confluence tools a plus.

    June 30, 2026
  • Lead IT Auditor

    Senior IT Audit Lead

    JOB DESCRIPTION

    As the Lead IT Auditor on this you will perform as part of an Internal Audit function, providing independent and objective assurance and advisory services to business and technology leadership by evaluating risks and internal controls across a complex enterprise environment. This includes infrastructure, applications, and core technology processes, using a structured audit methodology. Results are communicated to leadership along with practical recommendations to strengthen controls and mitigate risk. The team also supports advisory engagements and participates in strategic initiatives to proactively identify risks and improve governance.

    RESPONSIBILITIES

    • Lead and execute audit engagements from planning through reporting with limited oversight from senior leadership
    • Conduct end-to-end audit activities including stakeholder walkthroughs, process documentation, risk and control identification, testing, and validation of corrective actions
    • Define audit scope, timelines, and objectives while acting as the primary owner of assigned engagements
    • Guide and review the work of team members, providing ongoing feedback and supporting professional development
    • Identify control deficiencies, process gaps, and compliance considerations across assigned areas
    • Deliver audit work within agreed timelines, providing clear updates to leadership throughout the engagement
    • Operate within an agile audit environment, aligning deliverables to defined cycles and maintaining active collaboration with stakeholders
    • Track and validate remediation efforts to ensure timely and effective resolution of audit findings
    • Develop clear and concise audit reports and findings with minimal revision required
    • Contribute to integrated audits by assessing both technology and operational risks and controls
    • Build and maintain strong working relationships across business and technology teams
    • Present audit results and recommendations to management with confidence and clarity
    • Identify opportunities to enhance audit methodologies, tools, and practices
    • Participate in broader enterprise initiatives and internal projects
    • Apply data-driven techniques to support risk assessment and audit testing where appropriate

    REQUIRED ABILITIES

    • Strong proficiency with audit tools and methodologies
    • Deep understanding of technology environments, business processes, and associated risks and controls
    • Familiarity with industry-standard frameworks such as COBIT, COSO, or ITIL
    • Knowledge of applicable regulatory and compliance considerations
    • Awareness of fraud risk indicators and prevention techniques
    • Broad understanding of financial services operations or other highly regulated industries
    • Knowledge of enterprise technology including infrastructure, systems, security principles, and emerging areas such as cloud and advanced analytics

    REQUIRED SKILLS

    • Proven ability to lead and coordinate audit activities
    • Capable of independently executing complex audit programs
    • Sound professional judgment and decision-making ability
    • Strong collaboration skills across distributed and cross-functional teams
    • Ability to analyze, document, and clearly explain processes and findings
    • Skilled in identifying risks, controls, and areas for improvement
    • Effective time management and prioritization under deadlines
    • Strong analytical and problem-solving capabilities
    • Excellent written and verbal communication skills
    • Advanced proficiency with business tools and systems (for example reporting tools, collaboration platforms, and enterprise applications)
    • Demonstrated ability to quickly learn new tools, systems, and business domains
    • High level of professional skepticism and accountability
    • Self-driven with strong leadership presence

    REQUIRED EXPERIENCE

    5+ years’ experience in IT audit, risk, or related discipline

    PREFERRED EXPERIENCE

    IT Audit experience with a “big 4” consulting company is preferred OR

    IT Audit experience from within a highly regulated industry

    REQUIRED CERTIFICATIONS

    One or more relevant certifications: CIA, CISA, or CPA

    Work Environment

    Commitment to delivering high-quality service to internal stakeholders

    Flexibility to support varying workloads and deadlines

    Standard corporate office or hybrid work setting

    Occasional travel may be required, including potential international travel

    Role may involve adherence to defined service level expectations

    May 18, 2026

Follow us

Sitemap

About us

Talent

Contact us

Privacy Policy

Terms of Use

Contact info

1602 Abbey Court
Alpharetta, Georgia 30004

770-807-0583

info@tier4group.com

© 2026 Tier4 Group. All Rights Reserved.