Principal Technology Risk
Fidelity Investments is a privately held, Boston-headquartered financial services company providing investing, trading, retirement, wealth management, brokerage, workplace benefits, custody and clearing, and digital-asset services.
Maintainer signals as of 9/2/2026
About Fidelity Investments
Fidelity serves individual investors, employers, wealth-management firms, institutions, innovators, and charitable donors through diversified financial-services businesses. Current offerings include brokerage and trading, mutual funds and exchange-traded products, retirement and workplace savings, financial planning and advice, wealth management, institutional custody and clearing, and crypto/digital-asset products.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will evaluate technology, financial, reputational, and regulatory risks across the risk portfolio. You will conduct risk and control assessments, monitor technology controls, oversee remediation plans, and advise on strategic initiatives and emerging technologies. You will analyze data, communicate risk insights to leadership, and coordinate audit findings through resolution.
Requirements
- Apply analytical, problem-solving, and critical-thinking skills to assess risk and influence decisions.
- Know cloud-native architectures, container platforms, CI/CD pipelines, application security, and database management platforms.
- Have experience leading technology risk assessments, control assessments, IT audits, or cybersecurity-control implementation for large financial-services organizations.
- Communicate complex technology, risk, and operational risks to senior leadership and executive audiences.
- Know artificial intelligence, machine learning, LLMs, data science, and robotic process automation tools.
- Have 6 or more years of experience in information technology risk, cybersecurity, controls, or audit roles.
- Hold or be pursuing relevant technology-risk or cloud certifications, such as CISSP, CISA, CRISC, CISM, CCSP, CCSK, or AWS certification.
Responsibilities
- Evaluate technology, financial, reputational, and regulatory risks.
- Conduct proactive risk and control assessments.
- Monitor technology controls and oversee remediation plans.
- Provide risk and controls consulting for strategic initiatives and emerging technologies.
- Lead risk assessments for cloud modernization, emerging technology implementation, and key business capabilities.
- Identify systemic risk themes and emerging threats.
- Analyze data and use automated tools to assess potential exposure and business loss.
- Coordinate with legal, risk, compliance, enterprise technology, and audit stakeholders.
- Track audit findings, follow up on issues, and support resolution plans.
Benefits
- Fully paid parental leave.
- On-site health and wellness centers.
