Senior Technology Governance Analyst

Geode Capital
  • Boston, Massachusetts
    Today

    Job Description

    Geode Capital Management, LLC is seeking a highly skilled Senior Technology Governance Analyst to oversee our technology governance framework and lifecycle management processes. In this role, you will design, implement, and maintain IT standards, policies, and procedures while ensuring all technology assets are tracked from procurement to retirement. Utilizing your background in technology audit, risk management, and information security, you will bridge the gap between technical operations and compliance, ensuring our infrastructure remains secure, resilient, and fully aligned with regulatory requirements

    This role is based in our office in Boston, Massachusetts. You are required to follow the firm’s policy on in-office attendance. Our current policy requires in-office attendance on Tuesday, Wednesday, and Thursday, and then provides an option to work remotely on Monday and Friday. Please note that Geode may alter this policy at any time.

    Responsibilities:
    • Standards, Policies & Procedures:
      • Draft, review, and update comprehensive IT policies, procedures, and technical standards
      • Align IT frameworks with industry best practices and standards such as ISO, COBIT, NIST, and ITIL
      • Drive organization-wide adoption of technology standards through training and documentation
      • Evaluate existing technology governance, compliance and risk processes regularly to identify gaps, inefficiencies, and areas for governance improvement
    • Technology Lifecycle Management (TLM):
      • Manage the end-to-end lifecycle of hardware, software, and enterprise applications
      • Track asset health, support status, and obsolescence risks to prevent operational disruptions
      • Collaborate with Engineering, Finance, Vendor Risk management groups to identify, track and plan upgrades, migrations, and decommissioning of legacy systems, and act as vendor relationship manager for selected vendor partners.
      • Maintain the definitive software asset management (SAM) and hardware configuration management database (CMDB)
    • Technology Risk & Information Security:
      • Conduct technical risk assessments on existing infrastructure and newly proposed technologies
      • Identify vulnerability patterns and ensure security baselines are integrated into the deployment lifecycle
      • Partner with Information Security team to validate that policies meet strict data protection regulations
      • Develop risk mitigation strategies and maintain the details of known risks, mitigation plans, risk acceptance criteria, periodic renewal & closure of risks, in partnership with Enterprise Risk
    • Technology & Internal Audit Collaboration:
      • Act as a liaison for internal and external technology audit teams during reviews
      • Gather, validate, and organize audit evidence to demonstrate continuous compliance
      • Track audit findings and remediation plans, ensuring technical teams resolve deficiencies on schedule
      • Perform pre-audit readiness assessments to proactively identify and fix compliance gaps
    • Other Governance activities:
      • Assist in the ongoing execution and enhancement of Access Management processes, including maintaining and updating job profiles and supporting the user community with access-related requests
      • Provide support for periodic access reviews for both user and service/operational accounts, ensuring completeness and accuracy
    Skills You Bring:
    • 5-8 years of experience in IT governance, technology audit, information security, or IT risk management
    • Bachelor’s or Master’s degree in Computer Science, Information Systems, Cyber Security, or a related field
    • Preferred certifications: Certified Information Systems Auditor (CISA) or Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Security Professional (CISSP)
    • Deep knowledge of NIST, ISO/IEC 27001, COBIT, and ITIL frameworks
    • Hands-on experience with ITAM/ITSM tools (e.g., ServiceNow, Jira, Flexera)
    • Solid understanding of internal audit standards, risk testing, and control validation
    • Exceptional ability to translate complex technical concepts into clear, written policy language
    • Strong problem-solving skills with high attention to regulatory and procedural details
    • Experience implementing review and approval processes within a Secure Software Development Lifecycle (SSDLC), including use of modern fully integrated and automated processes within the CI/CD pipeline
    • Excellent verbal and written communication skills
    • Strong relationship building, organization, and critical thinking skills
     
    Company Overview:
     
    Founded in 2001, Geode is headquartered in Boston’s financial district, the center of one of the world’s most vibrant finance and technology hubs and employs approximately 200 employees.
     
    Geode is an institutional asset manager providing core beta exposures across a range of equity and niche asset classes, with over $2 trillion. With a robust infrastructure and experienced investment professionals, Geode offers the scale of a large asset management firm with the benefits of a smaller organization. 
     
    Our compensation philosophy is designed to attract, motivate, and retain top talent. We are committed to ensuring that compensation reflects the value our employees bring to Geode. Employees at all levels are eligible to receive a combination of base salary, variable compensation, and a comprehensive benefits package. Compensation decisions are informed by a range of factors including role, experience, education, and skillset.  
     
    Our benefits program is designed to support employees both professionally and personally, offering comprehensive health coverage, 401(k) matching, annual profit sharing, paid parental leave, and generous time off. We also provide tuition and certification reimbursement, student loan support, fitness reimbursement, commuter subsidy, charitable donation matching, family care assistance including a backup care benefit, adoption and surrogacy support. Hybrid work arrangements and a culture that encourages community engagement through volunteer opportunities and employee events further enhance the employee experience at Geode.
     
    Geode is proud to be an equal opportunity employer and support a diversified work environment. Learn more about Geode at www.geodecapital.com/careers.
     

    Numbers & Facts

    LocationBoston, Massachusetts
    Websitehttps://www.geodecapital.com/careers

    Skills

    • Adoptionunmatched
    • Asset Managementunmatched
    • Asset Management Softwareunmatched
    • Atlassian JIRAunmatched
    • Auditingunmatched
    • Best Practicesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Communication Skillsunmatched
    • Community Supportunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Documentationunmatched
    • Employee Retentionunmatched
    • Enterprise Applicationsunmatched
    • External Auditunmatched
    • Financeunmatched
    • Hardware Configuration Managementunmatched
    • Hubsunmatched
    • ISO (International Organization for Standardization)unmatched
    • IT Governanceunmatched
    • IT Service Management (ITSM)unmatched
    • ITIL (IT Infrastructure Library)unmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Institutional Asset Managementunmatched
    • Internal Auditunmatched
    • International Electro-Technical Commission (IEC)unmatched
    • Internet Securityunmatched
    • Maintain Complianceunmatched
    • Philosophyunmatched
    • Presentation/Verbal Skillsunmatched
    • Problem Solving Skillsunmatched
    • Purchasing/Procurementunmatched
    • Regulationsunmatched
    • Regulatory Requirementsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Security Auditingunmatched
    • ServiceNowunmatched
    • Software Administrationunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Strategic Planningunmatched
    • Supplier Relationship Management (SRM)unmatched
    • System Migrationunmatched
    • Technical Leadershipunmatched
    • Technical Operationsunmatched
    • Technology Analysisunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Validation Testingunmatched
    • Vendor/Supplier Relationsunmatched
    • Vendor/Supplier Selectionunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder