Apply Now

Please mention DailyRemote when applying

AI Summary

The analyst oversees the enterprise technology governance framework, lifecycle management, and IT compliance policies. They act as a liaison for audit teams and ensure infrastructure remains secure and aligned with business requirements.
Benefits:
  • Competitive salary
Location
Boston, MA

Experience Level
Senior Level (5 to 8 or more years of experience)

Role Overview
The Senior Technology Governance Analyst oversees the enterprise technology governance framework, lifecycle management processes, and IT compliance policies. This role designs, implements, and maintains IT standards and procedures while ensuring all technology assets are tracked from procurement to retirement. Drawing on a background in technology audit, risk management, and information security, the analyst bridges the gap between technical operations and regulatory compliance, ensuring that infrastructure remains secure, resilient, and fully aligned with business requirements. This is a contract position for 6 or more months.

Key Responsibilities
Standards, Policies, & Procedures

• Draft, review, and update comprehensive IT policies, procedures, and technical standards to align with industry frameworks such as ISO, COBIT, NIST, and ITIL.
• Drive organization-wide adoption of technology standards through training, structured documentation, and clear knowledge sharing.
• Evaluate existing technology governance, compliance, and risk processes regularly to identify gaps, operational inefficiencies, and opportunities for process optimization.

Technology Lifecycle Management (TLM)
• Manage the end-to-end lifecycle of hardware, software, and enterprise applications, tracking asset health, support status, and obsolescence risks.
• Maintain the definitive Software Asset Management (SAM) data and the hardware Configuration Management Database (CMDB).
• Collaborate with Engineering, Finance, and Vendor Risk Management teams to plan and execute system upgrades, data migrations, and decommissioning of legacy platforms.
• Act as the technical vendor relationship manager for selected third-party technology and infrastructure partners.

Technology Risk & Information Security
• Conduct technical risk assessments on existing infrastructure, newly proposed technologies, and automated release pipelines.
• Partner with Information Security teams to validate that data security policies meet strict data protection regulations.
• Identify vulnerability patterns and integrate secure baselines into the deployment lifecycle, supporting review and approval gates within a Secure Software Development Lifecycle (SSDLC).
• Develop risk mitigation strategies and maintain central registries of known risks, acceptance criteria, and periodic renewal and closure timelines in coordination with Enterprise Risk.

Audit Collaboration & Identity Governance
• Act as the primary liaison for internal and external technology audit teams, gathering, validating, and organizing audit evidence.
• Track audit findings and remediation plans, ensuring technical teams resolve identified control deficiencies on schedule.
• Perform pre-audit readiness assessments to proactively identify, test, and resolve compliance gaps.
• Assist in executing and enhancing Access Management processes, supporting user access requests, and coordinating periodic access reviews for user and operational accounts.

Required Qualifications
• 5 to 8 or more years of professional experience in IT governance, technology audit, information security, or IT risk management.
• In-depth knowledge of NIST, ISO/IEC 27001, COBIT, and ITIL frameworks.
• Hands-on experience utilizing ITAM and ITSM tools (such as ServiceNow, Jira, or Flexera) to manage directories and configurations.
• Solid understanding of internal audit standards, risk testing, and control validation methodologies.
• Experience implementing review and approval gates within a Secure Software Development Lifecycle (SSDLC), including automated processes within CI/CD pipelines.
• Bachelor's or Master's degree in Computer Science, Information Systems, Cyber Security, or a related technical field.

Preferred Qualifications
• Professional certifications, such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP).
• Prior experience managing compliance, ITAM registries, or audit remediations within highly regulated environments (such as financial services or investment management).
• Experience directly coordinating third-party vendor risk assessments and contract management frameworks.

Core Skills & Attributes
• Exceptional written and verbal communication skills, with a proven ability to translate complex technical concepts into clear, accessible policy language.
• Strong critical thinking, problem-solving, and analytical capabilities with high attention to regulatory and procedural details.
• Outstanding organizational and relationship-building skills to collaborate productively across cross-functional engineering, finance, and security teams.
• Self-motivated with a disciplined approach to tracking milestones, resolving audit findings, and managing timelines.

Flexible work from home options available.

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified