Overview Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship. Responsible for leading and performing New Business Initiative Assessments (NBIAs) for proposed and changing products, services, technologies, processes, partnerships, and business capabilities. The role evaluates risk across the initiative lifecycle, identifies material concerns and control needs, and helps business and risk partners reach well-informed, timely decisions. It requires practical experience working across the First, Second, and Third Lines of Defense (1LOD, 2LOD, and 3LOD), with clear understanding of each line's responsibilities, independence, and role in effective challenge and assurance.
The Principal Tech Risk Analyst partners with initiative owners and key stakeholders across Information Security, Fraud, Physical Security, Technology, Enterprise Risk, Compliance, Legal, Privacy, Procurement and Vendor Management, Internal Audit, and other relevant functions. The role translates complex technical and operational risks into clear business language, facilitates cross-functional assessments, documents decisions and evidence, and drives issues through resolution. The analyst also applies process improvement and Lean Six Sigma methods to improve NBIA intake, scoping, assessment, handoffs, cycle time, data quality, reporting, and stakeholder experience. Work is performed independently on complex, high-impact initiatives, with the individual serving as a recognized subject matter expert and trusted advisor.
Responsibilities - Lead and perform NBIAs for new or materially changing products, services, technologies, processes, third-party relationships, and business capabilities.
- Determine assessment scope, applicable risk domains, required stakeholders, evidence needs, decision points, and escalation paths based on the nature and risk of the initiative.
- Partner effectively across 1LOD, 2LOD, and 3LOD, respecting role clarity, ownership, effective challenge, independent oversight, and assurance responsibilities.
- Facilitate cross-functional risk discussions with initiative owners and stakeholders in Information Security, Fraud, Physical Security, Technology, Enterprise Risk, Compliance, Legal, Privacy, Procurement and Vendor Management, Internal Audit, and other relevant areas.
- Assess risks related to cybersecurity, data protection, fraud, physical security, technology resilience, third parties, regulatory obligations, operational processes, and control design.
- Identify risk themes, control gaps, dependencies, unresolved decisions, and conditions that must be satisfied before implementation or launch.
- Evaluate whether proposed controls are clearly defined, appropriately owned, supported by evidence, and designed to reduce risk to an acceptable level.
- Provide credible, constructive challenge and translate technical, security, fraud, and operational concerns into plain business language for both technical and non-technical audiences.
- Develop clear assessment records, risk statements, recommendations, action plans, approvals, exceptions, decision rationales, and evidence trails that support governance and audit needs.
- Track assessment actions and dependencies through closure, coordinating with accountable owners and escalating overdue or material concerns through established governance channels.
- Prepare concise, decision-ready reporting for senior leaders and governance forums, including material risk, open issues, required actions, ownership, and readiness considerations.
- Apply Lean Six Sigma and other process improvement methods to identify waste, reduce handoff delays, simplify intake and assessment steps, improve data quality, and strengthen the consistency and timeliness of NBIA outcomes.
- Develop and maintain NBIA procedures, templates, tools, decision criteria, training materials, metrics, dashboards, and stakeholder guidance.
- Promote early engagement and risk-informed decision-making by educating business and technology teams on when an NBIA is required and how to prepare for an efficient assessment.
- Monitor emerging threats, regulatory expectations, and business changes that could affect NBIA methodology, assessment criteria, or stakeholder participation.
Qualifications - Bachelor's or master's degree in Cybersecurity, Information Technology, Risk Management, Business, Engineering, Criminal Justice, Process Improvement, or a related field, or an equivalent combination of training, education, and experience.
- Significant experience performing or leading risk assessments for new business initiatives, products, services, technologies, processes, or third-party relationships in a complex or regulated organization.
- Demonstrated familiarity and hands-on experience working with the First, Second, and Third Lines of Defense (1LOD, 2LOD, and 3LOD), including business ownership, independent risk oversight and challenge, and audit or assurance activities.
- Significant background or experience in Information Security, with working knowledge of cybersecurity risk, data protection, identity and access, resilience, vulnerability management, and security control concepts.
- Experience evaluating fraud risks, fraud prevention considerations, or financial crime-related impacts associated with business and technology change.
- Experience evaluating Physical Security risks or partnering with Physical Security stakeholders on facilities, people, assets, access, safety, or related operational considerations.
- Proven ability to coordinate and influence a broad group of stakeholders across business, technology, risk, security, compliance, legal, privacy, procurement, vendor management, and audit functions.
- Strong understanding of risk and control concepts, including inherent risk, residual risk, risk appetite, control design, evidence, issues, exceptions, remediation, and governance reporting.
- Ability to analyze complex and incomplete information, identify the most important risks and dependencies, and form clear, well-supported conclusions and recommendations.
- Experience applying Process Improvement, Lean, Lean Six Sigma, or comparable methods to streamline workflows, reduce defects and delays, improve quality, and establish measurable outcomes.
- Ability to facilitate structured working sessions, resolve ambiguity, manage competing viewpoints, and drive decisions and actions to closure without losing necessary independence or challenge.
- Excellent written and verbal communication skills, including the ability to convert technical and risk information into concise, plain-language materials for executives, governance bodies, and non-technical partners.
- Strong documentation and organizational skills, with the ability to maintain complete, accurate, and audit-ready assessment records.
- Significant experience in financial services or another highly regulated industry preferred.
Desired Qualifications- Desired certifications may include CISSP, CRISC, CISA, PMP, Certified Fraud Examiner (CFE), Physical Security Professional (PSP), Lean Six Sigma Green Belt or Black Belt, or comparable credentials.
Additional InformationHours:- Monday - Friday, 8:00AM - 4:30PM
Location:- 820 Follin Lane, Vienna, VA 22180
About Us Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.
Our approach to careers is simple yet powerful: Make our mission your passion.
FORTUNE 100 Best Companies to Work For 2026
Yello and WayUp Top 100 Internship Programs 2025
Computerworld Best Places to Work in IT 2026
Most Loved Workplace - America's Top Most Loved Workplaces 2025
2025 PEOPLE Companies That Care
Newsweek Most Trustworthy Companies in America 2026
Military Times 2025 Best for Vets Employers
Forbes 2026 America's Best Large Employers
Forbes 2025 America's Best Employers for New Grads
Forbes 2025 America's Best Employers for Tech Workers
2025 RippleMatch Campus Forward Award Winner for Overall Excellence
Military.com Top Military Spouse Employers 2025
2026 Handshake Early Talent Award
Newsweek America's Greatest Workplaces for Culture, Belonging and Community 2026
From Fortune Magazine. 2026 Fortune Media IP Limited. All rights reserved. Used under license. Fortune and Fortune 100 Best Companies to Work For are registered trademarks of Fortune Media IP Limited and are used under license. Fortune Magazine, Fortune Media (USA) Corporation, and its affiliates are not affiliated with, and do not endorse products or services of, Navy Federal Credit Union.
Equal Employment Opportunity: All qualified applicants will receive consideration for employment without regard to age, race, sex, color, religion, national origin, disability, veteran status, pregnancy, sexual orientation, genetic information, gender identity or any other basis protected by applicable law.
Accommodations: If you need accommodation or assistance for a qualifying condition to complete the online application (or during any stage of the hiring process), you can contact Navy Federal's Medical Accommodations team at or by calling 1-. This team cannot provide any information on job postings or application status.
Disclaimers: Navy Federal reserves the right to fill this role at a higher/lower grade level based on business need. An assessment may be required to compete for this position. Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team's discretion based on qualified applicant volume. Navy Federal Credit Union assesses market data to establish salary ranges that enable us to remain competitive. You are paid within the salary range, based on your experience, location and market position. For additional details regarding compensation and benefits, review the Benefits page of the Navy Federal Career Site.
Protect Yourself from Job Scams: Navy Federal Credit Union jobs are posted on our career site, jobs.navyfederal.org and reputable job boards (e.g., LinkedIn, Indeed). We do not post jobs on social media marketplaces, messaging apps or unverified websites. We will never ask candidates for payment, bank details or personal financial information during the hiring process.
Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.