Software Risk Manager

San Francisco, CA, US • Posted 4 hours ago • Updated 18 minutes ago
Full Time
Part Time
On-site
Fitment

Dice Job Match Score™

📊 Calculating match score...

Job Details

Skills

  • Risk Analysis

Summary

Software Risk Manager

Hybrid role in Lawrence, MA or San Francisco, CA area. Local candidates are preferred.

Software Risk Manager

Job Description:

  • The Software Risk Manager is responsible for identifying, assessing, mitigating, and continuously monitoring risks associated with software development, deployment, integration, and operations.
  • This role operates at the intersection of engineering, cybersecurity, compliance, product management, and enterprise risk to ensure software systems meet regulatory, security, operational, and business continuity standards.
  • The position requires deep understanding of SDLC governance, third-party risk, secure architecture principles, and operational resilience frameworks.



Software Risk Governance

  • Establish and maintain a formal software risk management framework aligned to enterprise risk standards.
  • Define risk taxonomy specific to software engineering, DevOps, cloud architecture, AI/ML systems, and third-party integrations.
  • Develop and enforce risk control policies across the SDLC.
  • Maintain software risk register and risk heat maps.

Risk Identification & Assessment

Conduct risk assessments for:

  • New software initiatives
  • Major releases
  • IoT connected devices
  • Third-party software integrations
  • Perform architecture risk reviews.
  • Lead threat modeling exercises.
  • Evaluate systemic, operational, security, and compliance risks.
  • SDLC & DevSecOps Integration
  • Embed risk controls within Agile, or DevOps workflows.
  • Collaborate with engineering leadership to implement secure-by-design and privacy-by-design principles.
  • Ensure code review, vulnerability scanning, and penetration testing processes are enforced.
  • Validate CI/CD pipelines include appropriate risk gates.

Regulatory & Compliance Alignment

  • Align software controls with relevant frameworks such as:
  • Support internal and external audits.
  • Maintain documentation for regulatory reviews.

Third-Party & Vendor Risk (not part of device scope, but for future)

  • Assess software vendors and SaaS platforms for:
    • Security posture
    • Data protection controls
    • Operational resilience
    • Financial stability risk
  • Coordinate due diligence reviews and ongoing monitoring.

Incident & Issue Management (this is closer to system risk and not needed for this role as we have a system risk manager)

  • Participate in post-incident root cause analysis.
  • Evaluate control breakdowns.
  • Recommend systemic remediation actions.
  • Track risk treatment plans to closure.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90884655
  • Position Id: OOJ - 8303-7328-1772641727
  • Posted 4 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Alameda, California

Today

Easy Apply

Full-time

Depends on Experience

Hybrid in San Francisco, California

5d ago

Easy Apply

Full-time

$150,000+

San Francisco, California

17d ago

Full-time

USD 180,000.00 - 270,000.00 per year

San Francisco, California

Today

Full-time

USD 172,500.00 - 260,100.00 per year

Search all similar jobs