{"id":1142258,"url":"https://alion.io/job/carrier-senior-engineer-digital-risk-management","title":"Senior Engineer– Digital Risk Management","company":{"id":13755,"name":"Carrier","domain":"carrier.com","url":"https://alion.io/company/carrier","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Workday","truth_index":{"grade":"A","score":99,"open_postings":70,"ghost_share":0,"stale_share":0.043,"repost_share":0,"time_to_fill_p50_days":22,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Industrial Engineering","role_family":"Industrial Engineering","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Hyderabad, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"NIST AI RMF","optional":false},{"name":"NIST CSF","optional":false},{"name":"ServiceNow","optional":false}],"status":"live","first_seen_at":"2026-09-23T12:47:15Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-23T20:04:58Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Position Title: Senior Engineer- Digital Risk Management (P3)\nLocation: Bangalore / Hyderabad\nReports To: Associate Manager, Digital Risk Management - Carrier Global Capability Center (GCC), Digital Team\nPosition Summary: To lead the identification, assessment, management, and governance of IT risks across Carrier’s enterprise environment. This role is critical to ensuring the resilience of IT services and the integrity of Carrier's information assets by embedding a robust IT risk management framework aligned with global standards and Carrier's strategic goals. This role acts as the strategic owner of risk governance while working closely with IT Risk Analysts who are responsible for day-to-day execution and operationalization of controls, assessments, and reporting, with close coordination and frequent interaction across internal subject-matter-expert (SME) teams and Risk owners to ensure risk management process is followed.\nKey Responsibilities:\n1. IT Risk Governance & Framework Management\nDesign, implement, and maintain the IT Risk Management Framework aligned with Carrier based Digital Risk Framework which is derived from NIST CSF and ISO 27001.\nDefine IT risk taxonomy, thresholds, and escalation protocols for consistent enterprise-wide adoption.\nServe as the primary liaison for IT risk matters across Carrier's global business units, infrastructure, and application teams.\nServe as the primary record creator for risks in ServiceNow GRC application.\nKey person contributing to the design, configuration, and rollout of the ServiceNow GRC framework, covering the Policy, Risk, Issue, Compliance and Exception Management modules end-to-end.2. Risk Identification, Assessment & Prioritization\nConduct and oversee IT risk assessments (inherent and residual) across critical applications, infrastructure, and projects.\nGuide IT Risk Analysts in executing risk analysis, evidence collection, and scoring processes.\nFacilitate scenario-based and targeted risk assessments for high-impact areas including cloud migrations, system upgrades, and M&A.\nMaintain and update risk registers, scoring models, and risk heatmaps using GRC tools - ServiceNow IRM\n3. Control Management & Monitoring\nDefine and implement key risk indicators (KRIs) and key control indicators (KCIs) for ongoing risk monitoring.\nSupervise IT Risk Analysts in evaluating control effectiveness and documenting evidence.\nDevelop action plans for control deficiencies, monitor remediation, and report control maturity metrics.\n4. Exception & Deviation Handling\nLead the end-to-end management of risk exceptions, waivers, and deviations from IT policy.\nOversee the workflows managed by analysts and ensure that exceptions are timely reviewed and approved by appropriate stakeholders.\nAutomate exception workflows and integrate them with CMDB and audit logs for traceability.\n5. Stakeholder Engagement & Risk Reporting\nPrepare and present monthly/quarterly risk dashboards to senior leadership, Risk Council, and DCC.\nConduct regular stakeholder sessions to capture risk concerns, share insights, and promote risk ownership.\nProvide risk insights to inform IT strategic decisions, budget allocations, and project prioritization.\n6. Awareness, Training & Culture Building\nDevelop and deliver IT risk training modules to application owners, support teams, and project managers.\nPromote a risk-aware culture through playbooks, campaigns, and collaborative learning sessions.\nPartner with HR and L&D to integrate IT risk content into employee training journeys.\nMentor and coach IT Risk Analysts to build operational maturity and grow internal expertise.\nQualifications:\nBachelor's Degree in Computer Science, or related field.\nMinimum 8-10 years in IT risk management, audit, or cyber governance.\nStrong knowledge of risk frameworks (NIST, ISO 27001, COBIT), internal controls, and security policies.\nHands-on experience with GRC platforms, specifically ServiceNow IRM / GRC (Risk, Issue, and Exception Management modules), RSA Archer or any other platforms.\nDemonstrated ability to coordinate and interact frequently with internal SME teams and external stakeholders to drive risk topics and strengthen the risk management portfolio.\nWorking knowledge of AI risk frameworks (NIST AI RMF, ISO/IEC 42001) and hands-on ability to leverage AI tools - including building lightweight risk-reporting apps, dashboards, or chatbots - to automate risk triage, scoring, monitoring and stakeholder queries.\nCertifications (Preferred):\nCRISC.\nKey Attributes:\nStrategic thinking with tactical execution.\nStrong interpersonal, influencing, and negotiation skills.\nAnalytical mindset with the ability to simplify complex risk narratives for business audiences.\nProven ability to lead cross-functional teams and manage multi-country risk engagements.\nStrong coordination skills, with the ability to build and maintain effective working relationships across internal SME teams and external stakeholders for effective risk management outcomes.\nWhy Join Us? At Carrier, you will be part of a world-class, diverse workforce that is driving innovation and creating solutions that matter. This role provides an exciting opportunity to shape the future of communications at Carrier Digital, offering high visibility and strategic influence within the organization.\nCarrier is An Equal Opportunity/AffirmativeAction Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.\nJob Applicant's Privacy Notice:\nClick on this link to read the Job Applicant's Privacy Notice","description_format":"text","description_chars":5714,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Industrial Machinery","HVAC & Refrigeration"],"lifecycle":[{"event":"open","at":"2026-09-23T12:47:15Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":22,"reasons":["conf:0","win:early","comp:brand"],"computed_at":"2026-09-23T20:15:42Z"},"pay":null,"html_url":"https://alion.io/job/carrier-senior-engineer-digital-risk-management","json_url":"https://alion.io/job/carrier-senior-engineer-digital-risk-management.json","meta":{"generated_at":"2026-09-23T20:15:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}