Manager, IT Risk Operations

<p>Wilson Sonsini is the premier legal advisor to technology, life sciences, and other growth enterprises worldwide. We represent companies at every stage of development, from entrepreneurial start-ups to multibillion-dollar global corporations, as well as the venture firms, private equity firms, and investment banks that finance and advise them. The firm has approximately 1,100 attorneys in 17 offices: 13 in the U.S., two in China, and two in Europe. Our broad spectrum of practices and entrepreneurial spirit allow exceptional opportunities for professional achievement and career growth. </p><p></p><p><b>Essential Duties and Responsibilities:</b></p><p></p><p>This high-impact position in the Governance, Risk & Compliance function sits at the center of the firm’s technology, security, and operational <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">ecosystem. Managing</span> a small team, you will work closely with senior leaders across IT, Security Engineering, General Counsel, and firm leadership to shape how risk is understood, measured, and managed. </p><p></p><p>The role can be 100% remote or hybrid-in person if located near a physical office.</p><p></p><p><b>Strengthen IT Governance & Controls</b> </p><ul><li>Lead the development of executive-level reporting on IT risk, compliance posture, and operational performance </li><li>Build and evolve KPI/KRI dashboards that provide real-time visibility into risk trends and control effectiveness </li><li>Translate complex IT and security data into meaningful insights for decision making </li><li>Ensure adherence to IT policies, standards, and leading frameworks (e.g., NIST, ISO 27001) </li><li>Own and evolve the firm’s IT risk register and Risk & Control Self-Assessment (RCSA) program </li><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Identify emerging</span> and systemic risks across IT, security, privacy, and operational processes </li></ul><p></p><p><b>Incident Governance & Investigations</b> </p><ul><li>Partner with General Counsel, Security, and IT to lead internal investigations</li></ul><p></p><p><b>Own ITSM Governance & ServiceNow Analytics</b> </p><ul><li>Oversee governance and reporting across the IT Service Management (ITSM) ecosystem </li><li>Analyze incident, change, and problem management data <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">to identify trends</span> and improvement opportunities </li><li>Drive workflow optimization and automation within <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">ServiceNow  </span></li></ul><p></p><p><b>Vendor Risk Management</b> </p><ul><li>Review and advise on vendor agreements</li><li>Enhance vendor risk processes, including risk tiering, assessments, and monitoring </li><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Identify opportunities</span> to streamline processes, enhance reporting, and improve governance</li><li>Introduce data-driven approaches to risk management and operational oversight </li><li>Perform related duties as assigned or directed by supervisor</li><li>Maintain compliance with all firm policies and procedures</li></ul><p></p><p><b>Education and/or Work Experience Requirements: </b></p><ul><li>Bachelor’s degree preferred</li><li>Seven years of experience in <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">IT risk, security compliance, technology audit,</span> or <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">IT governance preferred</span></li><li><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Experience operating in</span> complex, regulated environments (e.g., law firms, financial services, <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">consulting) preferred</span></li><li>Proven ability to lead reporting, analytics, and governance initiatives </li><li>Familiarity with ServiceNow and ITSM reporting including understanding of incident, change, and problem management lifecycles </li><li>Experience with security and collaboration platforms such as Microsoft <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">365, Purview and</span> email security tools </li><li>Working knowledge of frameworks such as the NIST Cybersecurity Framework, ISO/IEC 27001 and SOC 2 </li><li>Strong understanding of control design, risk registers, RCSA programs, and audit response </li><li>Basic understanding of privacy regulations </li><li>CISA, CISSP, <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">CRISC, CTPRM and/or</span> <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">ITIL preferred </span></li></ul>The primary location for this job posting is in Palo Alto, but other locations may be listed. The actual base pay offered will depend upon a variety of factors, including but not limited to the selected candidate’s qualifications, years of relevant experience, level of education, professional certifications and licenses, and work location. The anticipated pay range for this position is as follows:<p style="text-align:inherit"></p><h3></h3>Palo Alto, New York, San Francisco: $163,200 - $220,800 per <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">year. Austin,</span> Boston, Boulder, Century City, Los Angeles, Salt Lake City, San Diego, Seattle: $147,050 - $198,950 per year.<p style="text-align:inherit"></p><h3></h3><p style="text-align:left"><span>The compensation for this position may include a discretionary year-end merit bonus based on performance. We offer a highly competitive salary and benefits package. </span></p><p style="text-align:inherit"></p><p style="text-align:left"><span>Benefits information can be found <a href="https://www.wsgr.com/en/careers/professional-staff/employee-benefits-summary.html" target="_blank" rel="noopener noreferrer">here</a></span><span>. Equal Opportunity Employer (EOE).</span><span> </span></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...