
Insurance and financial services
Director Application & Data Technology Risk at Hartford
About the role
- Director Information Security
- IS06AE
We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
The Director, Application & Data Technology Risk provides senior leadership for identifying, assessing, and managing technology risks across the enterprise application landscape. This role focuses on application‑driven risks throughout the software development lifecycle (SDLC), including design, development, deployment, and ongoing operations, while maintaining strong awareness of data risk, sensitive data exposure, and risks associated with the use of artificial intelligence (AI), automation, and emerging technologies.
The Director serves as a trusted risk advisor to CIOs and senior technology leaders, partnering to enable modern application delivery while ensuring risks are understood, clearly communicated, and managed in alignment with enterprise risk appetite, regulatory expectations, and business priorities.
This role will have a Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Hartford, CT or Charlotte, NC) 3 days a week. Candidates must be eligible to work in the US without company sponsorship
Key Responsibilities
Application & Technology Risk Leadership
-
Lead the identification and management of application‑level technology risks, including secure design, SDLC controls, configuration weaknesses, dependency risks, and operational resilience.
-
Provide risk oversight across the end‑to‑end application lifecycle, including requirements, architecture, development, testing, release, and production support.
-
Assess risks introduced through modern engineering practices, including agile delivery, DevOps, CI/CD pipelines, APIs, cloud‑native services, and third‑party integrations.
-
Partner with application, platform, and security teams to promote adherence to security, infrastructure, and engineering control expectations.
Data Risk & AI Exposure
-
Evaluate data risk and sensitive data exposure within applications, including unauthorized access, data leakage, improper transmission, retention weaknesses, and aggregation risk.
-
Provide risk guidance on AI, GenAI, and automation use cases, with emphasis on data sourcing, access governance, explainability, monitoring, and emerging regulatory or ethical risks related to technology.
-
Maintain awareness of evolving risks associated with AI adoption and emerging technologies, ensuring they are incorporated into application risk assessments and governance.
Infrastructure & Cloud Dependencies
-
Maintain strong understanding of infrastructure and cloud dependencies (e.g., identity and access management, logging and monitoring, network security, encryption, resiliency) that directly influence application risk.
-
Partner with infrastructure, cloud, and cybersecurity teams to assess shared‑responsibility risk impacts on applications.
Executive Partnership & Risk Storytelling
-
Serve as a trusted risk partner to CIOs and senior technology leaders, supporting informed decision‑making while enabling delivery.
-
Translate complex technical risks into clear, business‑relevant risk narratives that articulate impact, likelihood, trends, and tradeoffs.
-
Present concise risk perspectives to senior leadership, technology governance forums, and risk committees, focusing on decision‑oriented insights rather than issue listings.
-
Influence prioritization decisions by balancing business value, delivery timelines, and risk exposure.
Risk Reporting & Governance
-
Own and deliver application and data technology risk reporting for senior leadership, highlighting trends, concentration risk, and systemic control gaps.
-
Define, monitor, and mature risk metrics, KRIs, and leading indicators related to application security, data exposure, DevOps maturity, and AI.
-
Identify patterns across findings and assessments to surface root causes and enterprise‑level risk themes.
-
Support audit, regulatory, and internal governance activities by representing application, data, and AI risk topics with credibility and consistency.
People Leadership
-
Lead, coach, and develop a team of technology risk professionals focused on application and emerging technology risk.
-
Promote a culture of partnership, transparency, and accountability across technology and risk teams.
Required Experience & Qualifications
-
10+ years of experience in technology risk management, application security, IT audit, engineering, or related domains.
-
Strong working knowledge of application architectures, SDLC, DevOps practices, and CI/CD pipelines.
-
Demonstrated experience assessing data risks and data exposure within application environments.
-
Practical understanding of AI and automation risks, including model governance, data usage, and control considerations.
-
Solid familiarity with cloud and infrastructure control domains (IAM, logging, encryption, network security, resiliency).
-
Proven ability to communicate effectively with senior leaders and translate technical issues into executive‑level insights.
-
Experience working with industry frameworks (e.g., NIST, CIS Controls, COBIT, secure SDLC standards).
Preferred Qualifications
-
Prior hands‑on experience in software engineering, application architecture, platform operations, or DevOps.
-
Experience managing risk in high-growth, technology-driven organizations with evolving governance expectations
-
Relevant certifications such as CISSP, CISM, CRISC, CISA, or cloud security certifications.
Compensation
The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford’s total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:
$153,600 - $230,400
Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age
About Us | Our Culture | What It’s Like to Work Here | Perks & Benefits
Required skills
Technology risk
Application security
SDLC governance
Risk assessment
Executive communication
Data risk
AI risk
Total Views
0
Total Apply Clicks
0
Total Mock Apply
0
Total Bookmarks
0
More open roles at Hartford

Counsel, Commercial Transactions – Technology & AI Contracting
Hartford · Hartford, CT

Sr Applied AI Scientist, Knowledge Graph
Hartford · Hartford; Columbus; Charlotte; Chicago

Life Sciences Underwriter - Boston
Hartford · Boston, MA

Director of Underwriting, Employee Benefits National Accounts
Hartford · Hartford; Lake Mary; Alpharetta

Managing Attorney, Maryland
Hartford · Hunt Valley, MD
Similar jobs

Staff Tech, Security, T4
Collins Aerospace (RTX) · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site)

Principal Systems Security Engineer (Cyber) - P4 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Senior Principal Systems Security Engineer (Cyber) - P5 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Principal Systems Security Engineer (Cyber) - P4 (Onsite)
Collins Aerospace (RTX) · US-AL-HUNTSVILLE-401 ~ 401 Jan Davis Dr NW ~ JAN DAVIS 401

Network/Security Analyst- Onsite
Collins Aerospace (RTX) · US-MT-GREAT FALLS-6932-CUST ~ 6932 Goddard Dr ~ GODDARD (External Site)
About Hartford

Hartford
BootstrappedThe Hartford Insurance Group, Inc., known as The Hartford, is a U.S.-based insurance company. The Hartford is a Fortune 500 company headquartered in its namesake city of Hartford, Connecticut. It was ranked 162nd in Fortune 500 in 2024.
51-200
Employees
Paris
Headquarters
Reviews
10 reviews
3.7
10 reviews
Work-life balance
4.2
Compensation
2.8
Culture
4.3
Career
2.5
Management
3.2
68%
Recommend to a friend
Pros
Good work-life balance and flexible hours
Strong team culture and supportive colleagues
Excellent health benefits and vacation time
Cons
Low pay and uncompetitive salary
Limited career advancement and growth opportunities
Poor communication from upper management
Salary Ranges
62 data points
Junior/L3
Mid/L4
Senior/L5
Director
Junior/L3 · Business Intelligence Developer
1 reports
$95,082
total per year
Base
$82,680
Stock
-
Bonus
-
$95,082
$95,082
Interview experience
3 interviews
Difficulty
3.3
/ 5
Duration
14-28 weeks
Experience
Positive 0%
Neutral 67%
Negative 33%
Interview process
1
Phone Interview
2
Video Interview
3
Analyst Interview
4
Trader Interview
5
Vice President Interview
Latest updates
Camp safety, state tourism, Hartford Whalers Day: CT politics news - CT Mirror
CT Mirror
News
·
2w ago
Hartford fights to cap EPL coverage at $5,000 in disability claim - Insurance Business
Insurance Business
News
·
2w ago
Utica Woman Charged With Leandra's Law After New Hartford Stop - WKTV
WKTV
News
·
2w ago
Hawks Baseball Drop Annual Dunkin' Park Game to Western Connecticut State - University of Hartford Athletics
University of Hartford Athletics
News
·
2w ago