Job opening
IT Risk & Control Senior Analyst - W2 Position
Filed under Software Development
Full job description
Job Title: IT Risk & Control Senior Analyst
Location: Hybrid (4 Days/Week) – NYC / Jersey City, NJ
Work Authorization: US Citizen or Green Card Only
Job Description
We are seeking an experienced IT Risk & Control Senior Analyst to support IT Risk Management initiatives within a banking/financial services environment. The ideal candidate will have extensive experience in IT Risk, Cyber Security, IT Controls, and Control Testing, with a strong understanding of regulatory requirements and industry frameworks such as NIST CSF and FAIR.
Key Responsibilities
- Perform fit-for-purpose reviews and challenge assessments of IT (Technology & Infrastructure) controls tested by the 1st Line of Defense (1LOD) team.
- Review Test of Design (ToD) and Test of Effectiveness (ToE) results to ensure compliance with internal policies, standards, and governing principles.
- Provide guidance to 1LOD teams on IT control testing methodologies and best practices.
- Conduct Process, Risk, and Control (PRC) reviews to evaluate the effectiveness of IT control descriptions and overall control environment.
- Support regulatory examinations, audits, and compliance-related deliverables.
- Analyze IT and cyber risks by collecting and evaluating data from internal and external sources.
- Prepare detailed reports and metrics to communicate cyber risk posture to business and technology stakeholders.
- Monitor evolving cybersecurity threats, technologies, and regulatory requirements to provide risk mitigation recommendations.
- Participate in IT risk and cybersecurity initiatives, assessments, and special projects.
Required Qualifications
- Bachelor's Degree or equivalent experience.
- 12+ years of experience in Information Security, Cyber Security, or IT Risk.
- 6+ years of experience in Cyber Security Operations, IT Risk Management, Incident Response, or IT Investigations.
- Strong experience evaluating IT control testing evidence and determining control effectiveness.
- Hands-on experience with Test of Design (ToD) and Test of Effectiveness (ToE).
- Excellent analytical, documentation, and stakeholder communication skills.
Preferred Qualifications
- Prior IT Control Audit experience.
- Experience in the Banking or Financial Services industry.
- Strong understanding of financial regulations and IT control frameworks.
- Experience with cybersecurity and risk frameworks such as NIST CSF, FAIR, or similar.
- Knowledge of cybersecurity threats, vulnerabilities, and risk management practices.
- Ability to work collaboratively with cross-functional teams and senior leadership.
Required Skills
- IT Risk Management
- IT Controls & Control Testing
- Cyber Security
- Test of Design (ToD)
- Test of Effectiveness (ToE)
- Process, Risk & Control (PRC) Reviews
- IT Audit
- Regulatory Compliance
- NIST CSF / FAIR Frameworks
- Banking / Financial Services
- Risk Assessment
- Cyber Risk Analysis
- Incident Response