IT Risk & Control Senior Analyst
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Business Analyst
IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY?
The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. The ITRM Security Senior Analyst will conduct fit for purpose review and challenges of internal IT controls to ensure consistency with internal policies and standards. Additionally, conduct process/risk/control (PRC) reviews to evaluate overall control program effectiveness in mitigating risk.
The ITRM Senior Analyst's goal is to create actionable information for IT and business leadership, and to provide objective assessment of cyber security controls for auditors, regulators and external parties. This requires routinely performing review and challenge reviews against 1
LOD testing practices specific to T&I controls, authoring detailed reports and gathering metrics to ensure stakeholders receive accurate and complete information. The ITRM Senior Analyst keeps abreast of external cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject-matter recommendations and guidance to achieve a posture within the bank's overall risk appetite.
This is an advanced senior professional with wide range of experience who uses professional concepts and to resolve complex issues in creative and effective ways. Serves as an expert in own discipline or area of specialization, works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.
- Perform fit for purpose review and challenges specific to IT (T&I) controls tested by 1
LOD Testing team against Governing Principles and applicable Policies and Standards. Reviews are specific to Test of Design (ToD) and Test of Effectiveness (ToE). - Provide guidance to 1
LOD colleagues to ensure testing practices meet internal standards. - Conduct Process/Risk and Control (PRC) reviews against IT control descriptions to ensure they meet requirements.
- Support regulatory requirements and deliverables as needed.
- Define analysis objectives, collect data from internal and external sources, and evaluate/analyze data to provide objective information on cyber risks for IT and business management with both summary and detailed reporting.
- Participate in other projects and duties as needed or requested.
Required Qualifications *
- Bachelor's Degree or equivalent
- Minimum of 12 years’ experience in Information/Cyber Security field
- Minimum of 6 years' experience in cyber security operations, incident response, IT risk management or investigations
- Demonstrated experience analyzing IT control testing attributes and evidence to properly evaluate and conclude control effectiveness
- Prior IT Control Audit experience is strongly preferred
- Experience in banking/financial industry specific to technology is strongly preferred
- Demonstrated knowledge of financial regulation and control frameworks applicable to cyber security or IT risk
- Demonstrated experience with Industry or subject specific analysis or assessment frameworks is highly desired (FAIR, NIST CSF, etc.)
- Demonstrated knowledge of cyber security landscape -- threats, trends, technologies
- Excellent communication and interpersonal skills. Including a strong ability to create positive and professional business relationships with internal clients.
- Strong commitment to working as a team and providing excellent customer service.
Starting base salary: $101,231 - $172,355 per year. Exact compensation may vary based on skills, experience, and location. This job is eligible for bonus and/or commissions.
Benefits and Perks- Comprehensive healthcare coverage, including Medical, Dental and Vision plans, available the first of the month following start date
- Generous 401(k) company matching contribution
- Career Development through Tuition Reimbursement and other internal upskilling and training resources
- Valued Time Away benefits including vacation, sick and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).