IT Risk and Control Analyst
Listed on 2026-06-06
-
IT/Tech
IT Consultant, Cybersecurity, IT Business Analyst, Information Security
Job Overview
This role will help to manage and reduce the organization’s information security risks through continuous management & reporting relating to the NIST Framework. Additionally, this role will act as a supporting resource for the timely completion of Internal & External IT audit evidence requests, questions, and action items. The position is part of the IT Control & Service Management team (ITC&SM), which also liaises with global counterparts.
This position is based in our Chicago office and requires a min of 3 days per week onsite in office.
Job Responsibilities- Continuously manage, monitor, & report on the risk control framework detailed in the Information Security Governance Plan, specifically NIST & COBIT control frameworks
- Act as a supporting resource for both internal & external audits (audit management), gathering & presenting detailed operational evidence (control monitoring), while driving recommended audit action items through execution and closure (issue management)
- Liaise with the Information Security CoE (Center of Excellence), and 2nd Line of Defense on key issues and projects
- Execute various risk assessments and analyze the data, present the results and conclusions to management. Research deviations and advise about risk mitigating actions. Organize and controls follow‑up of assessments
- Responsible for management reporting for any needed improvements and advise on the development and implementation of changes in standards and procedures
- Reviews and revises Information Security procedures and makes recommendations for their implementation
- Provide First Line of Defense IT Risk guidance within the IT Control & Service Management team across all aspects of the IT landscape; inclusive of Client and Third‑Party questionnaires
- Collaborate with IT teams and individuals across the globe on various initiatives, projects and tasks
- 5+ years of IT Risk Management experience, working with both internal and external audit
- Bachelor’s degree or equivalent qualification in related field
- Knowledge and experience with NIST frameworks
- Knowledge and experience with audit life cycles
- Familiarity of Information Security best practices, particularly in the financial services industry
- Knowledge of information security management and of IT systems, processes and regulations
- Excellent oral and written communication skills
- Ability to effectively communicate with all levels of an organization, including senior stakeholders
- Strong attention to detail & documentation required
- Strong knowledge of Microsoft office tools
- CISM, CISA, CISSP, CRISC or CGEIT certifications
- Experience working in a regulated and/or financial and/or IT industry preferred – move to preferred
- Knowledge and experience with COBI and/or ITIL frameworks
- Familiarity with Atlassian Products (Jira, Confluence) and Service Now
Below is the expected base salary for this position. Offers will ultimately be determined based on experience, education, skill set, and performance in the interview process. This position will also be eligible for a discretionary bonus.
Base Salary Range: $105,000—$130,000 USD
Perks and BenefitsAs a global leader in financial services, we rely on the strengths of our employees to deliver their best work for our clients. We invest back in our employees by offering a host of benefits and perks.
- Competitive health benefit offerings, including choice of three medical plans through BCBS-IL, dental, vision and flexible spending accounts
- Complimentary annual membership to One Medical as well as an EAP
- Robust 401(k) Plan with a generous match and vesting schedule
- Use it or lose it pre‑tax commuter benefits, corporate Divvy memberships and employer paid benefits such as term life and AD&DD and disability insurance
- Generous paid time off, sick days, a robust holiday schedule and parental leave plans.
- Monthly wellness subsidy
- Open communication including regular Town Hall meetings with the Management Team
- Forward‑thinking, culture‑based organization with collaborative teams that promote diversity, equity and inclusion
- Free coffee & tea and “bagel Wednesday”
- Weekly lunch credit
- Employee‑led Social and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).