IT Risk & Control Senior Analyst (W2 Only) (USC or GC Only
Listed on 2026-08-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Consultant
Job Description – IT Risk & Control Senior Analyst (Second Line of Defence) Role: IT Risk & Control Senior Analyst (Second Line of Defence)
Location:
Hybrid – 4 Days Onsite (NYC/Jersey City, NJ) (Charlotte, NC or Phoenix, AZ also considered) Duration:
Long-Term Contract Rate: $60/hr W2
Experience:
8–12+ Years
We are seeking a hands‑on IT Risk & Control Senior Analyst with extensive experience in Second Line of Defence (2
LOD) functions,
end‑to‑end IT control testing
, and banking regulatory compliance
. The ideal candidate will independently validate First Line of Defence (1
LOD) testing, perform Test of Design (ToD) and Test of Effectiveness (ToE) assessments, conduct Process Risk Control (PRC) reviews, and provide objective risk assessments to leadership, auditors, and regulators.
This role requires deep expertise in IT Risk Management, Cyber Security Controls, Control Testing, Audit, and Financial Services Regulatory Frameworks
.
- Serve as the Second Line of Defence (2
LOD) for IT Risk and Cyber Security Controls. - Perform end-to-end IT Control Testing
, including Test of Design (ToD) and Test of Effectiveness (ToE). - Independently review and challenge First Line of Defence (1
LOD) testing results. - Conduct Process Risk Control (PRC) assessments and evaluate overall control effectiveness.
- Assess compliance with internal policies, regulatory requirements, and industry standards.
- Prepare detailed risk assessment reports for executive leadership, auditors, and regulators.
- Support regulatory examinations, audits, and compliance initiatives.
- Analyze IT and Cyber risks, recommend remediation plans, and monitor corrective actions.
- Track governance activities including risks, issues, dependencies, action items, and readiness plans.
- Stay current with emerging cyber threats, technologies, and industry best practices.
- Partner with cross-functional technology and business teams to strengthen enterprise risk posture.
- 8–12+ years of experience in IT Risk Management, Information Security, or Cyber Security
. - Strong experience working in a Second Line of Defence (2
LOD) environment. - Extensive hands‑on experience with IT Control Testing (ToD & ToE).
- Prior experience performing IT Control Audits and regulatory assessments.
- Strong knowledge of Process Risk Control (PRC) reviews.
- Experience challenging and validating 1
LOD control testing activities. - Strong Banking or Financial Services industry background.
- Experience supporting auditors, regulators, and compliance teams.
- Excellent analytical, documentation, communication, and stakeholder management skills.
- Knowledge of NIST CSF, SOX, FAIR, COBIT, ISO 27001, FFIEC
, or similar control frameworks. - Experience in Cyber Security Operations, Incident Response, or IT Investigations.
- Understanding of enterprise cyber threats, governance, and risk management practices.
- Professional certifications such as CISA, CRISC, CISSP, CISM
, or similar are highly preferred.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).