IT Analyst II - IT Governance, Risk, and Controls
Listed on 2026-09-20
-
IT/Tech
-
Finance & Banking
Job Title:
Staff IT Analyst II - IT Governance, Risk, and Controls
Location:Block 23
What you'll do:The IT Staff Analyst II - IT Governance, Risk & Controls is a Senior Analyst and serves as a first line of defense (1
LOD) risk professional responsible for supporting and executing risk programs and business unit risk activities in alignment with the Company's risk appetite and corporate strategy. This role acts as a key contributor and trusted partner to IT while engaging with second line of defense (2
LOD) functions to support the management of IT risks and controls across applicable risk types. The Senior Analyst monitors the execution of policies, standards, procedures, regulatory expectations, and control framework requirements. This position is expected to provide analytical leadership, strengthen control inventory documentation and evidence practices, and support Risk and Control Self-Assessments. Additionally, the Staff IT Analyst II will identify, develop, monitor, and maintain KRIs, KPIs, and Operational Metrics for decision making and risk oversight.
- Partner with control owners, risk owners, first line stakeholders, second line stakeholders, and other partners to track risk and control priorities and updates through completion.
- Support the timely preparation, execution, update, and refresh of risk and control information by collecting, validating, and organizing data from various sources.
- Execute assigned risk program and business unit risk activities with a sense of urgency, ensuring deliverables are completed accurately, effectively, and within required timelines.
- Engage with business units to support the management of risks and controls across applicable risk types, including monitoring adherence to risk policies, procedures, standards, and program requirements.
- Facilitate meetings with IT and other stakeholders to confirm process understanding, review process maps, validate narratives, and document process-level risk and control information.
- Collaborate with 2
LOD partners by coordinating updates, clarifying expectations, escalating concerns, and supporting the timely resolution of open items. - Assess the control environment for assigned processes to determine whether controls effectively mitigate identified risks or whether gaps, weaknesses, or remediation needs should be documented and escalated.
- Prepare clear documentation of review results, observations, risk and control updates, process changes, stakeholder feedback, and recommended actions for management review.
- Identify and recommend process improvements that strengthen risk and control documentation, execution consistency, transparency, reporting quality, and alignment with risk program expectations.
- Identify, develop, and monitor Key Risk Indicators (KRIs) to measure risk exposure and control effectiveness; analyze threshold breaches, track and report metrics and trends, and partner with stakeholders to identify, implement, and monitor corrective and remediation activities through timely resolution.
- Prepare and maintain risk reporting and dashboards for senior leadership, committees, and governance forums, providing insightful analysis of risk metrics, issues, KRIs, control effectiveness, and emerging trends to support informed decision-making and effective risk oversight.
- 5+ years of related experience in IT risk management, IT governance, internal controls, compliance, technology audit, or a similar field.
- Bachelor's degree in information technology, Information Systems, Cybersecurity, Business, Risk Management, Accounting, Finance, or a related field, or equivalent work experience.
- Intermediate experience with IT general controls, risk and control self-assessments, issue management, exception management,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).