Analyst II, Tech Governance & Assurance
Listed on 2026-08-14
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security & Data Protection
Where Ambition Meets Innovation Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you’ll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.
Job Overview: We are looking for an experienced IT Risk & Controls professional to join our first line of defense. In this role you will own the day-to-day readiness, testing, and audit facilitation for our IT compliance programs — including SOX, SOC 1, SOC 2, CCPA/CPRA cybersecurity audits, and NYDFS (23 NYCRR 500) attestation. You will partner closely with IT, Engineering, Security, Internal Audit, and external auditors to keep our control environment audit-ready year-round, while driving automation that reduces manual testing effort.
Please note: This position does not offer work authorization sponsorship now or in the future. Applicants must have valid U.S. work authorization that does not require employer sponsorship.
Responsibilities:- Audit Facilitation:
Serve as the primary coordinator for SOC 1, SOC 2, and SOX audits — managing PBC (Provided-by-Client) request lists, evidence collection, walkthrough scheduling, and auditor Q&A. - Audits liaison:
Act as the liaison between control owners and external auditors/service auditors, ensuring timely, complete, and accurate responses. - Track audit findings, exceptions, and management responses through to remediation and closure.
- First-Line Control Testing (ITGC):
Perform first-line risk assessments and control self-testing across IT General Controls domains, including logical/privileged access management, change management, SDLC, computer operations (backup, job scheduling, incident management), and data management. - Identify control gaps and design deficiencies proactively, and work with owners on remediation plans before formal audit periods.
- Maintain control narratives, risk-and-control matrices (RCMs), and evidence repositories.
- Regulatory & Compliance Programs:
Support CCPA/CPRA cybersecurity audit requirements, mapping controls to applicable privacy and security obligations. - Prepare and support the annual NYDFS (23 NYCRR 500) certification/attestation process, including evidence gathering and compliance validation.
- Keep control frameworks aligned to evolving regulatory and industry requirements.
- Automation & Continuous Improvement:
Design and implement control testing automation and continuous controls monitoring (CCM) to reduce manual sampling and evidence collection. - Build automated evidence pulls, testing scripts, and dashboards using GRC platforms and/or scripting/data tools.
- Recommend process and tooling improvements that increase testing coverage and efficiency.
We’re looking for strong collaborators who deliver exceptional client experiences and thrive in fast-paced, team-oriented environments. Our ideal candidates pursue greatness, act with integrity, and are driven to help our clients succeed. We value those who embrace creativity, continuous improvement, and contribute to a culture where we win together and create and share joy in our work.
Requirements:- 4+ years of experience in IT audit with hands-on exposure to SOX IT General Control and SOC 1 / SOC 2 engagements.
- 2+ years of IT General Controls and control frameworks (COSO, COBIT, SOC Trust Services Criteria).
- 2+ years of experience facilitating audits and managing auditor relationships (external, service auditor, or internal audit).
- Demonstrated experience with control testing automation or continuous controls monitoring.
- Excellent documentation, organization, and stakeholder-communication skills.
- Data Analytics or automated control testing experience
- Familiarity with data privacy and cybersecurity regulations such as CCPA/CPRA and NYDFS 23 NYCRR 500.
- Relevant certifications: CISA, CIA, CISSP, CRISC, or CPA.
- Hands-on experience with GRC / audit-automation platforms (e.g., Service Now GRC, Archer).
- Scripting/data skills for automation (SQL, Python, Alteryx, or Power BI).
- Experience in internal audit or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).