IT Risk and Control Analyst
Job in
New York, New York County, New York, 10261, USA
Listed on 2026-08-11
Listing for:
Intellectt Inc
Full Time
position Listed on 2026-08-11
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Job Description & How to Apply Below
Role: IT Risk & Control Senior Analyst or Cybersecurity Risk Analyst
Location:
NYC, NY or Jersey City, NJ - Hybrid
Duration:
Long term contract role
Skills:
Test of design, Test of execution TOD VS TOE, TOI (Test of Implementation), RCSA, Additional Notes from Hiring Manager: 2
LoD IT Control Testing:
- First Line of Defense (1 LOT) - Operational Management Who they are: IT operations, software developers, system administrators, and business unit managers.
- Main role: Owns the risk,
- Key actions:
- Design and run daily IT systems.
- Put security patches, firewalls, and access controls in place.
- Fix IT security errors or system failures right away.
- Second Line of Defense (2 LOT)
- Oversight and Policies Who they are: Chief Information Security Officer (CISO), IT Risk Managers, and Compliance Officers.
- Main role: Monitors and challenges the first line.
- Key actions:
- Write the company's IT security and data privacy policies.
- Check if the 1st line follows the rules. Help find new IT threats and test system defenses.
- Third Line of Defense (3 LOT)
- Independent Audit Who they are: Internal Auditors.
- Main role: Independent check and objective proof.
- Key actions:
- Test the whole IT risk setup without bias.
- Report directly to top leaders or the board of directors.
- Confirm if the 1st and 2nd lines are doing their jobs correctly.
- The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment.
- ITRM Security Senior Analyst will conduct fit for purpose review and challenges of internal IT controls to ensure consistency with internal policies and standards.
- Additionally, conduct process/risk/control (PRC) reviews to evaluate and overall control program effectiveness in mitigating risk.
- The ITRM Senior Analyst's goal is to create actionable information for IT and business leadership, and to provide objective assessment of cyber security controls for auditors, regulators and external parties.
- This requires routinely performing review and challenge reviews against 1
LOD testing practices specific to T&I controls, authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information. - The ITRM Senior Analyst keeps abreast of external cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject‑matter recommendations and guidance to achieve a posture within the bank's overall risk appetite.
- This is an advanced senior professional with wide range of experience who uses professional concepts and to resolve complex issues in creative and effective ways.
- Serves as an expert in own discipline or area of specialization, works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.
- Perform fit for purpose review and challenges specific to IT (T&I) controls tested by 1
LOD Testing team against Governing Principles and applicable Policies and Standards. Reviews are specific to Test of Design (ToD) and Test of Effectiveness (ToE). - Provide guidance to 1
LOD colleagues to ensure testing practices meet internal standards. - Conduct Process/Risk and Control (PRC) reviews against IT control descriptions to ensure they meet requirements.
- Support regulatory requirements and deliverables as needed.
- Define analysis objectives, collect data from internal and external sources, and evaluate/analyze data to provide objective information on cyber risks for IT and business management with both summary and detailed reporting.
- Participate in other projects and duties as needed or requested
- Bachelor's Degree or equivalent
- Minimum of 12 years’ experience in Information/Cyber Security field
- Minimum of 6 years' experience in cyber security operations, incident response, IT risk management or investigations
- Demonstrated experience analyzing IT control testing attributes and evidence to properly evaluate and conclude control effectiveness
- Prior IT Control Audit experience is strongly preferred
- Experience in banking/financial industry specific to technology is strongly preferred
- Demonstrated knowledge of financial regulation and control frameworks applicable to cyber security or IT risk
- Demonstrated experience with Industry or subject specific analysis or assessment frameworks is highly desired (FAIR, NIST CSF, etc.)
- Demonstrated knowledge of cyber security landscape -- threats, trends, technologies
- Excellent communication and interpersonal skills. Including a strong ability to create positive and professional business relationships with internal clients.
- Strong commitment to working as a team and providing excellent customer service.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×