×
Register Here to Apply for Jobs or Post Jobs. X

IT Risk and Control Analyst

Job in New York, New York County, New York, 10261, USA
Listing for: Intellectt Inc
Full Time position
Listed on 2026-08-11
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 130000 - 170000 USD Yearly USD 130000.00 170000.00 YEAR
Job Description & How to Apply Below
Location: New York

Role: IT Risk & Control Senior Analyst or Cybersecurity Risk Analyst

Location:

NYC, NY or Jersey City, NJ - Hybrid

Duration:
Long term contract role

Must Have

Skills:

Test of design, Test of execution TOD VS TOE, TOI (Test of Implementation), RCSA, Additional Notes from Hiring Manager: 2

LoD IT Control Testing:
  • First Line of Defense (1 LOT) - Operational Management Who they are: IT operations, software developers, system administrators, and business unit managers.
    • Main role: Owns the risk,
    • Key actions:
      • Design and run daily IT systems.
      • Put security patches, firewalls, and access controls in place.
      • Fix IT security errors or system failures right away.
  • Second Line of Defense (2 LOT)
    • Oversight and Policies Who they are: Chief Information Security Officer (CISO), IT Risk Managers, and Compliance Officers.
    • Main role: Monitors and challenges the first line.
    • Key actions:
      • Write the company's IT security and data privacy policies.
      • Check if the 1st line follows the rules. Help find new IT threats and test system defenses.
  • Third Line of Defense (3 LOT)
    • Independent Audit Who they are: Internal Auditors.
    • Main role: Independent check and objective proof.
    • Key actions:
      • Test the whole IT risk setup without bias.
      • Report directly to top leaders or the board of directors.
      • Confirm if the 1st and 2nd lines are doing their jobs correctly.
Position Overview:
  • The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment.
  • ITRM Security Senior Analyst will conduct fit for purpose review and challenges of internal IT controls to ensure consistency with internal policies and standards.
  • Additionally, conduct process/risk/control (PRC) reviews to evaluate and overall control program effectiveness in mitigating risk.
  • The ITRM Senior Analyst's goal is to create actionable information for IT and business leadership, and to provide objective assessment of cyber security controls for auditors, regulators and external parties.
  • This requires routinely performing review and challenge reviews against 1

    LOD testing practices specific to T&I controls, authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information.
  • The ITRM Senior Analyst keeps abreast of external cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject‑matter recommendations and guidance to achieve a posture within the bank's overall risk appetite.
  • This is an advanced senior professional with wide range of experience who uses professional concepts and to resolve complex issues in creative and effective ways.
  • Serves as an expert in own discipline or area of specialization, works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.
What Will You Do:
  • Perform fit for purpose review and challenges specific to IT (T&I) controls tested by 1

    LOD Testing team against Governing Principles and applicable Policies and Standards. Reviews are specific to Test of Design (ToD) and Test of Effectiveness (ToE).
  • Provide guidance to 1

    LOD colleagues to ensure testing practices meet internal standards.
  • Conduct Process/Risk and Control (PRC) reviews against IT control descriptions to ensure they meet requirements.
  • Support regulatory requirements and deliverables as needed.
  • Define analysis objectives, collect data from internal and external sources, and evaluate/analyze data to provide objective information on cyber risks for IT and business management with both summary and detailed reporting.
  • Participate in other projects and duties as needed or requested
Required Qualifications:
  • Bachelor's Degree or equivalent
  • Minimum of 12 years’ experience in Information/Cyber Security field
  • Minimum of 6 years' experience in cyber security operations, incident response, IT risk management or investigations
Additional Qualifications:
  • Demonstrated experience analyzing IT control testing attributes and evidence to properly evaluate and conclude control effectiveness
  • Prior IT Control Audit experience is strongly preferred
  • Experience in banking/financial industry specific to technology is strongly preferred
  • Demonstrated knowledge of financial regulation and control frameworks applicable to cyber security or IT risk
  • Demonstrated experience with Industry or subject specific analysis or assessment frameworks is highly desired (FAIR, NIST CSF, etc.)
  • Demonstrated knowledge of cyber security landscape -- threats, trends, technologies
  • Excellent communication and interpersonal skills. Including a strong ability to create positive and professional business relationships with internal clients.
  • Strong commitment to working as a team and providing excellent customer service.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary