Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
NITYO is seeking an experienced Risk Analyst – IT/Technology Risk to support technology risk governance, regulatory compliance and control framework. You will identify, assess and report IT risks across applications, infrastructure, cybersecurity, cloud, and third-party vendors.
Responsibilities include maintaining the IT Risk Register, coordinating audits, ensuring RBI/BFSI compliance, and driving remediation actions with stakeholders. Strong analytical and communication skills are essential.
We are looking for an experienced Risk Analyst – IT/Technology Risk to support the organization?s technology risk, governance, regulatory compliance and control framework. The role will be responsible for identifying, assessing, monitoring and reporting technology risks and ensuring timely remediation of control gaps in alignment with regulatory and organizational requirements.
Identify, assess and monitor IT and technology risks across applications, infrastructure, cybersecurity, cloud, third-party vendors and critical technology services.
Maintain and govern the IT Risk Register, including inherent risk, residual risk, risk ratings, KRIs and mitigation plans.
Support implementation and monitoring of the IT Risk & Control Framework.
Conduct IT risk assessments, control assessments and periodic reviews of technology processes.
Monitor and track risk exceptions, control gaps, audit observations and remediation actions to closure.
Support internal, external and regulatory IT audits and coordinate with technology and business teams for evidence and remediation.
Assist in compliance with applicable RBI / BFSI regulatory requirements, organizational policies and technology risk standards.
Review technology risks related to change management, access management, cybersecurity, BCP/DR, data protection, third-party risk and critical applications.
Support vendor/third-party technology risk assessments, including review of security controls and compliance requirements.
Prepare risk dashboards, KRI reports, management reports and governance presentations for senior management and risk committees.
Identify control deficiencies and recommend appropriate corrective actions and compensating controls.
Support the risk acceptance process by documenting risk impact, mitigating controls, residual risk and required approvals.
Follow up with stakeholders to ensure timely closure of audit and risk observations.
Participate in IT Risk/GRC committee meetings and prepare action trackers and minutes.
Ensure technology risk documentation, policies, procedures and control evidence are maintained appropriately.
4–8 years of experience in IT Risk, Technology Risk, IT GRC, Information Security Governance or related areas.
Experience in BFSI / Banking / Financial Services / Insurance is preferred.
Strong understanding of IT Risk Management and IT Controls.
Experience with Risk & Control Assessments, Risk Registers, KRIs, Risk Acceptance and Remediation Tracking.
Exposure to RBI regulatory requirements / BFSI IT governance will be an advantage.
Good understanding of:
Cybersecurity Risk
Access Management / IAM
Change Management
Vulnerability & Security Controls
Third-Party/Vendor Risk
BCP/DR
Cloud Risk
Data Protection & Privacy
Critical Application Risk
Experience handling internal/external/regulatory audits.
Good understanding of ISO 27001, NIST, COBIT or similar frameworks.
Strong analytical, documentation and stakeholder-management skills.
Good communication skills with the ability to present risk information to senior stakeholders.
CISA
CRISC
CISSP
ISO 27001 Lead Auditor / Implementer
ITIL
Risk Management certifications
IT Risk Management | IT GRC | Risk & Control Assessment | Regulatory Compliance | IT Audit | Cybersecurity Risk | Third-Party Risk | IAM | BCP/DR | Cloud Risk | KRI | Risk Register | Risk Acceptance | Audit Remediation | Stakeholder Management
Bachelor?s degree in IT, Computer Science, Engineering, Information Security, Risk Management or a related discipline. Relevant professional certifications will be an advantage.