Risk and Internal Control Analyst support the planning, execution, and reporting of IT, operational, compliance and security audit and assurance activities. The role evaluates the effectiveness of IT and operational controls, security processes, and risk management practices, identifies potential gaps and risks, and works with stakeholders to develop practical remediation actions.
The role will work closely with IT, Information Security, Risk, Compliance, and other business stakeholders to assess adherence to internal policies, control requirements, and applicable regulatory or industry standards.
Key Responsibilities:
Controls Evaluation and Assurance Activities
- Support the planning and execution of IT, operations, security, and technology-related audits and assurance reviews.
- Assess the design and operating effectiveness of controls (i.e., IT, Financial, Security, Compliance, etc.).
- Perform testing of controls related to areas such as access management, change management, IT operations, backup and recovery, incident management, vulnerability management, and data protection.
- Review IT processes, policies, procedures, system configurations, and supporting documentation to identify control weaknesses and potential risks.
- Document testing results, observations, and supporting evidence in accordance with established internal control methodology.
- Assist in identifying control deficiencies, root causes, risk implications, and opportunities for improvement.
- Support the planning and execution of audits to critical third parties on security, operational resilience, data privacy and AI compliance topics.
- Prepare clear and concise findings and recommendations for management.
- Support the tracking and validation of remediation activities and management action plans, ensuring timely and effective closure.
Risk Assessment and Monitoring
- Perform risk assessments for new and existing systems, applications, vendors and technology processes.
- Support the development and maintenance of the risk register, ensuring risks are well-described, assessed and updated.
- Monitor key risk indicators (KRIs) and provide insights on emerging risks or trends.
- Prepare dashboards and reports highlighting risk insights for senior management.
Governance, Policies and Compliance
- Assist in drafting, updating and reviewing IT policies, standards and procedures to align with regulatory, industry best practices and internal group policies.
- Support compliance with applicable regulatory requirements and internal governance standards.
- Contribute to periodic governance reporting and technology risk presentations.
- Contribute to improving IT and security control frameworks, internal control methodologies, and assurance processes.
- Identify opportunities to enhance the efficiency and effectiveness of control testing and monitoring.
- Stay informed about emerging cybersecurity threats, technology risks, regulatory developments, and industry practices relevant to IT audit and security.
QUALIFICATIONS:
Education and Experience
- Bachelor’s degree in IT, Accountancy, Risk Management, Cybersecurity or related discipline.
- 2–5 years of experience in IT risk, IT audit, information security or similar analytical roles.
- Hands-on experience with IT control testing, risk assessments, or security evaluations.
- Good understanding of ITGC, security principles, and key areas like access, change, and vulnerability management.
- Knowledge of frameworks such as ISO 27001, COBIT, or NIST; relevant certifications (e.g., CISA, CISSP) are a plus.
Skills and Competencies
- Strong analytical, critical-thinking, and problem-solving abilities, with expertise in identifying control weaknesses and assessing their impact.
- Excellent attention to detail, with a solid understanding of technology, cybersecurity risks, and audit evidence.
- Effective communication skills—both written and verbal—and the ability to challenge processes constructively.
- Strong organizational and project management capabilities, capable of handling multiple activities and deadlines independently.
- High integrity, objectivity, and a proactive mindset focused on continuous improvement and stakeholder collaboration