Get more replies from employers
Send a job-specific resume in minutes.
CloudIngest is seeking an IT Risk & Control Senior Analyst (Second Line of Defence) to join a hybrid role in the NYC/Jersey City area with some flexibility to Charlotte or Phoenix. The candidate will lead control testing, validate ToD/ToE, and provide objective risk assessments to leadership, auditors, and regulators.
The role requires 8–12+ years in information/cyber security with a strong banking/financial services background, deep knowledge of regulatory frameworks, and excellent
Role: IT Risk & Control Senior Analyst (Second Line of Defence)
Location: Hybrid – 4 days onsite in NYC/Jersey City, NJ (Charlotte or Phoenix also acceptable)
Experience: 8-12 yrs Industry: Banking/Financial Services Client is
FOCUS is - This role is all about control testing review and challenge.
The analyst will independently validate 1LOD testing (ToD/ToE), conduct PRC reviews, and provide objective risk assessments to leadership, auditors, and regulators.
Requires 8-12+ years in IT/cyber risk, strong audit/control testing experience, and financial services background.
Hybrid 4 days in NYC/Jersey City. PS - This has to be a HANDS on role , They have to know end to end Control testing. Key Responsibilities Act as second line of defence for IT risk and cyber security controls.
Perform heavy control testing (Test of Design, Test of Effectiveness).
Conduct Process/Risk/Control (PRC) reviews to evaluate control program effectiveness. Provide guidance and challenge to 1LOD testing teams to ensure practices meet standards.
Support regulatory deliverables and compliance requirements.
Define analysis objectives, collect/evaluate data, and provide objective cyber risk reporting for IT/business leadership.
Author detailed reports and gather metrics for auditors, regulators, and external parties.
Stay current on cyber security threats, trends, and technologies.
Collaborate with other teams on cyber risk initiatives and provide recommendations.
Manage site-level governance: track actions, risks, issues, dependencies, decisions, and readiness items.
Required Qualifications 10–15 years in Information/Cyber Security, with strong IT risk management background.
6+ years in cyber security operations, incident response, IT risk management, or investigations.
Prior IT Control Audit experience (heavy control testing focus). Strong banking/financial industry experience. Knowledge of financial regulation and control frameworks (FAIR, NIST CSF, SOX, etc.). Deep understanding of cyber security landscape (threats, trends, technologies). Excellent communication and interpersonal skills to build strong stakeholder relationships. Team-oriented, customer service mindset. Summary The client is seeking a seasoned IT Risk & Control professional who can operate as the second line of defence, with heavy control testing experience and a strong banking background. The role requires someone who can challenge 1LOD testing practices, ensure compliance with regulatory frameworks, and provide objective risk reporting to leadership. Hybrid onsite presence (4 days) is mandatory in NYC/Jersey City, with flexibility for Charlotte or Phoenix.
This position is part of the second line of defense in IT risk management. The focus is on reviewing and challenging IT control testing that the first line performs. You’ll be expected to run end‑to‑end control testing cycles, looking at both Test of Design (ToD) — whether a control is set up correctly on paper — and Test of Effectiveness (ToE) — whether it actually works in practice when tested with evidence.
You should also have exposure to RCSA (Risk and Control Self‑Assessment), where risks are identified, controls are assessed, and residual risks are documented