IT Risk & Control Analyst

CloudIngest

New York (NY)

Hybrid

USD 120,000 - 190,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CloudIngest is seeking an IT Risk & Control Senior Analyst (Second Line of Defence) to join a hybrid role in the NYC/Jersey City area with some flexibility to Charlotte or Phoenix. The candidate will lead control testing, validate ToD/ToE, and provide objective risk assessments to leadership, auditors, and regulators.

The role requires 8–12+ years in information/cyber security with a strong banking/financial services background, deep knowledge of regulatory frameworks, and excellent

Qualifications

  • 8–12+ years in IT/cyber risk and controls testing in financial services.
  • Heavy focus on control testing (ToD/ToE) and risk assessments.
  • Experience with regulatory frameworks (SOX, NIST CSF) and banking industry.

Responsibilities

  • Act as second line of defence for IT risk and cyber security controls.
  • Perform heavy control testing (Test of Design and Test of Effectiveness).
  • Conduct PRC reviews and provide objective risk reporting to leadership, auditors, and regulators.
  • Support regulatory deliverables and ensure compliance with frameworks.

Skills

IT risk management
Control testing
Regulatory frameworks
SOX
NIST CSF
ToD/ToE
Stakeholder management
Communication

Job description

Role: IT Risk & Control Senior Analyst (Second Line of Defence)

Location: Hybrid – 4 days onsite in NYC/Jersey City, NJ (Charlotte or Phoenix also acceptable)

Experience: 8-12 yrs Industry: Banking/Financial Services Client is

FOCUS is - This role is all about control testing review and challenge.

The analyst will independently validate 1LOD testing (ToD/ToE), conduct PRC reviews, and provide objective risk assessments to leadership, auditors, and regulators.

Requires 8-12+ years in IT/cyber risk, strong audit/control testing experience, and financial services background.

Hybrid 4 days in NYC/Jersey City. PS - This has to be a HANDS on role , They have to know end to end Control testing. Key Responsibilities Act as second line of defence for IT risk and cyber security controls.

Perform heavy control testing (Test of Design, Test of Effectiveness).

Conduct Process/Risk/Control (PRC) reviews to evaluate control program effectiveness. Provide guidance and challenge to 1LOD testing teams to ensure practices meet standards.

Support regulatory deliverables and compliance requirements.

Define analysis objectives, collect/evaluate data, and provide objective cyber risk reporting for IT/business leadership.

Author detailed reports and gather metrics for auditors, regulators, and external parties.

Stay current on cyber security threats, trends, and technologies.

Collaborate with other teams on cyber risk initiatives and provide recommendations.

Manage site-level governance: track actions, risks, issues, dependencies, decisions, and readiness items.

Required Qualifications 10–15 years in Information/Cyber Security, with strong IT risk management background.

6+ years in cyber security operations, incident response, IT risk management, or investigations.

Prior IT Control Audit experience (heavy control testing focus). Strong banking/financial industry experience. Knowledge of financial regulation and control frameworks (FAIR, NIST CSF, SOX, etc.). Deep understanding of cyber security landscape (threats, trends, technologies). Excellent communication and interpersonal skills to build strong stakeholder relationships. Team-oriented, customer service mindset. Summary The client is seeking a seasoned IT Risk & Control professional who can operate as the second line of defence, with heavy control testing experience and a strong banking background. The role requires someone who can challenge 1LOD testing practices, ensure compliance with regulatory frameworks, and provide objective risk reporting to leadership. Hybrid onsite presence (4 days) is mandatory in NYC/Jersey City, with flexibility for Charlotte or Phoenix.

This position is part of the second line of defense in IT risk management. The focus is on reviewing and challenging IT control testing that the first line performs. You’ll be expected to run end‑to‑end control testing cycles, looking at both Test of Design (ToD) — whether a control is set up correctly on paper — and Test of Effectiveness (ToE) — whether it actually works in practice when tested with evidence.

You should also have exposure to RCSA (Risk and Control Self‑Assessment), where risks are identified, controls are assessed, and residual risks are documented

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Risk & Control Senior Analyst (2LOD) - Control testing / Green Card / US Citizen only
IT Risk & Control Senior Analyst (2LOD) - Control testing / Green Card / US Citizen only

CloudIngest • Charlotte (NC)

Hybrid
USD 130,000 - 150,000
IT Risk & Control Senior Analyst (W2 Only) (USC or GC Only)
IT Risk & Control Senior Analyst (W2 Only) (USC or GC Only)

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
IT Risk & IT control testing (Second Line of Defence – 2LOD)
IT Risk & IT control testing (Second Line of Defence – 2LOD)

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 170,000
Senior IT Risk & Control Analyst — Second Line Testing
Senior IT Risk & Control Analyst — Second Line Testing

CloudIngest • Charlotte (NC)

Hybrid
USD 130,000 - 150,000
2nd-Line IT Risk & Control Analyst – ToD/ToE Expert
2nd-Line IT Risk & Control Analyst – ToD/ToE Expert

CloudIngest • New York (NY)

Hybrid
USD 120,000 - 190,000
Senior IT Risk & Control Analyst - 2LOD, Banking Regs
Senior IT Risk & Control Analyst - 2LOD, Banking Regs

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Senior IT Risk & Controls Analyst 2LOD Cyber Risk
Senior IT Risk & Controls Analyst 2LOD Cyber Risk

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 170,000
CyberSecurity Specialist - GRC
CyberSecurity Specialist - GRC

TechDigital Group • Phoenix (AZ)

On-site
USD 120,000 - 150,000
CyberSecurity Specialist - GRC
CyberSecurity Specialist - GRC

ReqRoute,Inc • Phoenix (AZ)

Hybrid
USD 90,000 - 130,000
Controls Testing Analyst
Controls Testing Analyst

Customers Bank • Malvern

On-site
USD 60,000 - 80,000