IT Risk & Control Analyst (GC and USC Only W2)

CloudIngest

Charlotte (NC)

Hybrid

USD 120,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CloudIngest is seeking an experienced IT Risk & Control Senior Analyst to join the Second Line of Defence (2LOD) Cybersecurity Risk function within a leading banking environment. The role emphasizes IT risk management, cybersecurity controls, control testing, regulatory compliance, and governance frameworks.

You will perform TOD, TOE, PRC assessments, control validations, risk reporting, and governance activities while partnering with cybersecurity, technology, audit, compliance, and business

Qualifications

  • 9+ years in Information Security, Cybersecurity, IT Risk Management or Technology Risk
  • 6+ years in Cybersecurity Operations, Incident Response, Control Testing, IT Risk or Security Investigations
  • Strong experience with IT control audits, control validation, and testing methodologies
  • Proven experience supporting Banking/Financial Services organizations
  • Familiarity with NIST CSF, SOX Controls, IT Governance & Risk Management Frameworks
  • Experience with PRC Reviews, Control Effectiveness Testing, Audit Remediation, Regulatory Compliance

Responsibilities

  • Serve as a Second Line of Defence (2LOD) cybersecurity risk professional providing independent oversight of IT controls and risk management activities.
  • Perform TOD and TOE reviews for cybersecurity and technology controls.
  • Conduct PRC assessments and evaluate control maturity and effectiveness.
  • Challenge and provide guidance to First Line of Defence (1LOD) control testing teams.
  • Support internal audits, regulatory examinations, compliance reviews, and remediation activities.
  • Analyze cybersecurity risks, vulnerabilities, threats, and control gaps to provide actionable insights.
  • Develop risk reporting, dashboards, metrics, and governance documentation for leadership and regulators.
  • Manage cybersecurity governance activities including risks, issues, actions, dependencies, decisions, and readiness tracking.
  • Collaborate with Cybersecurity, Technology Risk, Compliance, Audit, and Business teams on risk initiatives.
  • Stay updated on emerging cyber threats, regulatory expectations, and security trends.

Skills

IT risk mgmt
Cybersecurity controls
Control testing
Regulatory compliance
Governance frameworks
Communication

Tools

GRC Tools

Job description

NOTE: Quick Moving Position and Interviews having this week

Job Title: IT Risk & IT control testing (Second Line of Defence – 2LOD)

Location: Hybrid – 4 Days Onsite

Preferred Locations: NYC / Jersey City, NJ | Charlotte, NC | Phoenix, AZ

Job Overview

We are seeking an experienced IT Risk & Control Senior Analyst to join the Second Line of Defence (2LOD) Cybersecurity Risk function within a leading banking environment. The ideal candidate will have strong expertise in IT risk management, cybersecurity controls, control testing, regulatory compliance, and governance frameworks.

This role will be responsible for performing Test of Design (TOD), Test of Effectiveness (TOE), Process/Risk/Control (PRC) assessments, control validations, risk reporting, and governance activities while providing independent oversight and challenge to First Line of Defence (1LOD) teams. The candidate will partner with cybersecurity, technology, audit, compliance, and business teams to deliver objective cyber risk insights to leadership, auditors, and regulators.

Key Responsibilities
  • Serve as a Second Line of Defence (2LOD) cybersecurity risk professional providing independent oversight of IT controls and risk management activities.
  • Perform Test of Design (TOD) and Test of Effectiveness (TOE) reviews for cybersecurity and technology controls.
  • Conduct Process/Risk/Control (PRC) assessments and evaluate control maturity and effectiveness.
  • Challenge and provide guidance to First Line of Defence (1LOD) control testing teams.
  • Support internal audits, regulatory examinations, compliance reviews, and remediation activities.
  • Analyze cybersecurity risks, vulnerabilities, threats, and control gaps to provide actionable insights.
  • Develop risk reporting, dashboards, metrics, and governance documentation for leadership and regulators.
  • Manage cybersecurity governance activities including risks, issues, actions, dependencies, decisions, and readiness tracking.
  • Collaborate with Cybersecurity, Technology Risk, Compliance, Audit, and Business teams on risk initiatives.
  • Stay updated on emerging cyber threats, regulatory expectations, and security trends.
Required Qualifications
  • 9+ years of experience in Information Security, Cybersecurity, IT Risk Management, or Technology Risk.
  • 6+ years of experience in Cybersecurity Operations, Incident Response, Control Testing, IT Risk, or Security Investigations.
  • Strong experience with IT control audits, control validation, and testing methodologies.
  • Proven experience supporting Banking / Financial Services organizations.
  • Hands-on knowledge of cybersecurity and risk frameworks:
  • NIST Cybersecurity Framework (CSF)
  • SOX Controls
  • IT Governance & Risk Management Frameworks
  • Experience with:
  • Process/Risk/Control (PRC) Reviews
  • Control Effectiveness Testing
  • Audit Remediation
  • Regulatory Compliance
  • Strong understanding of cybersecurity threats, vulnerabilities, and risk management practices.
  • Excellent communication skills with ability to interact with executives, auditors, and regulators.
Preferred Skills
  • IT General Controls (ITGC)
  • Governance, Risk & Compliance (GRC) Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Executive Director, Head of Tech Cyber Data First Line Testing
Executive Director, Head of Tech Cyber Data First Line Testing

SMBC • Charlotte (NC)

On-site
USD 180,000 - 240,000
Executive Director, Head of Tech Cyber Data First Line Testing
Executive Director, Head of Tech Cyber Data First Line Testing

SMBC Group • Charlotte (NC), Northern (KY)

On-site
USD 180,000 - 240,000
IT Risk & Governance Consultant
IT Risk & Governance Consultant

Anblicks • Dallas (TX)

On-site
USD 120,000 - 180,000
IT Risk & Governance Consultant
IT Risk & Governance Consultant

Anblicks Inc. • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
2LOD IT Risk & Control Analyst – Banking
2LOD IT Risk & Control Analyst – Banking

CloudIngest • Charlotte (NC)

Hybrid
USD 120,000 - 160,000
IT Risk Analyst
IT Risk Analyst

Vertex Solutions Inc. • New York (NY)

Hybrid
USD 80,000 - 100,000
Sr. Technology Controls Testing Analyst
Sr. Technology Controls Testing Analyst

BankUnited • Miami (FL)

Hybrid
USD 110,000 - 160,000
Tech Risk & Controls Lead
Tech Risk & Controls Lead

JPMorgan Chase & Co. • New York (NY)

On-site
USD 150,000 - 190,000
Cyber Security Analyst
Cyber Security Analyst

Infobahn Softworld Inc • Oakland (CA)

Hybrid
USD 85,000 - 120,000
Compliance and Operational Risk Manager – Application Security and Technology Risk Oversight
Compliance and Operational Risk Manager – Application Security and Technology Risk Oversight

Bank of America • Chicago (IL)

On-site
USD 140,000 - 190,000