Senior IT Risk Analyst

Rockland Trust

Plymouth (MA)

Hybrid

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance
401K
Dental Insurance
Tuition Assistance
Wellness program

Job summary

Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This hybrid role features 3 days in the Plymouth office (Mon–Wed) and remote work on other days, focusing on risk identification, assessment, and mitigation with IT and business stakeholders.

The ideal candidate will lead risk assessments, evaluate controls, mentor colleagues, and drive process improvements while ensuring timely remediation and regulatory alignment across

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance, or a related field with equitable risk and controls experience.
  • Minimum of 5 years of professional experience in IT risk management, technology audit, or control testing, including execution of risk assessments, control evaluation, and reporting.
  • Must be able to work the hybrid schedule: 3 days Mon‑Wed in the Plymouth office then remaining days work remotely.
  • Experience with GRC platforms (e.g., Archer) and risk reporting tools (e.g., PowerBI dashboards).
  • Familiarity with risk and control frameworks such as NIST, CIS, COBIT, FFIEC, or ISO.
  • Demonstrated ability to effectively communicate, both written and verbally, complex IT risk and control concepts effectively to technical and non‑technical stakeholders.
  • Experience navigating highly regulated or matrixed environments, interacting with audit, compliance, and/ or regulatory stakeholders.
  • Strong analytical skills, attention to detail, and ability to make independent, informed decisions.
  • Proven ability to influence outcomes and drive follow‑through on risk identification and mitigation activities.

Responsibilities

  • Lead comprehensive IT risk assessments across applications, infrastructure, and IT processes, including inherent and residual risk evaluations.
  • Evaluate the design and operating effectiveness of controls, ensuring assessments are evidence‑based and aligned with internal methodologies and regulatory requirements.
  • Conduct detailed walkthroughs and interviews with IT and business stakeholders to validate processes and risks, identify control gaps, and obtain and evaluate appropriate documentation and evidence.
  • Analyze risk and control data to identify trends, recurring issues, or systemic weaknesses to translate findings into actionable insights.
  • Maintain sufficient documentation of assessments performed, tests conducted, and issues noted in the Bank's systems of record, ensuring clarity, completeness, and alignment with Bank and regulatory methodology and requirements.
  • Communicate findings, risk implications, control gaps, or other such issues to stakeholders in a professional, credible, and constructive manner.
  • Support, advise, and challenge remediation plans to ensure proposed actions effectively mitigate identified risks.
  • Coordinate responses to audit, regulatory, or other internal inquiries, ensuring timely and accurate resolution of outstanding issues.
  • Track and monitor remediation efforts and key milestones to facilitate risk closure, proactively identifying potential bottlenecks or emerging risks.
  • Provide guidance and informal coaching to junior team members, reviewing work products to ensure adherence to risk assessment standards and quality expectations.
  • Contribute to continuous improvement initiatives for IT risk assessment methodologies, reporting practices, and other opportunities.
  • Serve as a trusted resource for IT and business teams on risk‑related topics, fostering a risk‑aware culture and promoting best practices.
  • Stay current with regulatory guidance, industry standards, and emerging risks to support program maturity and long‑term risk management effectiveness.

Skills

GRC platforms
PowerBI dashboards
Communication
Risk assessment
Regulatory knowledge

Education

Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance, or related field

Tools

Archer

Job description

Senior IT Risk Analyst (First Line of Defense)

Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program.

This is a hybrid role, 3 days Mon‑Wed in the Plymouth office then remaining days working remotely.

This senior professional contributes to the identification, assessment, and mitigation of technology risks, providing informed recommendations to IT and business stakeholders. The role emphasizes accountability for high-quality risk assessments, strong judgment in interpreting results, and proactive contributions to process improvement and risk awareness across the organization.

This role serves as a resource and mentor to less‑experienced colleagues, supporting development and consistent execution of sound risk management practices. The Senior IT Risk Analyst works closely with stakeholders across IT and business areas to ensure risks are adequately identified and managed, controls are designed and operating effectively, and necessary remediation activities are completed in a timely manner.

Key Responsibilities
IT Risk Assessment & Control Evaluation
  • Lead comprehensive IT risk assessments across applications, infrastructure, and IT processes, including inherent and residual risk evaluations.
  • Evaluate the design and operating effectiveness of controls, ensuring assessments are evidence‑based and aligned with internal methodologies and regulatory requirements.
  • Conduct detailed walkthroughs and interviews with IT and business stakeholders to validate processes and risks, identify control gaps, and obtain and evaluate appropriate documentation and evidence.
  • Analyze risk and control data to identify trends, recurring issues, or systemic weaknesses to translate findings into actionable insights.
  • Maintain sufficient documentation of assessments performed, tests conducted, and issues noted in the Bank's systems of record, ensuring clarity, completeness, and alignment with Bank and regulatory methodology and requirements.
Risk Communication & Issue Resolution
  • Communicate findings, risk implications, control gaps, or other such issues to stakeholders in a professional, credible, and constructive manner.
  • Support, advise, and challenge remediation plans to ensure proposed actions effectively mitigate identified risks.
  • Coordinate responses to audit, regulatory, or other internal inquiries, ensuring timely and accurate resolution of outstanding issues.
  • Track and monitor remediation efforts and key milestones to facilitate risk closure, proactively identifying potential bottlenecks or emerging risks.
Program Support & Mentorship
  • Provide guidance and informal coaching to junior team members, reviewing work products to ensure adherence to risk assessment standards and quality expectations.
  • Contribute to continuous improvement initiatives for IT risk assessment methodologies, reporting practices, and other opportunities.
  • Serve as a trusted resource for IT and business teams on risk‑related topics, fostering a risk‑aware culture and promoting best practices.
  • Stay current with regulatory guidance, industry standards, and emerging risks to support program maturity and long‑term risk management effectiveness.
Required Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance, or a related field with equitable risk and controls experience.
  • Minimum of 5 years of professional experience in IT risk management, technology audit, or control testing, including execution of risk assessments, control evaluation, and reporting.
  • Must be able to work the hybrid schedule: 3 days Mon‑Wed in the Plymouth office then remaining days work remotely.
  • Experience with GRC platforms (e.g., Archer) and risk reporting tools (e.g., PowerBI dashboards).
  • Familiarity with risk and control frameworks such as NIST, CIS, COBIT, FFIEC, or ISO.
  • Demonstrated ability to effectively communicate, both written and verbally, complex IT risk and control concepts effectively to technical and non‑technical stakeholders.
  • Experience navigating highly regulated or matrixed environments, interacting with audit, compliance, and/ or regulatory stakeholders.
  • Strong analytical skills, attention to detail, and ability to make independent, informed decisions.
  • Proven ability to influence outcomes and drive follow‑through on risk identification and mitigation activities.
Highly preferred
  • Professional certifications: CISA, CRISC, CISM, CISSP, or equivalent.
  • Financial services industry experience.
Benefits

Our goal is to offer our colleagues the most generous benefits package possible. We strive to provide colleagues with a comprehensive benefits package and an environment that supports a healthy work‑life balance. Benefits include: Competitive compensation with performance incentive awards, Health Insurance, Dental Insurance, a 401K and DC Plan for your retirement, LTD & Life Insurance, Vacation Time, Day Care Reimbursement, Tuition Assistance for graduate and undergraduate programs, an Award Winning Wellness program and much more!

Equal Opportunity Employer

At Rockland Trust you'll find a respectful and inclusive environment where everyone is given the chance to succeed. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Audit Specialist
Senior IT Audit Specialist

Rockland Trust • Rockland (MA)

On-site
USD 110,000 - 145,000
Health Insurance
401(k) Plan
Tuition Assistance
Senior IT Audit Specialist
Senior IT Audit Specialist

Socket.dev • Rockland (MA)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
401(k) plan
+1
Senior IT Support Analyst
Senior IT Support Analyst

Rockland-Trust-Company • Rockland (MA)

On-site
USD 95,000 - 130,000
Health insurance
401(k) plan
Paid vacation
+1
Hybrid Senior IT Risk Analyst - Lead Controls & Risk
Hybrid Senior IT Risk Analyst - Lead Controls & Risk

Rockland Trust • Plymouth (MA)

Hybrid
USD 110,000 - 150,000
Health Insurance
401K
Dental Insurance
+2
Senior IT Support Analyst
Senior IT Support Analyst

Rockland Trust • Rockland (MA)

On-site
USD 90,000 - 130,000
Health insurance
Dental insurance
401(k) plan
+3
Identity & Access Management Analyst
Identity & Access Management Analyst

Rockland Trust • Plymouth (MA)

On-site
USD 80,000 - 100,000
Health and dental insurance
401(k) and DC retirement plan
Tuition assistance
+1
Compliance Program Officer at Rockland Trust Norwood, MA
Compliance Program Officer at Rockland Trust Norwood, MA

Rockland Trust • Norwood (MA)

On-site
USD 95,000 - 130,000
Health Insurance
Dental Insurance
401K/DC Plan
+4
Regulatory Change Management Officer
Regulatory Change Management Officer

Rockland Trust • Rockland (MA)

On-site
USD 75,000 - 95,000
Health and dental insurance
401(k) and DC retirement plan
Paid vacation
+2
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
E Banking Specialist I
E Banking Specialist I

Rockland Trust • Plymouth (MA)

On-site
USD 52,000 - 66,000
Health insurance
401(k) plan
Paid vacation
+1