IT Risk & IT control testing (GC & USC Only) (Hybrid 4 Days)

CloudIngest

Date: 1 week ago
City: Charlotte, NC
Contract type: Contractor

Please share your updated resume to

Job Title: IT Risk & IT control testing (Second Line of Defence – 2LOD)

Location: Hybrid – 4 Days Onsite

Preferred Locations: NYC / Jersey City, NJ | Charlotte, NC | Phoenix, AZ

Industry: Banking / Financial Services

Job Overview

We are seeking an experienced IT Risk & Control Senior Analyst to join the Second Line of Defence (2LOD) Cybersecurity Risk function within a leading banking environment. The ideal candidate will have strong expertise in IT risk management, cybersecurity controls, control testing, regulatory compliance, and governance frameworks.

This role will be responsible for performing Test of Design (TOD), Test of Effectiveness (TOE), Process/Risk/Control (PRC) assessments, control validations, risk reporting, and governance activities while providing independent oversight and challenge to First Line of Defence (1LOD) teams. The candidate will partner with cybersecurity, technology, audit, compliance, and business teams to deliver objective cyber risk insights to leadership, auditors, and regulators.

Key Responsibilities

  • Serve as a Second Line of Defence (2LOD) cybersecurity risk professional providing independent oversight of IT controls and risk management activities.
  • Perform Test of Design (TOD) and Test of Effectiveness (TOE) reviews for cybersecurity and technology controls.
  • Conduct Process/Risk/Control (PRC) assessments and evaluate control maturity and effectiveness.
  • Challenge and provide guidance to First Line of Defence (1LOD) control testing teams.
  • Support internal audits, regulatory examinations, compliance reviews, and remediation activities.
  • Analyze cybersecurity risks, vulnerabilities, threats, and control gaps to provide actionable insights.
  • Develop risk reporting, dashboards, metrics, and governance documentation for leadership and regulators.
  • Manage cybersecurity governance activities including risks, issues, actions, dependencies, decisions, and readiness tracking.
  • Collaborate with Cybersecurity, Technology Risk, Compliance, Audit, and Business teams on risk initiatives.
  • Stay updated on emerging cyber threats, regulatory expectations, and security trends.

Required Qualifications

  • 8+ years of experience in Information Security, Cybersecurity, IT Risk Management, or Technology Risk.
  • 6+ years of experience in Cybersecurity Operations, Incident Response, Control Testing, IT Risk, or Security Investigations.
  • Strong experience with IT control audits, control validation, and testing methodologies.
  • Proven experience supporting Banking / Financial Services organizations.
  • NIST Cybersecurity Framework (CSF)
  • FAIR Risk Framework
  • SOX Controls
  • IT Governance & Risk Management Frameworks
  • Risk & Control Self-Assessments (RCSA)
  • Process/Risk/Control (PRC) Reviews
  • Control Effectiveness Testing
  • Audit Remediation
  • Regulatory Compliance
  • Strong understanding of cybersecurity threats, vulnerabilities, and risk management practices.
  • Excellent communication skills with ability to interact with executives, auditors, and regulators.

Preferred Skills

  • Cyber Risk Reporting & Metrics
  • IT General Controls (ITGC)
  • Governance, Risk & Compliance (GRC) Tools
  • Third-Party Risk Management
  • Security Control Frameworks
  • Regulatory Risk Management
  • Audit & Compliance Readiness

For employers only

Is this your company's job post? Verify ownership to manage this listing and receive applications directly.

Claim this listing

Looking to apply for this job? Use the Apply button above.