Job Description/ Responsibilities
We are seeking a highly skilled Technology Risk & Controls Analyst with experience in SDLC, Architecture, Information Security, and Technology Risk Management within the financial services industry. The role requires hands-on experience in ITGC, ITAC, and Information Security control testing, risk assessments, audit support, and regulatory compliance activities. The successful candidate will act as a trusted risk advisor to technology teams while ensuring effective control design, testing, and remediation.
Key Responsibilities
" Conduct ITGC, ITAC, and Information Security control testing and document results.
" Perform Risk & Control Self-Assessments (RCSA) and identify technology risks and control gaps.
" Evaluate control design and operating effectiveness across SDLC, Architecture, and Technology processes.
" Manage audit findings, control deficiencies, and remediation activities through closure.
" Support internal/external audits, regulatory reviews, and compliance requests.
" Partner with SDLC and Architecture teams to provide risk guidance and governance oversight.
" Monitor risk metrics, control performance, and compliance status.
Required Skills & Experience
" 5+ years of experience in Technology Risk, Information Security, IT Controls, Audit, or GRC within financial services.
" Hands-on experience with ITGC, ITAC, and Information Security control testing.
" Strong knowledge of risk management, controls, RCSA, audit, and regulatory compliance.
" Experience supporting SDLC and Architecture governance processes.
" Excellent analytical, documentation, and stakeholder management skills.
Preferred Qualifications
" Experience with AI-driven control testing automation or control monitoring solutions.
" Certifications such as CISA, CRISC, CISSP, CISM, or equivalent.
" Familiarity with regulatory and industry frameworks such as NIST, COBIT, ISO 27001, SOX, or FFIEC.
" ITGC & ITAC Control Testing
" Technology Risk Management
" Information Security Controls
" RCSA
" SDLC & Architecture Risk Governance
" Audit & Regulatory Compliance