What are the responsibilities and job description for the IT Risk & Control Senior Analyst (Second Line of Defence – 2LOD) position at CloudIngest?
Hi,
Send your resume to Dilip@cloudingest.com
Job Title: IT Risk & Control Senior Analyst (Second Line of Defence – 2LOD)
Location: Hybrid – 4 Days Onsite
Preferred Locations: NYC / Jersey City, NJ | Charlotte, NC | Phoenix, AZ
Industry: Banking / Financial Services
Experience: 10–15 Years Preferred
Client: Direct
Job Overview
We are seeking an experienced IT Risk & Control Senior Analyst to join the Second Line of Defence (2LOD) Cybersecurity Risk function within a leading banking environment. The ideal candidate will have strong expertise in IT risk management, cybersecurity controls, control testing, regulatory compliance, and governance frameworks.
This role will be responsible for performing Test of Design (TOD), Test of Effectiveness (TOE), Process/Risk/Control (PRC) assessments, control validations, risk reporting, and governance activities while providing independent oversight and challenge to First Line of Defence (1LOD) teams. The candidate will partner with cybersecurity, technology, audit, compliance, and business teams to deliver objective cyber risk insights to leadership, auditors, and regulators.
Key Responsibilities
- Serve as a Second Line of Defence (2LOD) cybersecurity risk professional providing independent oversight of IT controls and risk management activities.
- Perform Test of Design (TOD) and Test of Effectiveness (TOE) reviews for cybersecurity and technology controls.
- Conduct Process/Risk/Control (PRC) assessments and evaluate control maturity and effectiveness.
- Challenge and provide guidance to First Line of Defence (1LOD) control testing teams.
- Support internal audits, regulatory examinations, compliance reviews, and remediation activities.
- Analyze cybersecurity risks, vulnerabilities, threats, and control gaps to provide actionable insights.
- Develop risk reporting, dashboards, metrics, and governance documentation for leadership and regulators.
- Manage cybersecurity governance activities including risks, issues, actions, dependencies, decisions, and readiness tracking.
- Collaborate with Cybersecurity, Technology Risk, Compliance, Audit, and Business teams on risk initiatives.
- Stay updated on emerging cyber threats, regulatory expectations, and security trends.
Required Qualifications
- 10 years of experience in Information Security, Cybersecurity, IT Risk Management, or Technology Risk.
- 6 years of experience in Cybersecurity Operations, Incident Response, Control Testing, IT Risk, or Security Investigations.
- Strong experience with IT control audits, control validation, and testing methodologies.
- Proven experience supporting Banking / Financial Services organizations.
- Hands-on knowledge of cybersecurity and risk frameworks:
- NIST Cybersecurity Framework (CSF)
- FAIR Risk Framework
- SOX Controls
- IT Governance & Risk Management Frameworks
- Experience with:
- Risk & Control Self-Assessments (RCSA)
- Process/Risk/Control (PRC) Reviews
- Control Effectiveness Testing
- Audit Remediation
- Regulatory Compliance
- Strong understanding of cybersecurity threats, vulnerabilities, and risk management practices.
- Excellent communication skills with ability to interact with executives, auditors, and regulators.
Preferred Skills
- Cyber Risk Reporting & Metrics
- IT General Controls (ITGC)
- Governance, Risk & Compliance (GRC) Tools
- Third-Party Risk Management
- Security Control Frameworks
- Regulatory Risk Management
- Audit & Compliance Readiness
Thanks,
Dilip Kumar