Enterprise Risk Analyst Sr.

Flagstar BankNew York, NY
$79,538 - $129,179Onsite

About The Position

The Technology Risk Analyst Sr. is responsible for creating, maintaining, assessing and reporting on the status of the information technology and information security threats, risks, and controls. This position will be responsible for identifying and documenting potential gaps, testing and validating control adherence, and recommending and validating risk mitigation. In addition this position will perform enterprise wide cyber and technology risk assessments, create formal risk assessment reports, and communicate these to senior leadership.

Requirements

  • High School / High School Equivalency (GED, HiSET, TASC) / Foreign Equivalent
  • Minimum experience required: 4+ Years in Technology Audit, Information Technology, or Information Security.
  • Security +, CISA, CRISC, CISSP or equivalent.
  • Strong understanding of internal/external processes and deadlines.
  • Expert in technology and security risk mitigation.
  • Expert in Risk Assessment and Control development.
  • Experience designing risk and control programs aligned to FFIEC, NIST 800-53, NIST 800-37 and financial services regulatory requirements.
  • Knowledge of Technology organization business processes and systems.
  • Experience creating and maintaining threat and risk registers, and explaining residual risk to non-technical audiences.
  • Expert in creating and maintaining KPIs and KRIs.
  • Prior experience implementing or overseeing cross functional, enterprise wide projects and technologies.
  • Well-rounded understanding of technology, operations, and key business processes.
  • Demonstrates a strong ability to build and maintain effective relationships with stakeholders by communicating clearly, engaging in proactive collaboration, and leveraging cross functional insights. Aligns relationship building efforts with enterprise goals to accelerate performance and drive strategic results.
  • Builds trusted client relationships, whether internal or external, by identifying needs and delivering tailored solutions to enhance the overall client experience.
  • Fosters or supports a positive work culture and productive work environment, displaying importance of effective relationships with customers and stakeholders.

Responsibilities

  • Govern and risk assess technology and security programs: including policies, standards, controls, procedures, and testing requirements for technology and security organization in line with NIST 800-53 and NIST 800-37, Secure Controls Framework, and Industry Best Practices.
  • Design, validate, track, and report risk mitigation strategies in line with the company risk appetite. Communicate results to stakeholders including executive leadership.
  • Perform complex enterprise wide risk assessments including mapping out threats and controls, identifying gaps, determining inherent and residual risk ratings in adherence with the enterprise Risk Governance Framework. Create formal risk assessment reports and present to executive leadership.
  • Assist stakeholders in the business lines and technology in understanding risk and control requirements to ensure that risk responsibilities are understood and followed throughout the enterprise. Assist more junior associates on the team with understanding complex technical concepts and best practices.
  • Uses independent judgement and discretion to make decisions.
  • Analyzes and resolves problems.
  • Performs special projects, and additional duties and responsibilities as required.
  • Consistently adheres to regulatory and compliance policies and standards linked to the job as listed and complete required compliance trainings. Accountable to maintain compliance with applicable federal, state and local laws and regulations.

Benefits

  • medical, dental, vision, life, and disability insurance
  • comprehensive leave program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service