The IT Risk Senior Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. Focus areas of IT Control assessment by the ITRM Security Senior Analyst includes fit for purpose review and challenges and process/risk/control (PRC) reviews to evaluate and overall control program effectiveness in mitigating risk. The ITRM Senior Analyst's goal is to create actionable information for IT and business leadership, and to provide objective assessment of cyber security risks for auditors, regulators and external parties. This requires routinely performing review and challenge reviews against 1LOD testing practices specific to T&I controls, authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information. The ITRM Senior Analyst keeps abreast of external cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject-matter recommendations and guidance to achieve a posture within the bank's overall risk appetite. This is an advanced senior professional with wide ranging experience uses professional concepts and to resolve complex issues in creative and effective ways. Serves as an expert in own discipline or area of specialization. Works on complex issues where analysis of situations or data requires an in-depth evaluation of variable factors.