Risk Analyst-Control Testing

BRMiVienna, VA
$97,000 - $110,000Hybrid

About The Position

BRMi is seeking a Risk Analyst – Control Testing who will support the Risk Control Self-Assessment (RCSA) process by performing control design assessments and control performance testing across security-related business areas, with a primary focus on fraud operations and information security. This role is responsible for evaluating the design and effectiveness of internal controls, documenting testing results, identifying deficiencies, and supporting the development of appropriate remediation plans. The ideal candidate will have prior experience conducting control testing within an internal audit or RCSA environment and a strong understanding of audit methodologies, risk management frameworks, sampling techniques, and control effectiveness. This position requires strong analytical and documentation skills and the ability to communicate findings clearly to stakeholders and management. Hybrid in Vienna, VA or Pensacola, FL In person interviews will be required for this role 6 month contract with possibility of extension.

Requirements

  • Three to five years of experience performing control testing within internal audit, Risk Control Self-Assessment (RCSA), risk management, or a similar control assurance environment.
  • Advanced understanding of internal audit and control testing techniques.
  • Strong understanding of risk management frameworks and control assessment methodologies.
  • Experience conducting control design assessments and control performance or operating effectiveness testing.
  • Knowledge of sampling methodologies and techniques used to support control testing.
  • Experience identifying, documenting, and communicating control deficiencies and testing findings.
  • Ability to perform root-cause analysis and support the development of remediation plans.
  • Strong analytical and critical-thinking skills with the ability to evaluate processes, controls, documentation, and supporting evidence.
  • Strong organizational skills and attention to detail.
  • Ability to manage multiple priorities and testing assignments under tight timeframes.
  • Strong written communication skills with the ability to clearly document testing procedures, analysis, conclusions, and findings.
  • Strong verbal communication skills with the ability to discuss findings with stakeholders and various levels of management.
  • Ability to work independently while collaborating effectively with business, risk, security, and audit stakeholders.

Nice To Haves

  • Prior experience evaluating controls within security-related business areas.
  • Experience supporting or evaluating fraud operations and associated controls.
  • Experience evaluating information security controls.
  • Experience working within a large enterprise or highly regulated environment.
  • Familiarity with governance, risk, compliance, and internal control programs.
  • Certified Internal Auditor (CIA), Certified Information Systems Auditor (CISA), Certified Public Accountant (CPA), or another relevant professional certification.

Responsibilities

  • Participate in the Risk Control Self-Assessment (RCSA) process and related control testing activities.
  • Execute design assessments on assigned controls to determine whether controls are appropriately designed to mitigate identified risks.
  • Perform control performance and operating effectiveness testing on assigned controls.
  • Follow enterprise testing guidelines, methodologies, and documentation standards.
  • Apply accepted sampling techniques to select appropriate populations and samples for control testing.
  • Review supporting documentation, evidence, processes, and procedures to evaluate control effectiveness.
  • Analyze testing results and determine whether controls are operating as intended.
  • Document testing procedures, analysis, conclusions, findings, and supporting evidence in accordance with enterprise guidelines.
  • Identify control deficiencies, exceptions, gaps, and other areas of risk discovered through testing.
  • Perform root-cause analysis for identified control deficiencies.
  • Assist business and risk stakeholders in developing appropriate remediation plans to address identified deficiencies.
  • Communicate testing results and findings clearly to business partners, risk stakeholders, and various levels of management.
  • Track testing activities, findings, remediation efforts, and related deliverables to ensure established timelines are met.
  • Maintain organized and complete testing documentation to support internal review, audit, and regulatory requirements.
  • Collaborate with stakeholders across security, fraud operations, information security, risk management, and other business areas.
  • Manage multiple control testing assignments and priorities within established deadlines.
  • Support continuous improvement of control testing processes, documentation, and risk management practices.
  • Perform other duties as required.

Benefits

  • Comprehensive Medical, Dental, and Vision Insurance
  • Employer-Paid Life Insurance
  • Employer-Paid Short-Term and Long-Term Disability Insurance
  • 401(k)
  • Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
  • Educational Assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service