The Staff IT Analyst – IT Governance, Risk & Controls serves as a first line of defense (1LOD) risk professional responsible for supporting the identification, assessment, monitoring, and reporting of technology risks and internal controls. This role helps protect the organization’s digital assets by partnering with IT, business stakeholders, control owners, risk owners, and second line of defense (2LOD) partners to maintain effective risk and control practices. The Staff IT Analyst supports risk assessments, control inventory documentation, issue and remediation tracking, audit and regulatory readiness, and the execution of applicable IT risk policies, standards, and procedures. This position uses a data-driven approach to strengthen risk visibility, improve control documentation, and support Risk and Control Self-Assessments. Partner with control owners, risk owners, IT stakeholders, business partners, and 2LOD teams to track risk and control priorities, updates, action items, and remediation activities through completion. Support the preparation, execution, review, and refresh of risk and control information by collecting, validating, analyzing, and organizing data from multiple sources. Execute assigned IT risk program activities and business unit risk deliverables accurately, effectively, and within required timelines. Engage with business units and technology teams to support the management of risks and controls across applicable risk categories, including monitoring adherence to policies, procedures, standards, and program requirements. Facilitate discussions with IT and business stakeholders to confirm process understanding, review process maps, validate narratives, and document process-level risks, controls, dependencies, and key handoffs. Coordinate with 2LOD partners to clarify expectations, provide status updates, escalate concerns, and support the timely resolution of open items. Document review results, observations, risk and control updates, process changes, stakeholder feedback, issue details, and recommended actions for management review. Identify and recommend process improvements that strengthen control documentation, execution consistency, transparency, reporting quality, and alignment with IT risk program expectations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level