Summer Associate Internship (Technical Risk Analyst - Security)

Navy Federal Credit UnionVienna, VA
$26 - $47Onsite

About The Position

The Security Controls Oversight, Risk & Evaluation (SCORE) team is responsible for evaluating risk, validating control effectiveness, and delivering actionable insights that help Security leaders manage risk, meet regulatory expectations, and improve business outcomes. Through risk & control self assessments (RCSA), controls testing, reporting, and emerging AI-enabled capabilities, the team serves as a strategic business partner focused on advancing risk maturity, operational excellence, and informed decision-making across the Security organization. The Summer Associate Program is a 12-week internship program beginning in May 2027 and ending in August 2027. Students will work on impactful projects and meaningful work during their internship. To qualify for this position, applicants must be currently pursuing a degree from an accredited college or university and have an anticipated graduation date of December 2027 or later. Potential Projects: Risk & Control Process Modernization (AI and Automation) - Evaluate current risk & control identification and controls testing activities to identify repetitive, time-intensive tasks that could benefit from AI-assisted capabilities. Develop a prioritized roadmap of AI use cases focused on improving productivity, quality, consistency, and analyst capacity. Reporting & Metrics Enhancement - Inventory SCORE reporting products and performance metrics to determine which measures effectively support decision-making and which create unnecessary effort. Recommend a future-state reporting framework that improves data quality, transparency, automation, and leadership visibility. Process Rationalization & Risk Mapping - Evaluate relationships between Security processes, risks, controls, standards, and regulatory requirements to improve traceability and reduce complexity. Produce a consolidated mapping model that supports process rationalization, risk coverage analysis, and future governance activities. Cross-function Shadowing - Shadow staff and leaders from other Security, Governance, and Risk functions to gain visibility into cross-team enterprise efforts such as issues management, incident management, and leadership reporting.

Requirements

  • Currently enrolled in an accredited college or university pursuing a Bachelor's or Master's degree in: Information Security/Cybersecurity, Computer Information Systems, Information Technology, Risk Management, Accounting, or a related field.
  • Strong analytical and problem-solving skills.
  • Effective verbal and written communication skills.
  • Ability to gather, organize, and analyze information from multiple sources.
  • Proficiency with Microsoft Office products, including Excel, Word, PowerPoint, and Teams.

Nice To Haves

  • Coursework or experience in risk management, audit, compliance, cybersecurity, information assurance, or internal controls.
  • Familiarity with risk assessment frameworks or control frameworks such as NIST, FFIEC, ISO 27001, COBIT, or COSO.
  • Experience using data analysis tools such as Excel, Power BI, SQL, or similar technologies.
  • Understanding of governance, risk, and compliance (GRC) concepts.
  • Interest in pursuing careers in cybersecurity, risk management, internal audit, compliance, or security governance.

Responsibilities

  • Support Risk & Control Identification and Assessment (RCIA) workshops and RCSA activities by documenting process information, risks, controls, and assessment outcomes.
  • Assist with the review and analysis of process documentation, narratives, procedures, and process maps to identify potential risks and control opportunities.
  • Participate in security control testing activities by collecting, organizing, and reviewing evidence under the supervision of testing personnel. Assist with documenting test procedures, test results, observations, and supporting workpapers.
  • Perform data analysis and validation to support risk assessments, control evaluations, and reporting activities.
  • Support the maintenance of risk and control inventories within governance, risk, and compliance (GRC) systems.
  • Assist with tracking action items, issues, remediation efforts, and testing milestones.
  • Create executive-ready summaries, presentations, and status reporting materials for management review.
  • Research regulatory requirements, industry standards, and leading practices related to operational risk, information security, and controls management.
  • Collaborate with risk managers, control testers, process owners, and business stakeholders to support ongoing assessment and governance activities.
  • Participate in team meetings, project discussions, and training opportunities to gain exposure to enterprise risk management practices.
  • Perform other duties as assigned.

Benefits

  • highly competitive pay
  • generous benefits and perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service