ABA Testing Analyst - 17567
About the Role
Seneca Resources is seeking an ABA Testing Analyst to support Asset-Based Assessment (ABA) and testing activities across IT and Information Security controls. This role is ideal for an early-to-mid-career professional with experience in IT audit, cybersecurity risk, controls testing, information security assessments, or governance, risk, and compliance (GRC).
The analyst will support the full assessment lifecycle, including planning and scoping, control walkthroughs, test strategy development, evidence review, issue documentation, reporting, and communication with business partners and leadership. The successful candidate will be comfortable working in an Agile environment and collaborating with stakeholders across multiple levels of an organization.
Responsibilities
- Plan and scope Asset-Based Assessments, including developing communications, risk and control matrices, scope documents, and supporting assessment materials.
- Conduct control walkthroughs with business partners to identify actual versus expected control activities.
- Develop and execute control testing strategies to evaluate the effectiveness of IT and Information Security controls.
- Review and document testing evidence and work performed in accordance with applicable Internal Audit reperformance standards.
- Identify, document, and communicate control deficiencies, issues, risks, and observations.
- Prepare clear and concise assessment reports and supporting documentation.
- Present assessment results, findings, and conclusions to leadership and key stakeholders.
- Collaborate with business partners, management, control owners, third parties, and other stakeholders throughout the assessment lifecycle.
- Conduct research and analysis related to information security controls, regulatory requirements, and industry frameworks.
- Support additional testing, risk, compliance, and information security initiatives as assigned.
Required Skills & Experience
- 1–5 years of experience in IT controls testing, IT audit, information security risk, cybersecurity assessments, GRC, or a related field.
- Experience with control testing and/or one or more areas of the Three Lines of Defense, including Internal Audit, Enterprise Risk Management (ERM), or First Line functions.
- Experience supporting IT audits, information security risk assessments, or cybersecurity control assessments.
- Knowledge of information security regulations, standards, and frameworks, including: NIST Cybersecurity Framework and NIST 800 Series, FFIEC, NCUA, GLBA, ISO 27001/27002, CIS/SANS controls, and PCI DSS.
- Strong understanding of IT and Information Security controls, risk management, compliance, and control assessment principles.
- Ability to work effectively with employees, management, business stakeholders, control owners, and third parties.
- Strong analytical, research, problem-solving, planning, and organizational skills.
- Excellent verbal and written communication skills, including technical writing and assessment reporting.
- Ability to present findings and recommendations clearly and concisely to leadership.
- Strong relationship-building skills, including the ability to establish trust, demonstrate diplomacy, and collaborate effectively.
- Proficiency with Microsoft Word, Excel, and other standard productivity tools.
- Bachelor's degree in Business, Information Systems, Cybersecurity, Information Technology, or a related field, or equivalent work/military experience.
Qualifications
- Relevant certifications such as CISA, CISSP, CCSP, CRISC, or other Information Security/GRC certifications are preferred.
- Maintain awareness of and comply with applicable organizational policies, procedures, and regulations related to the Bank Secrecy Act (BSA).
- Candidates must be authorized to work in the United States. Sponsorship is not available for this position.
Pay
- $40.00–$43.00/hour (contract position)