IT Risk & Controls Analyst
Tandym Group · Vienna, VA · 2 days ago
HybridFull-time
About the role
A financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna.
Responsibilities
- Plan and scope IT and Information Security control assessments, including communications, risk and control matrices, scope documents, and supporting materials
- Conduct walkthroughs with business partners to identify actual versus expected controls
- Develop and execute testing strategies to evaluate control effectiveness
- Document testing procedures, results, issues, and assessment conclusions
- Prepare final assessment reports and present findings to leadership and other stakeholders
Qualifications
- Experience performing control testing, audit, risk assessments, or related functions
- Experience with IT and/or Information Security risk assessments
- Knowledge of financial services regulations, standards, and frameworks, including FFIEC, NIST, ISO, NCUA, and GLBA
- Familiarity with NIST Cybersecurity Framework and 800 Series, ISO 27001/27002, SANS/CIS, and PCI DSS
- Bachelor's degree in Business, Information Systems, or a related field, or equivalent work or military experience
- Strong research, analytical, problem-solving, planning, and organizational skills
- Strong written, verbal, interpersonal, and technical writing skills
- Ability to clearly communicate assessment findings, conclusions, and recommendations to leadership
- Experience working effectively with staff, management, business stakeholders, and third parties
- Ability to build effective relationships through rapport, trust, diplomacy, and tact
- Strong proficiency with word processing and spreadsheet applications
Desired Skills
- Information Security certification, such as CISSP, CISA, CCSP, or CRISC
- Experience working within Audit, Enterprise Risk Management (ERM), or First Line of Defense functions
- Experience working in an Agile environment