Jobs · Quality Assurance · Massachusetts

RCSA Quality Control Lead

Apex Systems · Quincy, MA · 5 days ago
Quality AssuranceFull-time

About the role

The Quality Control Lead will provide independent quality control and effective challenge over Risk Control Self Assessment, IT risk assessments, control design, and control testing performed by IT Subject Matter Expert teams.

Responsibilities

  • RCSA and Risk Assessment Quality Control
  • Perform quality control review of IT Risk Control Self Assessments, including risk statements, control mapping, inherent risk ratings, control effectiveness ratings, residual risk ratings, and supporting rationale.
  • Challenge whether risks are clearly defined, appropriately rated, and aligned to the relevant IT process, application, infrastructure, or service.
  • Assess whether controls are appropriately mapped to risks and whether they sufficiently mitigate the stated risk.
  • Review whether key controls are accurately identified and whether control gaps are appropriately documented.
  • Evaluate whether residual risk ratings are supported by control design, operating effectiveness, issue history, incident trends, audit findings, and other risk indicators.
  • Identify inconsistencies, unsupported conclusions, or understatements of risk within IT RCSA submissions.
  • Ensure RCSA documentation meets internal standards, governance expectations, and auditability requirements.
  • Control Testing Effective Challenge
  • Perform independent review and challenge of control testing executed by IT SME teams.
  • Assess whether control testing scripts are clear, risk-based, and aligned to the control objective.
  • Review population completeness, sampling methodology, test steps, evidence sufficiency, exception analysis, and final testing conclusions.
  • Determine whether testing evidence supports the stated pass/fail result and control effectiveness rating.
  • Challenge insufficient evidence, weak testing approaches, inappropriate sampling, incomplete populations, or unsupported conclusions.
  • Ensure that control testing evaluates both control design effectiveness and operating effectiveness.
  • Review testing over manual controls, automated controls, and IT-dependent manual controls.
  • Validate whether exceptions are appropriately assessed for severity, root cause, risk impact, and potential issue escalation.
  • Assess whether compensating controls are appropriately designed, evidenced, and operating effectively.
  • Issue Identification and Remediation Challenge
  • Challenge review control testing exceptions and determine whether they should result in formal issues, action plans, or risk acceptances.
  • Challenge issue severity ratings, root cause analysis, remediation plans, target dates, and ownership.
  • Evaluate whether remediation plans address the underlying control weakness rather than only the observed symptom.
  • Review evidence supporting issue closure and control remediation validation.
  • Identify repeat findings, systemic control weaknesses, and themes across IT domains.
  • Stakeholder Engagement and Governance
  • Partner with IT SME teams, risk owners, control owners, second line risk teams, audit, compliance, and technology leadership.
  • Communicate effective challenge clearly, professionally, and with supporting evidence.
  • Facilitate resolution of challenge points and escalate unresolved matters through appropriate governance channels.
  • Prepare clear documentation of QC results, challenge outcomes, themes, and recommendations.
  • Support management reporting on IT control health, testing quality, RCSA quality, and recurring control deficiencies.
  • Promote consistency and discipline across IT risk and control assessment activities.

Requirements

  • 10+ years of experience in IT risk management, technology audit, IT controls, operational risk, cybersecurity risk, regulatory control testing, or related disciplines.
  • Significant hands-on experience with Risk Control Self Assessment programs in a financial services, regulated, or large enterprise environment.
  • Deep experience reviewing and challenging IT control testing performed by technology, risk, audit, or control teams.
  • Strong understanding of IT general controls, cybersecurity controls, technology operations, infrastructure controls, application controls, and third-party technology risk.
  • Proven experience assessing control design effectiveness and control operating effectiveness.
  • Experience evaluating testing evidence, population completeness, sampling approaches, test scripts, exception handling, and control conclusions.
  • Prior experience performing independent quality control, quality assurance, second line challenge, internal audit review, or regulatory readiness review.
  • Experience interacting with senior IT stakeholders and challenging risk/control conclusions in a professional and evidence-based manner.
  • Strong knowledge of technology risk frameworks and control standards such as COBIT, NIST, ISO 27001, ITIL, COSO, or similar frameworks.
  • Experience in banking, insurance, financial services, fintech, or another highly regulated environment is strongly preferred.
  • Must be well versed in the following IT domains: Identity and Access Management, IT Change Management, Cybersecurity Risk and Controls, Vulnerability and Patch Management, Infrastructure and Platform Controls, Application Controls, Cloud Technology Risk, Data Protection and Privacy Controls, IT Operations, Disaster Recovery and Business Continuity, Third-Party and Technology Vendor Risk, Software Development Life Cycle and DevSecOps, Logging, Monitoring, and Audit Trail Controls.

Preferred Certifications

  • CIA — Certified Internal Auditor
  • CISA — Certified Information Systems Auditor
  • IT, cybersecurity, risk, or technology control certifications, such as: CRISC — Certified in Risk and Information Systems Control, CISSP — Certified Information Systems Security Professional, CISM — Certified Information Security Manager, CGEIT — Certified in the Governance of Enterprise IT, COBIT certification, ITIL certification, ISO 27001 Lead Auditor or Lead Implementer, Cloud security or architecture certifications, such as AWS, Azure, Google Cloud, or CCSP

Benefits

Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a retirement plan (401k or local country equivalent) program. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Apex team member can provide.

Equal Opportunity Employer

We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

Similar jobs

Quality Control Lead

Oldcastle InfrastructureElgin, IL· 4 days ago
Quality Assurance$39.55/hrapply on app.careerarc.com

Quality Control Lead

Oldcastle InfrastructureHouston, TX· 1 wk ago
Quality Assuranceapply on app.careerarc.com

Quality Control Lead

INW: Innovations in Nutrition + WellnessCarrollton, TX· 3 wk ago
Quality Assuranceapply on recruiting2.ultipro.com

Quality Control Lead

EnovisVista, CA· 4 wk ago
Quality Assuranceapply on enovis.wd5.myworkdayjobs.com

Quality Control Lead

US ModulesCollege Station, TX· 1 mo ago
Quality Assuranceapply on us-modules.oasisrecruit.com