A financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna.
About the Opportunity:
Responsibilities:
Plan and scope IT and Information Security control assessments, including communications, risk and control matrices, scope documents, and supporting materials
Conduct walkthroughs with business partners to identify actual versus expected controls
Develop and execute testing strategies to evaluate control effectiveness
Document testing procedures, results, issues, and assessment conclusions
Prepare final assessment reports and present findings to leadership and other stakeholders
Qualifications:
Experience performing control testing, audit, risk assessments, or related functions
Experience with IT and/or Information Security risk assessments
Knowledge of financial services regulations, standards, and frameworks, including FFIEC, NIST, ISO, NCUA, and GLBA
Familiarity with NIST Cybersecurity Framework and 800 Series, ISO 27001/27002, SANS/CIS, and PCI DSS
Bachelor's degree in Business, Information Systems, or a related field, or equivalent work or military experience
Strong research, analytical, problem-solving, planning, and organizational skills
Strong written, verbal, interpersonal, and technical writing skills
Ability to clearly communicate assessment findings, conclusions, and recommendations to leadership
Experience working effectively with staff, management, business stakeholders, and third parties
Ability to build effective relationships through rapport, trust, diplomacy, and tact
Strong proficiency with word processing and spreadsheet applications
Desired Skills:
Information Security certification, such as CISSP, CISA, CCSP, or CRISC
Experience working within Audit, Enterprise Risk Management (ERM), or First Line of Defense functions
Experience working in an Agile environment