Position: Risk and Controls Analyst
Engagement Length: 12+ months Controls
Location: Hybrid (3 days) in Montreal, New York, Alpharetta, Chicago, Dallas, Austin, and Philadelphia
Role Overview This role sits within a technology controls measurement function inside a large financial firm. The team is responsible for defining and reporting on metrics that demonstrate whether technology and cybersecurity controls are operating effectively. Rather than testing controls manually on a periodic basis, the goal is to build ongoing, near real time visibility into control performance across the environment.
The analyst in this role will not implement the metrics themselves. Instead, they will work directly with control owners to translate high level control requirements into detailed, structured metric definitions, including data sources, calculation logic, and reporting requirements, then hand those requirements to a separate engineering team for implementation into a BI style reporting dashboard.
Key Responsibilities
- Partner with control owners across security and technology domains to understand how a control operates and what data supports measuring it
- Translate control requirements into clear metric definitions, including data sources, numerator and denominator logic, and any conditions or exceptions
- Work with policy teams to make sure metric requirements stay aligned as policies and controls evolve
- Partner with reporting and engineering teams to hand off requirements for dashboard implementation
- Support governance reporting, thresholds, and escalation processes tied to metric results
- Manage stakeholder expectations across multiple control areas and work under deadline pressure when needed
Required Skills
- 5 or more years of experience in information security or information technology
- 2 or more years of hands on experience with technology or cybersecurity control implementation, for example vulnerability management, identity and access management, or firewall administration
- Ability to define metrics or key control indicators that demonstrate whether a control is operating effectively
- Working understanding of KPIs, OKRs, and how metrics tie back to control assurance
- Familiarity with cybersecurity frameworks and the regulatory context financial institutions operate under
- Strong communication skills, with the ability to align with control owners and translate technical detail for non technical stakeholders
- Strong analytical skills and comfort making decisions based on quantitative and qualitative data
- Experience working with clients or internal stakeholders across a large organization
Not Required
- No coding or data analysis background needed
- No hands on dashboard development or BI tool building, this is a requirements and design role, not an implementation role
Nice to Have
- Knowledge of public cloud technology
- Knowledge of security concepts across identity and authentication, data security, system security, network security, or application security
- Knowledge of security logging, monitoring, or incident response
- Cybersecurity certifications