Data First Jobs

CloudIngest

IT Risk & Control Senior Analyst (Second Line of Defence)

Contract · In Office · New York, New York (USA)

$60,000–$70,000 · Posted Jul 24, 2026

Work Options
Seniority Level
Job Type
Position Group
  • Role: IT Risk & Control Senior Analyst (Second Line of Defence)
  • 65 W2 and 70 C2C - lil higher is ok Location: Hybrid –
  • 4 days onsite in NYC/Jersey City, NJ (Charlotte or Phoenix also acceptable)
  • Eligibility: Green Card / US Citizen only
  • Experience: 10–15 years preferred
  • Industry: Banking/Financial Services
  • Key Responsibilities Act as second line of defence for IT risk and cyber security controls. Perform heavy control testing (Test of Design, Test of Effectiveness). Conduct Process/Risk/Control (PRC) reviews to evaluate control program effectiveness. Provide guidance and challenge to 1LOD testing teams to ensure practices meet standards. Support regulatory deliverables and compliance requirements. Define analysis objectives, collect/evaluate data, and provide objective cyber risk reporting for IT/business leadership. Author detailed reports and gather metrics for auditors, regulators, and external parties. Stay current on cyber security threats, trends, and technologies. Collaborate with other teams on cyber risk initiatives and provide recommendations. Manage site-level governance: track actions, risks, issues, dependencies, decisions, and readiness items. Required Qualifications 10–15 years in Information/Cyber Security, with strong IT risk management background. 6+ years in cyber security operations, incident response, IT risk management, or investigations. Prior IT Control Audit experience (heavy control testing focus). Strong banking/financial industry experience. Knowledge of financial regulation and control frameworks (FAIR, NIST CSF, SOX, etc.). Deep understanding of cyber security landscape (threats, trends, technologies). Excellent communication and interpersonal skills to build strong stakeholder relationships. Team-oriented, customer service mindset. Summary The client is seeking a seasoned IT Risk & Control professional who can operate as the second line of defence, with heavy control testing experience and a strong banking background. The role requires someone who can challenge 1LOD testing practices, ensure compliance with regulatory frameworks, and provide objective risk reporting to leadership. Hybrid onsite presence (4 days) is mandatory in NYC/Jersey City, with flexibility for Charlotte or Phoenix.

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

IT Risk & Control Senior Analyst (Second Line of Defence)

CloudIngest

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.