IT Risk & Controls Analyst
Tandym Group · Vienna, VA
Apply & track with Apply EdgeA financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna.About the Opportunity:Schedule: Monday to FridayHours: Standard businessSetting: Hybrid (3 days onsite)Responsibilities:Plan and scope IT and Information Security control assessments, including communications, risk and control matrices, scope documents, and supporting materialsConduct walkthroughs with business partners to identify actual versus expected controlsDevelop and execute testing strategies to evaluate control effectivenessDocument testing procedures, results, issues, and assessment conclusionsPrepare final assessment reports and present findings to leadership and other stakeholdersQualifications:Experience performing control testing, audit, risk assessments, or related functionsExperience with IT and/or Information Security risk assessmentsKnowledge of financial services regulations, standards, and frameworks, including FFIEC, NIST, ISO, NCUA, and GLBAFamiliarity with NIST Cybersecurity Framework and 800 Series, ISO 27001/27002, SANS/CIS, and PCI DSSBachelor's degree in Business, Information Systems, or a related field, or equivalent work or military experienceStrong research, analytical, problem-solving, planning, and organizational skillsStrong written, verbal, interpersonal, and technical writing skillsAbility to clearly communicate assessment findings, conclusions, and recommendations to leadershipExperience working effectively with staff, management, business stakeholders, and third partiesAbility to build effective relationships through rapport, trust, diplomacy, and tactStrong proficiency with word processing and spreadsheet applicationsDesired Skills:Information Security certification, such as CISSP, CISA, CCSP, or CRISCExperience working within Audit, Enterprise Risk Management (ERM), or First Line of Defense functionsExperience working in an Agile environment