Jobs and Careers
XS
Senior Analyst, Technology Compliance & Risk Management
xScionWashington, United StatesRemotefull_timeVerifiedPosted 7 Feb 2023
About the role
As an employee, you Turn Change Into Value® - for our clients, for our company, for your professional growth, for the consumers. We hire the best and brightest, who are driven to create lasting value. At xScion, you aren't just another team member, you're impactful. You're empowered. You're driven. You're an xScioneer.
Location: Washington, DC (Remote)
As a Senior Analyst - Technology Compliance & Risk Management, You Will:
- Ensure the IT control environment is maintained and continuously improved in accordance with compliance goals, industry standards and legislative updates and mandates
- Work with the internal controls team to design and implement a risk-based approach for controls and testing strategies for the IT general control's environment to support compliance objectives
- Integrate controls into existing processes, perform assessments of projects and initiatives as they relate to complacent issues and deliver risk and control profiles for integration into systems development and operational lifecycles
- Provide oversight and guidance to process and control owners to maintain the required documentation and necessary artifacts to document the operational effectiveness of IT general controls
- Conduct management testing of IT general controls and application controls, providing results and mitigation or remediation strategies to process owners and management
- Assist in the set up and maintenance of a third-party vendor risk management program
- Assist in the day-to-day maintenance of a stable production change management environment by ensuring changes to production systems are properly planned, tested and approved
- Perform risk assessments and deliver risk-mitigation strategies to process owners, project leads and management
- Conduct periodic testing and quality assurance reviews of policies, procedures and process documentation
- Drive the establishment and monitoring of key risk indicators and key performance indicators (KRIs/KPIs) to ensure that senior management makes information risk aware decisions. Responsible for developing, monitoring and tracking of metrics to monitor and evaluate the efficiency and effectiveness of KRIs/KPIs
- Lead the development of reports/dashboards to senior management on IT activities and potential risks. Manage the annual risk assessment date gathering process and development/maintenance of risk heat maps, dashboards and risk registers
- Provide advice and influence risk management strategies and educate risk owners on best practices.
- Analyze information gathered from on-going collaboration with functional areas to develop and implement risk solutions to ensure continued stability and success.
- Work closely with counterparts in internal audit, financial operations, and other second line of defense risk areas
- Foster a climate that manages organizational risk and supports company's goals and culture
- Deliver high quality work products and effectively manage workload to meet deadlines
- Assist in set up and maintenance of a vendor management program and take accountability for developing a program to strive for optimal vendor performance and operational efficiencies
- Coordinate, support and manage all stages of the contract lifecycle including:
- Communicating with senior level team member about vendor performance and relationship management
- Building and fostering or a robust, transparent and cooperative relationship and partnership between IT department, it's management and partners
- Assure that all vendors and contractors report to a defined IT vendor manager who endures that KPIs and SLAs are defined for the vendors and contractors that build an atmosphere of monitoring and continuous performance improvement
- Plan, manage and oversee all operation support of these vendor relationships,. working directly with the IT vendor manager and vendor to ensure performance is meeting expectations outlined in the contract as well future contract negotiation planning and implementation for new business needs
To Be Successful, You Need:
- Bachelor’s degree or equivalent experience required in Computer Science or equivalent experience
- Minimum 8+ years of relevant experience in IT operations, general controls, internal/external audit relationships, risk management, security standards or change management
- Strong understanding of operational governance, risk and compliance practices
- Experience in relevant risk industry standards/frameworks: ESG, COSO, COBIT, ISO, NIST, FFIEC
- Fundamental understanding of data analysis/GRC tools and techniques
- ServiceNow experience required
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s