Want to know if you’re a fit?
Upload your resume and let our AI show you.
Skills
Analysis Skillsunmatched
Artificial Intelligence (AI)unmatched
Auditingunmatched
CISA - Certified Information Systems Auditorunmatched
CISM - Certified Information Security Managerunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Computer Securityunmatched
Control Objectives for Information and related Technology (COBIT)unmatched
Design Evaluationunmatched
Document Managementunmatched
Documentationunmatched
External Auditunmatched
Financial Servicesunmatched
Health Planunmatched
ISO (International Organization for Standardization)unmatched
Information Technology Consultingunmatched
Information Technology/Systems Auditunmatched
Information/Data Security (InfoSec)unmatched
Internal Auditunmatched
Performance Metricsunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Riskunmatched
Risk Analysisunmatched
Risk Managementunmatched
Sarbanes-Oxley Act (SOX)unmatched
Security Analysisunmatched
Software Development Lifecycle (SDLC)unmatched
Technical Leadershipunmatched
Test Automationunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Description
Our client, a IT Services and Consulting company, is looking for a Information Security Risk Analyst (GRC) for their Phoenix, AZ / Hybrid location.
Responsibilities:
- Conduct ITGC, ITAC, and Information Security control testing and document results.
- Perform Risk & Control Self-Assessments (RCSA) and identify technology risks and control gaps.
- Evaluate control design and operating effectiveness across SDLC, Architecture, and Technology processes.
- Manage audit findings, control deficiencies, and remediation activities through closure.
- Support internal/external audits, regulatory reviews, and compliance requests.
- Partner with SDLC and Architecture teams to provide risk guidance and governance oversight.
- Monitor risk metrics, control performance, and compliance status.
Requirements:
- 5+ years of experience in Technology Risk, Information Security, IT Controls, Audit, or GRC within financial services.
- Hands-on experience with ITGC, ITAC, and Information Security control testing.
- Strong knowledge of risk management, controls, RCSA, audit, and regulatory compliance.
- Experience supporting SDLC and Architecture governance processes.
- Excellent analytical, documentation, and stakeholder management skills.
- Preferred Qualifications:
- Experience with AI-driven control testing automation or control monitoring solutions.
- Certifications such as CISA, CRISC, CISSP, CISM, or equivalent.
- Familiarity with regulatory and industry frameworks such as NIST, COBIT, ISO 27001, SOX, or FFIEC.
- ITGC & ITAC Control Testing
- Technology Risk Management
- Information Security Controls
- RCSA
- SDLC & Architecture Risk Governance
- Audit & Regulatory Compliance
- Years of Experience: 10.00 Years of Experience
Why Should You Apply?
- Health Benefits
- Referral Program
- Excellent growth and advancement opportunities