
IT Controls Analyst
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in United States.
• Act as the primary contact for IT General Controls regarding third-party technology partnerships, which include offshore staffing, SaaS/cloud vendors, outsourced services, contractors, and staff augmentation.
• Maintain documentation of third-party due diligence and approval updates, ensuring current records are kept up to date.
• Convert due diligence and risk assessment results into operational control requirements prior to launch.
• Manage the classification and setup of third-party engagements before onboarding.
• Evaluate third-party roles and access to ensure they align with job functions and adhere to the principle of least privilege.
• Supervise external business partner access models, approved roles, identity attributes, and necessary monitoring requirements.
• Organize periodic access certifications and guarantee timely adjustments or removals of access.
• Oversee controls related to virtual desktops, third-party access, MFA, DLP, endpoint protection, and CASB/Zscaler.
• Track remediation efforts for identity gaps, manual provisioning, excessive provisioning, incomplete deprovisioning, and absent enhanced monitoring.
• Coordinate the setup of the White Room and validate controls for high-risk engagements.
• Manage changes in third-party roles and scopes.
• Monitor control issues, gaps, incidents, audits, and remediation actions.
• Plan and conduct tabletop exercises simulating third-party incidents.
• Oversee the escalation and reporting of third-party incidents until resolution is achieved.
• Generate periodic risk reports related to third parties for Governance Committees, including metrics, evidence, and Key Risk Indicators (KRIs).
• Assist with third-party Business Continuity Planning (BCP) and Disaster Recovery (DR) initiatives and their annual testing.
• Support both internal and external audits, as well as regulatory examinations.
• Monitor the offboarding process of third parties and ensure exit controls are in place, including removal of system/physical access and closure of contractual/data obligations.
• Facilitate third-party governance, oversight, risk classification, location assessments, contract management, and engagement intake.
• Maintain the library of third-party controls, along with process flows, procedures, and control narratives.
• Create specialized assessment reports and other deliverables related to third-party processes.
• Advise the IT General Controls Manager and collaborate with IT Governance, Vendor Management, IT Operations, Information Security, HR, Legal, Compliance, and other relevant stakeholders.
• Support compliance with regulations concerning third-party staffing, sourcing, and operations.
• Provide training, presentations, and communications regarding third-party control requirements.
• Foster continuous improvement through the use of visible metrics and Key Performance Indicators (KPIs).
• Stay updated on industry best practices and suggest enhancements to the control framework.
• Carry out other assigned tasks as needed.
• A Bachelor’s degree in Business Administration, Information Technology, or a related field, or a comparable combination of education and experience.
• At least five years of experience in IT Operations, Security, Risk, Audit, Vendor/Third-Party Risk Management, and/or administration of offshore/outsourced staffing programs.
• Familiarity with access reviews, vendor risk management, and IT General Controls audits.
• Preferred experience in supporting or coordinating offshore/outsourced staffing, SaaS/cloud vendors, or IT contractor programs.
• Capability to collaborate with risk and governance functions and translate due diligence and risk assessment findings into operational controls.
• Proficiency in analyzing and manipulating data using Excel, CRMs, GRC platforms, and online repositories.
• Competence in creating, enhancing, and maintaining IT processes.
• Understanding of the systems development lifecycle and change management principles.
• Knowledge of governance and regulations applicable to financial institutions, including SSAE 16/18, FFIEC, and ISACA/COBIT.
• Advanced skills in Microsoft Word, Excel, and PowerPoint.
• Experience with GRC tools, vendor risk management platforms, project management tools, and IT asset-management platforms is preferred.
• Ability to interpret and communicate complex IT systems, third-party relationships, and operations to diverse audiences.
• Strong research and problem-solving capabilities.
• Ability to establish and adhere to critical deadlines.
• Proficient in prioritizing multiple tasks and complex projects simultaneously.
• Work authorization/location: Remote within the United States.
• Availability to work primarily during the Monday–Friday business week.
• Willingness to travel 5% or less.
• Medical insurance
• Dental insurance
• Vision insurance
• Life insurance
• Accidental Death & Dismemberment (AD&D) insurance
• Long-Term Disability (LTD) insurance
• 401(k) plan with employer match
• A pleasant work environment
• Competitive compensation
Hotelbeds
PointClickCare
Vision Cybersecurity
Método Engenharia
Get handpicked remote jobs straight to your inbox weekly.