Technology Risk Analyst
Indexed description
JOB SUMMARY
Supports the company’s technology risk, Information Security and IT operations by executing recurring monitoring, control, documentation, audit-preparation and follow-up activities. The role improves the consistent execution and evidencing of controls, reduces operational backlog, and creates capacity for senior resources to focus on higher-value risk analysis, infrastructure strategy and modernization. The position is designed as an early-career, shared resource with an initial allocation of 50% Information Security, 40% IT and 10% innovation and automation.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Perform initial daily monitoring of security alerts, logs, access activity and anomalies; complete and retain the required security checklist and supporting evidence.
- Prepare recurring security, compliance and technology-risk reports in accordance with approved calendars, internal service levels and management requirements.
- Support user-access administration for applications, including request intake, documentation, validation, status tracking and escalation of exceptions.
- Support quarterly access recertifications by preparing populations, organizing evidence, tracking responses and following up on incomplete items.
- Collect, organize and maintain evidence for internal audits, external audits, regulatory examinations, SWIFT reviews and other control assessments.
- Maintain shared trackers for audit requests, remediation commitments, vulnerabilities, access reviews, policy updates and other technology-risk activities.
- Support vulnerability-management and penetration-testing remediation by confirming ownership, target dates, aging and status; escalate overdue or high-risk items.
- Assist with the documentation, review cycle and controlled maintenance of Information Security and IT policies, procedures, standards and operating checklists.
- Support security-awareness activities, phishing simulations and employee communications, including scheduling, evidence retention and follow-up reporting.
- Provide operational support during security incidents by documenting actions, maintaining timelines, organizing evidence and escalating matters to the appropriate decision-makers.
- Support Business Continuity Plan maintenance, exercise documentation, action tracking and continuity evidence for technology services.
- Prepare capacity-planning and performance reports that improve visibility into infrastructure utilization, trends and potential bottlenecks.
- Document corporate technology projects, intake items, decisions, dependencies, meeting minutes and status updates to improve traceability and prioritization.
- Map manual processes and support approved automation initiatives, dashboards, internal AI use-case documentation and maintenance of an operational knowledge base.
- Support emerging control activities, including Shadow IT identification, hardening-baseline implementation, AI/GenAI governance under applicable Group frameworks, SaaS/cloud security reviews and third-party security follow-up.
- Coordinate work across IT and Information Security while preserving segregation of duties. The role does not provide final approval, make regulatory decisions, own critical controls, or perform activities that create a conflict of interest.
- Prioritize regulatory, audit, security and critical operational matters; participate in monthly workload reviews and quarterly allocation adjustments based on demand.
POSITION REQUIREMENTS
- Working knowledge of technology risk, information security, IT operations, internal controls or audit-support concepts.
- Ability to execute repeatable control activities accurately and maintain complete, audit-ready evidence.
- Ability to organize data, identify exceptions, analyze aging and trends, and escalate issues based on risk and urgency.
- Familiarity with user-access administration, access reviews and the importance of segregation of duties.
- Basic understanding of vulnerability management, system hardening, security monitoring and remediation tracking.
- Basic understanding of business continuity, technology capacity and performance-management concepts.
- Strong written and oral communication skills, including the ability to prepare clear reports, procedures, trackers and meeting notes.
- Strong organizational, problem-solving and analytical skills with acute attention to detail.
- Ability to manage priorities and workflow across two functional areas and adapt to audit cycles, incidents and changing business needs.
- Ability to work independently with general direction and collaboratively with IT, Information Security, audit, risk, business and management stakeholders.
- Ability to handle confidential information responsibly and maintain professional judgment.
- Commitment to continuous learning in technology risk, cybersecurity, control frameworks, automation and emerging technologies.
FUNCTIONAL AND TECHNICAL KNOWLEDGE
- Security monitoring and daily control checklists.
- Access administration, access-review evidence and recertification tracking.
- Audit and regulatory evidence collection, indexing, version control and response tracking.
- Vulnerability, remediation and penetration-test recommendation tracking.
- Policy, procedure, standard and operational-document maintenance.
- Business continuity documentation and exercise support.
- Infrastructure capacity and performance reporting.
- Process mapping, workflow documentation, dashboards and basic automation concepts.
- Technology-risk issues associated with SaaS/cloud services, third parties, Shadow IT, AI/GenAI and system hardening.
- Use of spreadsheets, shared trackers, reporting tools, ticketing/workflow platforms and document repositories.
CORE COMPETENCIES
- Analytical - Synthesizes information from reports, evidence, trackers and stakeholder input; identifies exceptions, trends and unresolved risks.
- Control Mindset- Follows approved procedures, preserves evidence, understands approval boundaries and escalates deviations or potential control gaps.
- Problem Solving - Identifies issues in a timely manner, gathers relevant facts, proposes practical next steps and seeks
assistance when decisions exceed the role’s authority.
- Technical Skills- Builds knowledge through training and hands-on experience; uses technology tools effectively and documents repeatable methods for others.
- Communication - Presents information clearly, asks focused questions, documents decisions and tailors updates to technical and non-technical audiences.
- Teamwork - Balances shared priorities, welcomes feedback and contributes positively across IT, Information Security and other functions.
- Adaptability - Responds constructively to changing priorities, incidents, audit requests, regulatory deadlines and unexpected events.
- Dependability - Takes responsibility for assigned actions, keeps commitments, meets deadlines and provides timely notice when plans must change.
- Initiative - Looks for opportunities to improve documentation, reduce manual work, strengthen controls and build reusable knowledge.
- Attention to Detail - Maintains accurate records, validates completeness and protects the quality and traceability of control evidence.
KEY PERFORMANCE EXPECTATIONS
- Complete and evidence the approved daily monitoring checklist, with timely escalation of significant exceptions.
- Issue assigned recurring reports according to the approved calendar or escalate anticipated delays before the due date.
- Support completion of access recertifications by the established deadline and maintain complete supporting evidence.
- Maintain at least 90% of standard audit evidence in an organized, current and readily retrievable state.
- Maintain owners and target dates for assigned vulnerability and remediation items and support progressive reduction of aged open items.
- Support a 50% reduction of the assigned policy and procedure backlog within nine months and document at least two approved automation use cases within twelve months.
EDUCATION AND EXPERIENCE
- Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, Technology Risk, Business, or a related
field, or equivalent relevant experience.
- Early-career experience in technology risk, IT operations, information security, audit, compliance or internal controls is preferred. Relevant internship, academic or project experience may be considered.
- Foundational training or certification in cybersecurity, IT service management, risk, audit or control frameworks is a plus.
- Experience preparing reports, maintaining trackers, organizing evidence or documenting processes is preferred.
- Bilingual English& Spanish.
PERSONAL RESPONSIBILITIES
- Proven ability to handle multiple assignments and meet deadlines.
- Maintains awareness of contemporary standards, practices, procedures and methods related to technology risk and cybersecurity.
- Exercises good judgment and makes timely, sound recommendations within the authority of the role.
- Works on assignments with general direction and requests guidance when risk, approval or ownership decisions are required.
- Effectively presents information and responds to questions from stakeholders at different organizational levels.
- Must be able to speak, read, write and understand the primary language used in the workplace.
- Works effectively with a diverse range of individuals and maintains a service-oriented, professional approach.
- Protects confidential, customer, employee and company information in accordance with applicable requirements.
- Abides by the company’s Code of Conduct, operational and general policies and procedures, and all applicable laws, rules and regulations, including requirements related to the Bank Secrecy Act, Anti-Money Laundering, Know Your Customer, Suspicious Activity reporting and the Office of Foreign Assets Control.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search