The Risk and Control Self-Assessment (RCSA) Sr. Risk Analyst will assist with the day-to-day management of the second line of defense RCSA program. This role is responsible for assessing the design and operating effectiveness of internal controls, in partnership with first and second line business process owners.
What you'll be doing
Execute Control Design Assessments, which includes conducting process walkthroughs and/or researching process documentationConduct Control Performance Testing, which includes an audit of control operations utilizing risk-based sampling methodologiesCreate test steps and a detailed evidence request listManage evidence requests to ensure timely turnaroundDocument testing and necessary criteria in professional workpapers, ensuring workpapers are adequately captionedConduct quality reviews of RCSA testing activitiesConfirm any control design or performance deficiencies with control ownersAssess the impact of control weaknesses and raise findings to RCSA managementPresent findings to process owners and manage timely remediation planningChallenge remediation plans, to ensure sustainable resolution of the root causeValidate finding closures and work with control owners to update risks and controlsPrepare and present comprehensive reports regarding RCSA managementOversee adherence to RCSA standards, including training internal departments on requirementsYou'll bring the following required skills and experiences
2-5 years experience in Risk, Auditing, Compliance, and/or Finance preferably in Financial Services organizationsExperience with COSO and ISO ERM/ORM frameworks and their application to internal controls is strongly preferredExperience in identifying, documenting, and testing internal controls is strongly preferredExperience with analyzing automated controls is favorableAbility to quickly absorb and comprehend information presented in various formats, adapting to new information and changing processes quickly and effectivelySkilled in analyzing information to identify patterns, relationships, and potential issues within a processSkilled in simultaneously managing multiple time-sensitive activitiesSkilled in strong detail-orientation and commitment to accuracyExperience with Google Sheets, Docs, and Slides or MS Excel is preferredExperience with a Governance, Risk, Compliance (GRC) tool; Archer IRM is preferred