First Line Risk Analyst
Citizens Financial
- Location
- United States
- Work model
- Hybrid
- Level
- Mid
- H-1B history
- 87 approvals (FY2023)
- Posted
- 15h ago
Skills
About this role
Location & Work Arrangement This position follows a hybrid work schedule. Candidates must be able and willing to work onsite 4 days per week from one of the following hub locations: • Johnston, RI • Westwood, MA • Boston, MA • Iselin, NJ Remote work is not available for this position. First Line Risk Analyst Description At Citizens, we believe in creating opportunities for growth and development. As a First Line Risk Analyst, you will support the execution of control monitoring and testing activities designed to assess the effectiveness of the Enterprise Technology & Security (ETS) risk and control environment. Working closely with business partners and First Line Risk Managers, you will evaluate key controls, monitor risk indicators, support Risk and Control Self-Assessments (RCSAs), and contribute to risk reporting and governance activities. In this role, you will help identify potential control gaps, support issue remediation efforts, and provide analysis that strengthens risk management practices. You will gain exposure to technology risk frameworks, cybersecurity controls, cloud services, regulatory requirements, and continuous monitoring processes while developing expertise in risk management and control testing.
Primary Responsibilities
Execute control monitoring and testing activities in accordance with established methodologies and timelines. Assess technology and operational controls to identify potential risks, control gaps, and areas for improvement. Monitor and report Key Risk Indicators (KRIs) and Key Control Indicators (KCIs). Maintain Risk and Control Self-Assessments (RCSAs), process maps, and supporting documentation within designated systems of record. Contribute to the development of risk dashboards, management reporting, and control monitoring metrics. Document and track control issues, remediation activities, and corrective action plans. Analyze testing results and control performance data to identify trends and opportunities to enhance control effectiveness. Partner with business stakeholders and First Line Risk Managers to support risk management initiatives and governance activities. Support audit, regulatory, compliance, and issue management activities. Assist in evaluating controls related to information security, cybersecurity, infrastructure, cloud services, and DevSecOps environments.
Required Qualifications
Bachelor's degree in Information Technology, Cybersecurity, Business, Risk Management, Information Systems, Finance, or a related field, or equivalent work experience. 2+ years of experience in technology risk, information security, cybersecurity, audit, compliance, controls, operational risk, or related functions. Knowledge of information security, cybersecurity, infrastructure, cloud operations, software development lifecycle (SDLC) methodologies, and/or DevSecOps practices. Understanding of cloud-based service models including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Working knowledge of risk and control frameworks such as NIST 800-53, NIST Cybersecurity Framework (CSF), COBIT, ITIL, or similar standards. Strong analytical and problem-solving skills with the ability to interpret complex data and translate findings into actionable insights. Ability to manage multiple priorities and meet deadlines with minimal oversight. Strong written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders. Proficiency with Microsoft Excel, Word, and PowerPoint. Ability to work independently and collaboratively within a team environment.
Preferred Qualifications
Experience supporting control testing, control monitoring, risk assessments, audit, compliance, or risk management programs. Experience with Governance, Risk, and Compliance (GRC) platforms such as Archer. Familiarity with ServiceNow, Jira, or similar IT service management tools. Exposure to security and monitoring tools