Risk Control Self-Assessment CoordinatorPlan and facilitate RCSA workshops, document outcomes, assign action owners, and track open items through resolution.Review RCSA documentation to confirm risks and controls are clearly defined, properly mapped, current, and supported.Identify missing, outdated, duplicative, or unclear controls and coordinate remediation with Technology and First Line of Defense teams.Draft and enhance control language so controls clearly identify the activity, owner, frequency, scope, evidence, and expected outcome.Review testing scripts for alignment with control objectives, evidence requirements, populations, sampling methods, and expected results.Recommend testing-script improvements and support control testing, evidence review, exception documentation, and results validation when needed.Maintain Risk and Control Matrix inventories and help update process maps, control libraries, ownership, system linkages, and testing requirements.Maintain traceability across RCSA documentation, controls, testing scripts, issues, process maps, and change records.Coordinate stakeholder reviews, approvals, version control, change logs, and implementation tracking.Required Experience and Qualifications8+ years of experience in technology risk, IT controls, operational risk, RCSA, control testing, internal audit, risk governance, or a related field.Strong understanding of RCSA methodology, control design, testing, issue management, and remediation.Experience facilitating workshops and walkthroughs with Technology stakeholders, control owners, process owners, and First Line of Defense teams.Strong experience reviewing risk and control documentation, identifying gaps, and improving control language for clarity, testability, and auditability.Experience reviewing testing scripts and recommending practical improvements.Familiarity with Risk and Control Matrices, process mapping, control libraries, risk taxonomies, and change management.Knowledge of technology control areas such as access management, cybersecurity, infrastructure, applications, data protection, IT operations, change management, and third-party risk.Strong analytical, documentation, communication, and stakeholder-management skills.Ability to translate technical processes into clear risk and control language, manage multiple deliverables, and meet deadlines.Preferred CertificationsCISA, CRISC, CIA, CISM, CISSP, CGEIT, COBIT, ITIL, ISO 27001, or relevant cloud security certifications.
IT Risk & Controls Analyst in washington at Unknown Company
This position is listed as full time and onsite.