ETS Risk Analyst II

Posted 2 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Mid level
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Ready to Transform the Future | Careers in Technology & Security
The Role
Execute technology and cybersecurity control monitoring and testing, assess control design and operating effectiveness, document audit-ready results, support remediation validation and issue management, analyze trends and KRI data, participate in RCSAs and process mapping, and drive automation and analytics to improve control coverage and risk insight.
Summary Generated by Built In

ETS Risk Analyst II – Monitoring and Testing

Role Overview

The Enterprise Technology & Security (ETS) Risk Analyst II plays a critical role in the identification, assessment, and mitigation of technology and security related risks across the organization. Working within a first-line risk team, this role partners directly with Risk Managers to execute control monitoring and testing that aligns with the bank's risk appetite framework, regulatory expectations, and industry standards including Cybersecurity Risk Institute (CRI) Profile, NIST 800-53, and NIST Cybersecurity Framework. You will independently assess control effectiveness, monitor key risk indicators, and analyze results to identify trends, control gaps, and areas for improvement. This role requires strong professional judgment, high quality documentation, and timely communication to support a resilient control environment and informed risk decisions. This is an excellent opportunity for an early-career risk professional looking to build foundational expertise in technology and security risk within a growing regulated financial institution.

Responsibilities

  • Partner with Risk Managers to execute the control monitoring and testing program across multiple complex technology and cybersecurity processes.

  • Independently perform control design and operating effectiveness testing in accordance with established methodologies and timelines.

  • Assess material controls and determine whether enhanced controls are effective to support issue validation and closure.

  • Document testing results clearly and accurately in the system of record and supporting tools, producing audit ready documentation suitable for QA, Internal Audit, and Regulatory review.

  • Support the analysis of monitoring and testing results to identify themes, trends, root causes, and emerging issues.

  • Escalate control deficiencies, emerging risks, and potential delays in a timely and professional manner.

  • Support issue management activities, including testing to validate remediation and support issue closure 

  • Participate in Risk and Control Self Assessments (RCSAs), including creation and validation of process maps that reflect key processes, risks, and controls 

  • Maintain awareness of emerging risks and evolving technologies (e.g., artificial intelligence, automation, and data driven processes) and assess their impact on control design, effectiveness, and monitoring approaches.

  • Contribute to the continuous monitoring program by leveraging automated testing, key control metrics, and trend analysis to improve risk insight and control coverage.

  • Identify, evaluate, and prioritize opportunities to enhance control testing through automation, data analytics, and improved key control metrics, partnering with stakeholders to support implementation.

  • Build effective working relationships with business and technology stakeholders to stay informed of process changes and emerging risks.

  • Develop understanding of internal policies, infrastructure processes, and evolving industry risk trends.

  • Proactively pursue ongoing professional development, including relevant certifications, industry training, etc. to maintain current knowledge in a rapidly evolving field.

Experience & Skills

Required:

  • 3–5 years of experience in IT, information security, risk management, or internal audit.

  • Foundational understanding of technology risk concepts, control frameworks (NIST 800-53, NIST CSF, CRI Profile, COBIT, or ITIL), and risk management lifecycle.

  • Familiarity with GRC platforms (e.g., Archer) and IT service management tools (e.g., ServiceNow, Jira).

  • Ability to analyze and interpret data from security and operational monitoring tools.

  • Strong written and verbal communication skills, with the ability to translate technical risk findings into clear documentation.

  • Demonstrated ability to manage multiple priorities in a fast-paced environment with attention to detail.

  • Proficiency in Microsoft Office Suite (Excel, Word, PowerPoint).

 

Preferred:

  • Experience in a regulated financial services or banking environment.

  • Familiarity with cloud environments (AWS, Azure) or infrastructure risk concepts.

  • Exposure to audit response, regulatory exam support, or corrective action tracking.

 

Education

  • Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field required.

  • One or more of the following certifications are preferred:
  • CompTIA Security+
  • AWS Cloud Practitioner or Microsoft Azure Fundamentals

  • CISA (Certified Information Systems Auditor)

  • CRISC (Certified in Risk and Information Systems Control)

Hours & Work Schedule

  • Hours per Week: 40
  • Work Schedule: Monday - Friday
  • Hybrid: 4 days per week onsite
About Us

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Equal Employment and Opportunity Employer

Job Applicant Data Privacy Policy

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.


Skills Required

  • 3-5 years of experience in IT, information security, risk management, or internal audit
  • Foundational understanding of technology risk concepts and control frameworks (NIST 800-53, NIST CSF, CRI Profile, COBIT, or ITIL)
  • Familiarity with GRC platforms (e.g., Archer) and IT service management tools (e.g., ServiceNow, Jira)
  • Ability to analyze and interpret data from security and operational monitoring tools
  • Strong written and verbal communication skills, with ability to translate technical risk findings into clear documentation
  • Demonstrated ability to manage multiple priorities with attention to detail
  • Proficiency in Microsoft Office Suite (Excel, Word, PowerPoint)
  • Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field
  • Experience in a regulated financial services or banking environment
  • Familiarity with cloud environments (AWS, Azure) or infrastructure risk concepts
  • Exposure to audit response, regulatory exam support, or corrective action tracking
  • Certifications such as CompTIA Security+, AWS Cloud Practitioner, Microsoft Azure Fundamentals, CISA, or CRISC

Citizens Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Citizens and has not been reviewed or approved by Citizens.

  • Healthcare Strength Healthcare coverage is positioned as comprehensive, with multiple plan options and preventive care highlighted as fully covered. Mental-health support is also emphasized through EAP-style counseling access and app-based support.
  • Retirement Support Retirement benefits are described as meaningful, including an employer match and additional company contributions in some descriptions. Stock purchase features and occasional profit-sharing framing add to the overall retirement-and-wealth picture.
  • Leave & Time Off Breadth Time-off benefits are described as generous, including a substantial PTO bank, paid holidays, and sizeable parental leave. Adoption assistance and emergency backup care are also presented as part of the leave-related support set.

Citizens Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Providence, RI
17,000 Employees
Year Founded: 1828

What We Do

As one of the oldest and largest financial services firms in the United States with a history dating back to 1828, we’re committed to providing solutions and expertise that support our customers, clients, colleagues, and communities in what’s next on their own unique journey. We invest in the humans who build the logic, ideas, and innovations that bring new technologies to life. Investments in AI, cloud computing, machine learning and automation provide our engineers the tools that enable us to remain competitive and win in today’s environment. At Citizens, we recognize that the journey to accomplishment is no longer linear and that individuals are made of all they have done and all they are going to do. Whether you’re considering banking with us or looking to work with us, you’ll find a customer-centric culture and a supportive, collaborative workforce at Citizens. You’re made ready and so are we. If you're ready to advance your career in technology and security, learn more about opportunity's Citizens offers here: https://jobs.citizensbank.com/digital-transformation

Why Work With Us

We empower the colleagues that power our tech. With growth & upskilling opportunities and sought-after benefits, plus a diverse culture of people and perspectives, we help our colleagues achieve career goals. Because innovation can’t happen without the minds and hearts of our people. Technology is constantly evolving, and we believe you can too.

Gallery

Gallery

Similar Jobs

Sailor Health Logo Sailor Health

RN Healthcare Advocate (Remote)

Healthtech • Social Impact • Telehealth
Remote
United States
20 Employees
40-40 Hourly

Sailor Health Logo Sailor Health

Founding Engineer (Senior/Staff)

Healthtech • Social Impact • Telehealth
Remote
United States
20 Employees

Sailor Health Logo Sailor Health

Founding Engineer

Healthtech • Social Impact • Telehealth
Remote
United States
20 Employees

Shift Group Logo Shift Group

Business Development Representative

HR Tech • Sales • Social Impact • Software • Sports
Remote or Hybrid
Boston, MA, USA

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account