Location & Work Arrangement
This position follows a hybrid work schedule. Candidates must be able and willing to work onsite 4 days per week from one of the following hub locations:
• Johnston, RI
• Westwood, MA
• Boston, MA
• Iselin, NJ
Remote work is not available for this position.
First Line Risk AnalystDescriptionAt Citizens, we believe in creating opportunities for growth and development.
As a First Line Risk Analyst, you will support the execution of control monitoring and testing activities designed to assess the effectiveness of the Enterprise Technology & Security (ETS) risk and control environment. Working closely with business partners and First Line Risk Managers, you will evaluate key controls, monitor risk indicators, support Risk and Control Self-Assessments (RCSAs), and contribute to risk reporting and governance activities.
In this role, you will help identify potential control gaps, support issue remediation efforts, and provide analysis that strengthens risk management practices. You will gain exposure to technology risk frameworks, cybersecurity controls, cloud services, regulatory requirements, and continuous monitoring processes while developing expertise in risk management and control testing.
Primary Responsibilities- Execute control monitoring and testing activities in accordance with established methodologies and timelines.
- Assess technology and operational controls to identify potential risks, control gaps, and areas for improvement.
- Monitor and report Key Risk Indicators (KRIs) and Key Control Indicators (KCIs).
- Maintain Risk and Control Self-Assessments (RCSAs), process maps, and supporting documentation within designated systems of record.
- Contribute to the development of risk dashboards, management reporting, and control monitoring metrics.
- Document and track control issues, remediation activities, and corrective action plans.
- Analyze testing results and control performance data to identify trends and opportunities to enhance control effectiveness.
- Partner with business stakeholders and First Line Risk Managers to support risk management initiatives and governance activities.
- Support audit, regulatory, compliance, and issue management activities.
- Assist in evaluating controls related to information security, cybersecurity, infrastructure, cloud services, and DevSecOps environments.
- Bachelor's degree in Information Technology, Cybersecurity, Business, Risk Management, Information Systems, Finance, or a related field, or equivalent work experience.
- 2+ years of experience in technology risk, information security, cybersecurity, audit, compliance, controls, operational risk, or related functions.
- Knowledge of information security, cybersecurity, infrastructure, cloud operations, software development lifecycle (SDLC) methodologies, and/or DevSecOps practices.
- Understanding of cloud-based service models including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
- Working knowledge of risk and control frameworks such as NIST 800-53, NIST Cybersecurity Framework (CSF), COBIT, ITIL, or similar standards.
- Strong analytical and problem-solving skills with the ability to interpret complex data and translate findings into actionable insights.
- Ability to manage multiple priorities and meet deadlines with minimal oversight.
- Strong written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders.
- Proficiency with Microsoft Excel, Word, and PowerPoint.
- Ability to work independently and collaboratively within a team environment.
- Experience supporting control testing, control monitoring, risk assessments, audit, compliance, or risk management programs.
- Experience with Governance, Risk, and Compliance (GRC) platforms such as Archer.
- Familiarity with ServiceNow, Jira, or similar IT service management tools.
- Exposure to security and monitoring tools such as Splunk, Qualys, DataDog, Wiz, CyberArk, or similar technologies.
- Experience with cloud platforms such as AWS and/or Microsoft Azure.
- Familiarity with reporting and visualization tools such as Power BI or Tableau.
- Experience using data and metrics to support risk-based decision making.
- Exposure to Python or other analytical tools.
- Experience working in a regulated industry, preferably financial services.
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- CISM (Certified Information Security Manager)
- AWS Cloud Practitioner
- Microsoft Azure Fundamentals
Education
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, Information Systems, or a related field, or equivalent work experience.
We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens’ paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.
About Us
Equal Employment Opportunity
Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.
Equal Employment and Opportunity Employer
Job Applicant Data Privacy Policy
Background Check
Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.
Skills Required
- Bachelor's degree in IT, Cybersecurity, Risk Management, Information Systems, Finance, or related field (or equivalent work experience).
- 2+ years experience in technology risk, information security, cybersecurity, audit, compliance, controls, or operational risk.
- Knowledge of information security, cybersecurity, infrastructure, cloud operations, SDLC methodologies, and/or DevSecOps practices.
- Understanding of cloud-based service models (IaaS, PaaS, SaaS).
- Working knowledge of risk and control frameworks such as NIST 800-53, NIST CSF, COBIT, or ITIL.
- Strong analytical and problem-solving skills; ability to interpret complex data and provide actionable insights.
- Ability to manage multiple priorities and meet deadlines with minimal oversight.
- Strong written and verbal communication skills; able to explain technical concepts to non-technical stakeholders.
- Proficiency with Microsoft Excel, Word, and PowerPoint.
- Ability to work independently and collaboratively within a team environment.
- Experience supporting control testing, control monitoring, risk assessments, audit, compliance, or risk management programs.
- Experience with GRC platforms (e.g., Archer); familiarity with ServiceNow, Jira, or similar ITSM tools.
- Exposure to security and monitoring tools (e.g., Splunk, Qualys, Datadog, Wiz, CyberArk).
- Experience with cloud platforms such as AWS and/or Microsoft Azure.
- Familiarity with reporting and visualization tools such as Power BI or Tableau.
- Exposure to Python or other analytical tools.
- Experience working in a regulated industry, preferably financial services.
- Preferred certifications: CISA, CRISC, CISM, AWS Cloud Practitioner, Microsoft Azure Fundamentals.
Citizens Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Citizens and has not been reviewed or approved by Citizens.
-
Parental & Family Support — Parental leave is described as six weeks at 100% pay for all new parents, with up to 16 weeks for birthing parents. Family-building and caregiving supports include more than $25,000 in adoption assistance and up to 10 days of backup care.
-
Leave & Time Off Breadth — Time off includes 11 paid holidays and up to 27 PTO days, with materials encouraging employees to use their time. This breadth is frequently positioned as a core strength of the total rewards package.
-
Fair & Transparent Compensation — Pay practices are presented as equitable, with disclosures citing near-parity by gender and no gaps for people of color in similar roles. Transparency shows up in posted hourly ranges for retail roles, and some markets list banker pay at competitive levels.
Citizens Insights
What We Do
As one of the oldest and largest financial services firms in the United States with a history dating back to 1828, we’re committed to providing solutions and expertise that support our customers, clients, colleagues, and communities in what’s next on their own unique journey. We invest in the humans who build the logic, ideas, and innovations that bring new technologies to life. Investments in AI, cloud computing, machine learning and automation provide our engineers the tools that enable us to remain competitive and win in today’s environment. At Citizens, we recognize that the journey to accomplishment is no longer linear and that individuals are made of all they have done and all they are going to do. Whether you’re considering banking with us or looking to work with us, you’ll find a customer-centric culture and a supportive, collaborative workforce at Citizens. You’re made ready and so are we. If you're ready to advance your career in technology and security, learn more about opportunity's Citizens offers here: https://jobs.citizensbank.com/digital-transformation
Why Work With Us
We empower the colleagues that power our tech. With growth & upskilling opportunities and sought-after benefits, plus a diverse culture of people and perspectives, we help our colleagues achieve career goals. Because innovation can’t happen without the minds and hearts of our people. Technology is constantly evolving, and we believe you can too.
Gallery







