Senior Analyst, IT Risk

Posted 17 Days Ago
Be an Early Applicant
Long Island, AL
In-Office
122K-136K Annually
Senior level
Financial Services
The Role
The Sr. IT Risk Analyst focuses on enhancing technology risk management, audit coordination, and controls. Responsibilities include coordinating audits, assessing technology risks, and compliance with regulatory standards.
Summary Generated by Built In

Join our team - and take the next step in achieving a fulfilling career!

What We Do

At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most.

Who We Are

CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC.

CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans.  We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.

Merrick Bank is an FDIC-insured Utah Industrial Loan BankMerrick operates three main business lines:  credit cards, recreational lending, and merchant services.

Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.

Position Summary:

The Senior Analyst, IT Risk is responsible for supporting and enhancing the organization’s technology risk management, audit coordination, and IT control framework. This role partners closely with Internal Audit, Compliance, Technology, and business stakeholders to ensure regulatory readiness, effective control operation, and timely remediation of findings. The ideal candidate has a strong understanding of technology risks, audit processes, IT general controls, and information security principles.

Essential Functions:

Audit & Regulatory Coordination

  • Coordinate audit preparation activities—including scheduling, evidence collection, and stakeholder communication—for internal audits and regulatory examinations (e.g., FDIC, SOX, SOC, and other technology-focused reviews).
  • Serve as the primary liaison between Internal Audit, IT, and Compliance teams to ensure timely and accurate responses to audit inquiries.
  • Oversee and track remediation activities; validate completion and effectiveness of corrective actions for technology-related audit findings.
  • Participate in readiness assessments and pre-audit walkthroughs to identify issues before formal reviews begin.

Technology Risk Assessment & Control Evaluation

  • Conduct comprehensive Technology Risk Assessments, identifying inherent and residual risks across infrastructure, applications, security, and cloud environments.
  • Evaluate the design and operating effectiveness of technology controls, including IT General Controls (ITGCs), logical access, change management, operations, and security controls.
  • Perform independent control testing to verify compliance with policies, standards, and regulatory requirements.
  • Advise IT leadership on control gaps, deficiencies, risks, and recommended remediation strategies.

Governance, Risk, and Compliance (GRC) Support

  • Provide risk insights for new initiatives, technology implementations, cloud migrations, and major IT projects.
  • Support enhancements to the IT risk management framework, control library, and GRC tooling.
  • Monitor emerging technology risks and collaborate with stakeholders to develop mitigating controls.
  • Contribute to the development and maintenance of IT policies, standards, and procedures.

Education and Experience:

Required:

  • Bachelor’s degree in information technology, Cybersecurity, Risk Management, or related field (or equivalent experience).
  • 5-10+ years of experience in IT risk, audit, information security, or technology governance.
  • Strong knowledge of IT controls frameworks (e.g., COBIT, NIST, ISO 27001) and regulatory requirements (SOX, FFIEC, SOC, etc.).
  • Experience working with audit functions and responding to regulatory reviews.
  • Ability to analyze control gaps and articulate risks clearly to technical and non-technical stakeholders.

Preferred:

  • Professional certifications such as CISA, CRISC, CISSP, CIA, or similar.
  • Experience with GRC platforms (e.g., Archer, ServiceNow GRC, MetricStream).
  • Familiarity with cloud technologies (AWS, Azure, GCP) and related risk assessments.
  • Prior first line Technology experience.

Summary of Qualifications:

  • Strong analytical and problem-solving skills
  • Excellent communication and documentation abilities
  • Detail-oriented with strong organizational skills
  • Ability to manage multiple concurrent audits and priorities
  • Collaborative mindset with the ability to work across IT, audit, and compliance functions
  • Occasional travel may be required

Ideally, the qualified candidate will work at the following location: Woodbury, NY. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role.

The salary range for this position, if located in NY Metro/NY State is $122,309 to $135,899. However, please note that the salary range will vary for other geographic areas.

#INDHP

Our Employee Value Proposition

  • Competitive Pay, including a Bonus Target or Variable Pay Incentive Program 
  • Benefits Package -Medical, Dental, and Vision (plus much more) 
  • 401(k) Plan with Company Match 
  • Short- & Long-Term Disability 
  • Wellness Programs 
  • Group Life and AD&D Insurance 
  • Paid Vacation, Sick Days and bank Holidays 
  • Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition

We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite.  Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.

We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic.  We will conduct a thorough background check for all hires in compliance with applicable laws.

Top Skills

AWS
Azure
Cobit
Ffiec
GCP
Grc Platforms
Iso 27001
It Risk Frameworks
Nist
Regulatory Requirements
Soc
Sox
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Woodbury, NY
730 Employees
Year Founded: 1987

What We Do

Cardworks is one of the largest privately held providers of end-to-end operational servicing and support functions for credit card and installment loan products in North America.

As a leading consumer firm, we service our consumer and small business loan clients across the credit spectrum, from super-prime to non-prime, and provide comprehensive support to bank and non-bank lenders in the United States and Canada. Our management expertise and customized servicing solutions enable banks and financial institutions to mitigate risk, increase profitability, and support their customers.

Cardworks is also the parent of Merrick Bank Corporation, a top-15 issuer of credit cards, top 15 merchant acquiring bank, and leader in the recreational vehicle lending industry.

As a CardWorks employee, you are at the very heart of all that we do. Our corporate success is based on your contributions. The most valuable resource we have at CardWorks is our employees. Each individual has an impact on how well we execute and on whether we achieve our enterprise objectives

Similar Jobs

Order.co Logo Order.co

Event Marketer

eCommerce • Fintech • Payments • Software
Remote or Hybrid
United States
119 Employees
90K-110K Annually

Order.co Logo Order.co

Consultant

eCommerce • Fintech • Payments • Software
Remote or Hybrid
United States
119 Employees
80K-100K Annually

Order.co Logo Order.co

Customer Success Manager

eCommerce • Fintech • Payments • Software
Remote or Hybrid
United States
119 Employees
80K-100K Annually

CrowdStrike Logo CrowdStrike

Architect

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
135K-205K Annually

Similar Companies Hiring

Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Rain Thumbnail
Web3 • Payments • Infrastructure as a Service (IaaS) • Fintech • Financial Services • Cryptocurrency • Blockchain
New York, NY
80 Employees
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account