
IT Risk & Control Senior Analyst, NYC
Overview
Own the fit-for-purpose review and challenge of internal IT controls in a complex cyber environment. Partner with engineering and security teams to enforce policies and standards across cloud and on-premise infrastructure. This contract role in NYC drives cyber risk mitigation with direct impact on audit readiness and compliance.
What You'll Do6
- 1Review and challenge internal IT controls to align with policies and standards
- 2Create recommendations for cyber risk mitigation in complex technical environments
- 3Drive fit-for-purpose assessments of control design and operating effectiveness
- 4Partner with security teams to remediate control gaps and strengthen audit posture
- 5Document control evidence and support internal audit engagements
- 6Monitor emerging threats and adjust control frameworks accordingly
Requirements6
- 15+ years in IT risk, control, or cybersecurity audit
- 2Hands-on expertise with NIST or ISO 27001 frameworks
- 3Experience with GRC tools for risk tracking
- 4Strong knowledge of IT general controls and SOX
- 5Bachelor's degree in IT, cybersecurity, or related field
- 6Relevant certifications such as CISA, CISM, or CISSP
Salary Insight
Salary not disclosed in listing
Similar open positions
Explore active roles that match your skills and interests.

Icon International Group LLC
VerifiedIT Risk Consultant, Technology Risk & GRC
You will own technology risk management for enterprise applications and architecture at Icon International Group LLC, embedding controls across the SDLC. You will partner with control owners to design, review, and strengthen technology controls, working in a hybrid model from New York. This 6-month contract offers direct influence over GRC, RCSA, and control frameworks.
Selective Insurance Company of America
VerifiedVulnerability Management Specialist - GRC
You will own the governance, risk, and compliance (GRC) activities for a midsized property and casualty insurer with 100 years of financial stability. You will assess third-party risk, manage vulnerability governance, and support audit and compliance efforts across NIST CSF, NYDFS, and ISO 27001. You will work with technology and risk stakeholders to track remediation and produce clear reporting. This role offers hybrid work in New York and a clear path for growth in a Forbes Best Midsize Employer.
LPL Financial Corp
VerifiedAnalyst II Tech Governance & Assurance
We seek a skilled IT Risk & Controls professional to lead our first line of defense in IT compliance. You will own daily readiness testing and audit facilitation for critical programs like SOX SOC 1 SOC 2 CCPA/CPRA cybersecurity audits and NYDFS attestation. This hands-on role embeds within control owners to perform self-testing and drive automation reducing manual effort. Expect collaboration with IT Engineering Security and external auditors to maintain audit readiness year-round.
Beacon Staffing
VerifiedIT Risk and Compliance Analyst - Beacon Staffing
Lead ownership of IT governance and compliance initiatives at Beacon Staffing. Own development of controls and drive continuous monitoring. Impact visibility across 2-3 days weekly onsite. Differentiate through expertise in SOX and COSO frameworks.

Javen Technologies, Inc
VerifiedSenior IT Risk and Compliance Analyst - GRC Framework Expertise
Lead ownership of IT governance alignment supporting Bank's GRC framework Enterprise Risk Management and Sarbanes-Oxley compliance. Drive improvements through collaboration with IT staff. Analyze technology risks and develop appropriate controls. Stand out by delivering measurable risk reduction outcomes within first 90 days.
PricewaterhouseCoopers Advisory Services LLC
VerifiedCyber Strategy Manager, Compliance & Risk
You will lead cyber strategy and transformation engagements, guiding clients through complex regulatory landscapes and enhancing internal controls. In this role, you will own project delivery, from planning to execution, while mentoring junior staff and collaborating with senior stakeholders. You will implement frameworks like NIST CSF and ISO/IEC 27001 to strengthen data protection and compliance. This position offers exposure to high-impact client work across industries, with up to 60% travel and a focus on innovation and technology adoption.