
Analyst - Business Risk Controls Management
Tiaa External Schroder InternalMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Conduct application risk assessments aligned with defined security frameworks (e.g., NIST CSF, ISO 27001) to identify and rate risks in enterprise applications.
Validate and track security controls, document findings, and follow remediation efforts with application owners.
Maintain accurate risk records in GRC tools and contribute to process improvements and assessment methodologies.
Minimum Requirements
3+ years of work experience required; 5+ years preferred.
1+ year experience in cybersecurity, risk, or application support.
Basic understanding of web applications, APIs, OWASP Top 10 vulnerabilities, and authentication/access control concepts.
Vocational and/or Technical education preferred; Work Experience Required: 3+ years explicitly mentioned.
Ideal Candidate Profile
Comfortable working at the intersection of technology and risk with ownership of application risk assessment tasks and clear communication of risks in business terms.
Demonstrated experience applying structured risk methodologies and frameworks in an operational environment.
Experience with GRC tools, security controls validation, and familiarity with cloud basics and secure SDLC practices preferred but not mandatory.
