
Analyst - Business Risk Controls Management
Tiaa SearchMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Conduct application risk assessments using established frameworks like NIST CSF and ISO 27001, influencing design decisions and security posture.
Validate security controls, identify and rate risks in enterprise applications, and manage remediation tracking.
Maintain accurate records in GRC tools and contribute to process improvements including playbooks and templates.
Minimum Requirements
Minimum 3 years of relevant work experience; 5+ years preferred.
At least 1 year experience in cybersecurity, risk, or application support.
Basic understanding of web applications, APIs, authentication, access control, and common vulnerabilities like OWASP Top 10.
Vocational and/or Technical Education preferred.
Ideal Candidate Profile
Skilled in translating technical security risks into business-friendly language with clear documentation and communication.
Experience working at the intersection of technology and risk within structured assessment methodologies.
Exposure to secure SDLC, cloud basics (AWS, Azure, GCP), risk frameworks (NIST CSF 2.0, ISO 27001), and GRC tools is advantageous.
