IT Risk (2LOD) -SOX + Cyber Governance + IAM/PAM + Cloud Security + AI Governance + Control Testing // Only USC,GC // W2 ROLE // Only …

September 9, 2026

Job Description

Company: CloudIngest

Location: NC, US

Role: IT Risk & Control Senior Analyst (Second Line of Defence)

60 W2 and 65 C2C – lil higher is ok

Location: Hybrid – 4 days onsite in NYC/Jersey City, NJ (Charlotte or Phoenix also acceptable) Eligibility: Green Card / US Citizen only

Experience: 8-12 yrs

Industry: Banking/Financial Services

This role is all about control testing review and challenge. The analyst will independently validate 1LOD testing (ToD/ToE), conduct PRC reviews, and provide objective risk assessments to leadership, auditors, and regulators. Requires 8-12+ years in IT/cyber risk, strong audit/control testing experience, and financial services background. Hybrid 4 days in NYC/Jersey City. PS – This has to be a HANDS on role , They have to know end to end Control testing. Key Responsibilities Act as second line of defence for IT risk and cyber security controls. Perform heavy control testing (Test of Design, Test of Effectiveness). Conduct Process/Risk/Control (PRC) reviews to evaluate control program effectiveness. Provide guidance and challenge to 1LOD testing teams to ensure practices meet standards. Support regulatory deliverables and compliance requirements. Define analysis objectives, collect/evaluate data, and provide objective cyber risk reporting for IT/business leadership. Author detailed reports and gather metrics for auditors, regulators, and external parties. Stay current on cyber security threats, trends, and technologies. Collaborate with other teams on cyber risk initiatives and provide recommendations. Manage site-level governance: track actions, risks, issues, dependencies, decisions, and readiness items. Required Qualifications 10–15 years in Information/Cyber Security, with strong IT risk management background. 6+ years in cyber security operations, incident response, IT risk management, or investigations. Prior IT Control Audit experience (heavy control testing focus). Strong banking/financial industry experience. Knowledge of financial regulation and control frameworks (FAIR, NIST CSF, SOX, etc.). Deep understanding of cyber security landscape (threats, trends, technologies). Excellent communication and interpersonal skills to build strong stakeholder relationships. Team-oriented, customer service mindset. Summary The client is seeking a seasoned IT Risk & Control professional who can operate as the second line of defence, with heavy control testing experience and a strong banking background. The role requires someone who can challenge 1LOD testing practices, ensure compliance with regulatory frameworks, and provide objective risk reporting to leadership. Hybrid onsite presence (4 days) is mandatory in NYC/Jersey City, with flexibility for Charlotte or Phoenix.

Skills· Banking

Source: LinkedIn