First Line Risk Analyst
Location & Work Arrangement
This position follows a hybrid work schedule. Candidates must be able and willing to work onsite 4 days per week from one of the following hub locations:
• Johnston, RI
• Westwood, MA
• Boston, MA
• Iselin, NJ
Remote work is not available for this position.
First Line Risk Analyst
Description
At Citizens, we believe in creating opportunities for growth and development.
As a First Line Risk Analyst, you will support the execution of control monitoring and testing activities designed to assess the effectiveness of the Enterprise Technology & Security (ETS) risk and control environment. Working closely with business partners and First Line Risk Managers, you will evaluate key controls, monitor risk indicators, support Risk and Control Self-Assessments (RCSAs), and contribute to risk reporting and governance activities.
In this role, you will help identify potential control gaps, support issue remediation efforts, and provide analysis that strengthens risk management practices. You will gain exposure to technology risk frameworks, cybersecurity controls, cloud services, regulatory requirements, and continuous monitoring processes while developing expertise in risk management and control testing.
Primary Responsibilities
- Execute control monitoring and testing activities in accordance with established methodologies and timelines.
- Assess technology and operational controls to identify potential risks, control gaps, and areas for improvement.
- Monitor and report Key Risk Indicators (KRIs) and Key Control Indicators (KCIs).
- Maintain Risk and Control Self-Assessments (RCSAs), process maps, and supporting documentation within designated systems of record.
- Contribute to the development of risk dashboards, management reporting, and control monitoring metrics.
- Document and track control issues, remediation activities, and corrective action plans.
- Analyze testing results and control performance data to identify trends and opportunities to enhance control effectiveness.
- Partner with business stakeholders and First Line Risk Managers to support risk management initiatives and governance activities.
- Support audit, regulatory, compliance, and issue management activities.
- Assist in evaluating controls related to information security, cybersecurity, infrastructure, cloud services, and DevSecOps environments.
Required Qualifications
- Bachelor's degree in Information Technology, Cybersecurity, Business, Risk Management, Information Systems, Finance, or a related field, or equivalent work experience.
- 2+ years of experience in technology risk, information security, cybersecurity, audit, compliance, controls, operational risk, or related functions.
- Knowledge of information security, cybersecurity, infrastructure, cloud operations, software development lifecycle (SDLC) methodologies, and/or DevSecOps practices.
- Understanding of cloud-based service models including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
- Working knowledge of risk and control frameworks such as NIST 800-53, NIST Cybersecurity Framework (CSF), COBIT, ITIL, or similar standards.
- Strong analytical and problem-solving skills with the ability to interpret complex data and translate findings into actionable insights.
- Ability to manage multiple priorities and meet deadlines with minimal oversight.
- Strong written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders.
- Proficiency with Microsoft Excel, Word, and PowerPoint.
- Ability to work independently and collaboratively within a team environment.
Preferred Qualifications
- Experience supporting control testing, control monitoring, risk assessments, audit, compliance, or risk management programs.
- Experience with Governance, Risk, and Compliance (GRC) platforms such as Archer.
- Familiarity with ServiceNow, Jira, or similar IT service management tools.
- Exposure to security and monitoring tools such as Splunk, Qualys, DataDog, Wiz, CyberArk, or similar technologies.
- Experience with cloud platforms such as AWS and/or Microsoft Azure.
- Familiarity with reporting and visualization tools such as Power BI or Tableau.
- Experience using data and metrics to support risk-based decision making.
- Exposure to Python or other analytical tools.
- Experience working in a regulated industry, preferably financial services.
Preferred Certifications
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- CISM (Certified Information Security Manager)
- AWS Cloud Practitioner
- Microsoft Azure Fundamentals
Education
Bachelor's degree in Information Technology, Cybersecurity, Risk Management, Information Systems, or a related field, or equivalent work experience.
We offer competitive pay, comprehensive medical, dental, and vision coverage, retirement benefits, maternity and paternity leave, flexible work arrangements, education reimbursement, wellness programs, and more. Citizens’ paid time off policy exceeds the mandatory paid sick or paid time away policies of local and state jurisdictions in the United States. For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.