About this role
ITGC Risk Analyst (Hybrid - Columbia, SC)
The ITGC Risk Analyst supports the organization's information technology control environment by coordinating control assessments, audit activities, and risk-based reviews. The role independently evaluates the design and operating effectiveness of moderately complex information technology controls, validates supporting evidence, communicates control gaps and expectations, and monitors remediation through closure. Working with control owners, business units, and assurance teams, the analyst contributes to team and departmental control outcomes.
What You'll Do
IT Control and Audit Coordination
- Coordinate information technology general control and service organization control walkthroughs, testing support, and related audit activities.
- Review control ownership, control design, and alignment with current business and technology operations.
- Evaluate control submissions and complete risk-based assessments of control documentation and evidence.
- Manage the collection, validation, organization, and timely submission of audit and assessment evidence.
- Track identified findings and partner with responsible stakeholders to support timely remediation and closure.
Risk Review and Control Assurance
- Perform independent review and challenge of moderately complex control design, implementation, and operating effectiveness.
- Assess control risk, identify gaps or inconsistencies, and document supportable conclusions.
- Validate control testing activities and confirm alignment with established program standards and requirements.
- Communicate expectations, assessment results, and identified gaps clearly to control owners and stakeholders.
- Recommend practical improvements that strengthen control execution and documentation.
Control Monitoring and Business Unit Support
- Perform scheduled assessments and ad hoc control reviews in coordination with internal and external assurance teams.
- Support business units with day-to-day control assurance activities, including change management and identity and access management controls.
- Conduct ongoing monitoring activities designed to maintain and enhance the control environment.
- Maintain accurate documentation of assessment procedures, evidence reviewed, conclusions, and follow-up actions.
- Build effective working relationships across business and technology teams to promote consistent control execution and risk awareness.
What You'll Need
- Bachelor's degree in information systems, cybersecurity, accounting, finance, business administration, risk management, or a related field.
- 4-6 years in information technology controls, technology risk, internal audit, external audit, compliance, or a related assurance function.
- Working knowledge of information technology control concepts, risk assessment practices, and audit or assurance principles.
- Ability to independently evaluate moderately complex control design and effectiveness and document supportable conclusions.
- Ability to manage multiple assessments, evidence requests, findings, and remediation activities while meeting deadlines.
- Written and verbal communication skills to explain requirements and findings to technical and nontechnical stakeholders.
- Analytical judgment, attention to detail, and ability to collaborate across business, technology, risk, and audit teams.