Intermediate First Line Risk & Control Analyst
Job Description Summary
The Intermediate First Line Risk & Control Analyst will conduct IT risk assessments for Transamerica’s technology and risk teams and assist with implementing and maintaining IT Risk Management processes, procedures, and tools.
Responsibilities:
- Plan and facilitate evidence-based risk assessments for processes, applications, technologies, and projects to assess controls and identify control gaps.
- Help develop and conduct the annual Risk and Control Self-Assessment plan.
- Identify, assess, and record risks along with mitigation or acceptance plans.
- Prepare Architecture Review Board (ARB) summaries, outlining risk assessment recommendations.
- Train stakeholders and promote awareness of risk management.
- Work with IT Risk (2nd Line), Information Security, Internal Controls, Internal Audit, and external consultants to mature Transamerica’s IT Risk Management Program.
- Ensure application compliance data accuracy in the Configuration Management Database (CMDB).
- Maintain assessment templates for alignment with relevant regulations (SOX, SOC1/2, NYDFS)
Qualifications
- Bachelor’s degree in Information Technology, Computer Science, or a related field
- 2 years of experience in IT risk management, compliance, governance, or controls, or the equivalent combination of knowledge and skills through experience, education and certifications.
- Knowledge of relevant laws, regulations, and standards
- Strong analytical and problem-solving skills
- Knowledge of IT governance frameworks such as COBIT, ITIL, or ISO 27001
- Familiarity with risk management tools and software
- Ability to work collaboratively across the organization
- Excellent communication and interpersonal skills
- Assist with fostering a culture of continuous improvement and professional development
Preferred Qualifications
- Strong knowledge and/or prior experience within the insurance, pensions or financial services sectors, encompassing relevant business processes and technologies.
- One or more of the following certifications:
- (CRISC) Certified in Risk and Information Systems Control
- (CGEIT) Certified in in the Governance of Enterprise IT
- (CISM) Certified Information Security Manager
- (CISA) Certified Information Systems Auditor
- Proficient in the use of Microsoft Office programs like Excel and PowerPoint, as well as Power BI and Power Automate.
- Demonstrated success in risk management roles.
- Effective problem-solving and decision-making skills to identify and address issues to mitigate risk.
- Solid grasp of risk management, design methods, and best practices.
Working Conditions
Hybrid working environment.
Minimum travel may be required for team meetings or training.
May require work outside of normal working hours due to global support.
Compensation
- The Salary for this position generally ranges between $72,000 - $90,000 annually. Please note that the salary range is a good faith estimate for this position and actual starting pay is determined by several factors including qualifications, experience, geography, work location designation (in-office, hybrid, remote) and operational needs. Salary may vary above and below the stated amounts, as permitted by applicable law.
- Additionally, this position is typically eligible for an Annual Bonus based on the Company Bonus Plan/Individual Performance and is at the Company’s discretion.
Applicants must possess legal authorization to work for our company in the U.S. without the need for immigration, sponsorship or otherwise serving as an employer of record for immigration employment purposes. At this time, this role is not eligible for immigration-related employment authorization sponsorship.
This is a hybrid position requiring three days in office per week in one of our hub locations. Relocation assistance will not be provided for this position.
Disclaimer
Beware of fake job offers!
We’ve been alerted to scammers impersonating Transamerica recruiters, particularly for remote positions. Please note:
- We will never request personal information such as ID or payment for equipment upfront.
- Official offers are sent via DocuSign following a verbal offer—not through text or email.
This job description is not a contract of employment nor for any specific job responsibilities. The Company may change, add to, remove, or revoke the terms of this job description at its discretion. Managers may assign other duties and responsibilities as needed. In the event an employee or applicant requests or requires an accommodation to perform job functions, the applicable HR Business Partner should be contacted to evaluate the accommodation request.