Sr. IT Risk Management Analyst

CNA · Remote

Company

CNA

Location

Remote

Type

Full Time

Job Description

You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.
CNA seeks to offer a comprehensive and competitive benefits package to our employees that helps them - and their family members - achieve their physical, financial, emotional and social wellbeing goals.
For a detailed look at CNA's benefits, check out our Candidate's Guide .
The Analyst will support the Risk and Controls Governance (RCG) leadership team and business partners execute risk management activities in alignment with Risk and Controls Governance framework and IT process, risk and control (PRC) framework. The Analyst will be accountable to spearhead initiatives that enable the broader RCG strategy including technology capabilities and modernizations, methodology execution, and adoption activities. Given appropriate oversight and guidance, the Analyst will be accountable to perform first line activities such as RCG risk assessments and other risk management activities including risk identification, profiling, assessment, response, evaluation and advising the business on issues remediation.
This position requires that the applicant have a foundational or intermediate understanding of IT risks and the execution of first line IT risk management processes and governance within a large institution. The applicant must also have good communication and management skills, and strong knowledge of industry best practices.
JOB DESCRIPTION:
RCG Strategy and Transformation:
  • Support the implementation of the target state program based on the planned roadmap for RCG focus areas including governance, risk management methodologies, technology enablement and automation, metrics, and reporting.
  • Collaborate with the three lines of defense and other risk functions on behalf of RCG to support, enable and align the Risk and Controls Governance strategy within the broader CNA risk functions.
  • Engage stakeholders at all levels across businesses and divisions to ensure effective communication and sufficient stakeholder input and buy-in.
  • Help develop education, training, and awareness campaign materials regarding IT risks as well as critical communications to help provide clarity and adoption in support of the RCG program transformation.

RCG Operational Activities:
  • Execute Risk and Controls Governance operational activities including:
    • Risk profiling (inherent risk assessment);
    • Risk assessments for processes, applications and infrastructure;
    • Risk and scenario analysis for IT risks; and
    • Risk metrics and reporting .
  • Document and develop materials for leadership to review issues identified through RCG activities.
  • Help the business create, shepherd governance channels and monitor execution of the risk response plans in alignment with RCG methodology.
  • Act as the point of contact to assist and respond to questions from key stakeholders and the business; manage required escalations and communication.
  • Provide IT guidance and risk advisory support to key initiatives.
  • Develop materials to provide regular updates to CNA Executives on the overall health of the program including preparing necessary information to facilitate management discussion and decision making.

Qualifications
  • 3+ years of experience with IT Governance and risk functions
  • Demonstrates a willingness to learn, self-starter and strong teaming capabilities
  • Understanding of IT governance and technology risk management principles and best practices
  • Strong interpersonal skills to support stakeholder communication and engagement across businesses
  • Experience with technology process, risk and control framework
  • Required: Bachelor's degree
  • Preferred: Knowledge and skills across
    • COSO
    • ISACA Risk IT framework
    • ISACA COBIT 5.0 or 2019
    • ISO 31000-series and 27000-series, 13335
    • NIST Cybersecurity framework

#LI-JB1 #LI-Remote
CNA is committed to providing reasonable accommodations to qualified individuals with disabilities in the recruitment process. To request an accommodation, please contact [email protected] .
Apply Now

Date Posted

03/13/2023

Views

5

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Recovery Analyst Underpayments - Trend Health Partners

Views in the last 30 days - 0

TREND Health Partners seeks an Underpayment Recovery Analyst to optimize client reimbursement through collaboration and detailed claim analysis The ro...

View Details

Senior Business Analyst - Xpansiv

Views in the last 30 days - 0

Xpansiv promotes its role as an energy market innovator with a global platform for environmental commodities The job posting seeks a Business Analyst ...

View Details

Fraud Investigation Analyst - Vonage

Views in the last 30 days - 0

The text describes the Trust Safety Teams mission to protect Vonages services from fraud and abuse detailing their proactive monitoring fraud detecti...

View Details

Senior Design Manager (Infrastructure) - Canonical

Views in the last 30 days - 0

Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...

View Details

Senior Product Designer - Org & Security - Typeform

Views in the last 30 days - 0

This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...

View Details

Executive Director Patient Advocacy - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...

View Details