job_description.job_card.job_descriptionLEAD IT RISK & CONTROLWHAT IS THE OPPORTUNITY? "The Lead IT Risk Controls Analyst is a subject-area specialist with specialized training, methods and analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. Focus areas of security assessment by the Lead ITRC Security Analyst includes third party security and overall security program effectiveness in mitigating risk. The ITRC Analyst's goal to create actionable information for IT and business leadership, and to provide objective assessment of cyber security risks for auditors, regulators and external parties. This requires routinely authoring detailed reports and gathering metrics ensure stakeholders receive accurate and complete information. The Lead ITRC tkeeps abreast of external cyber security trends, technologies and cyber risk management approaches, and often works with other teams on cyber risk-related initiatives to provide subject-matter recommendations and guidance to achieve a posture within the bank's overall risk appetite. The Lead ITRC serves as an expert area of specialization. This role is a working lead that provides functional guidance and may coordinates or supervise the daily activities of individual contributors or working teams in areas of specialization.Provides input on resources planning, procedures." WHAT WILL YOU DO?Define analysis objectives, collect data from internal and external sources, and evaluate / analyze data to provide objective information on cyber risks for IT and business management with both summary and detailed reportingAssess risk within subject specialty area to evaluate the design and effectiveness of security controlsWork collaboratively with all Lines of Defense, coordinate and proactively identify, manage and monitor IT Risk.Act as Subject Matter Expert for the activities performed to manage IT RiskExecute IT Risk Assessment (e.g. Risk Control Self Assessments) to identify and quantify the risks and their associated controls.Execute GLBA Risk and Control AssessmentIdentify and Define Key Performance Indicators (KPIs) metrics and Key Risk Indicators (KRIs) to monitor all risks and ratings to Controls to measure the performance on the control operation.Provide insight and classify data to assess Risk assessmentsCoordinate the completion of risk mitigating actions and providing status updates of all issues statuses to senior managementInvestigates large or repetitive loss events impacting the division to assess for potential systemic weaknesses and to ensure appropriate corrective action is taken.Provide insight and classify data to assess Risk assessmentsCoordinate the completion of risk mitigating actions and providing status updates of all issues statuses to senior managementInvestigates large or repetitive loss events impacting the division to assess for potential systemic weaknesses and to ensure appropriate corrective action is taken.Create new and maintain process and procedural documentation for various risk analysis and risk assessment activities; Highlight industry-based methodologies, techniques or standards (FAIR, NIST, FFIEC, etc.) used as the basis for analysis effortsPublish routine, accurate risk analysis and assessment reports as defined by organizational risk policies and procedures to applicable audiences for each subject area disciplineParticipate in other security support projects and duties as needed or requested" WHAT DO YOU NEED TO SUCCEED?Required QualificationsBachelor's Degree or equivalentMinimum of 12 years experience in Information / Cyber Security fieldMinimum of 7 years experience in cyber security operations, incident response, IT risk management or investigationMinimum 3 years' experience managing or coordinating resources such as people or projectsAdditional QualificationsCertifications are a plus (e.g., CRISC, CISA, CISM,CAMS CISSP)Experience with process documentation, risk and control assessments, and designing / executing IT General Controls (ITGC), test scriptsExperience and / or knowledge in working with multiple IT risk and controls domains such as identity and access management, privilege success, vulnerability management privacy, incident response etc.Understand of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectationsDemonstrated experience analyzing complex cyber security data sets within subject area specialtyDemonstrated knowledge of cyber security landscape threats, trends, technologiesDemonstrated knowledge of financial regulation and control frameworks applicable to cyber security or IT riskExcellent communication and interpersonal skills. Including a strong ability to create positive and professional business relationships with internal clients.Strong commitment to working as a team and providing excellent customer service.Exposure to banking or equivalent highly controlled technology environment is preferredMasters' degree in business, computer science or related field preferredSecurity certifications (CISSP, GSEC, etc.) are highly desired.Demonstrated experience with Industry or subject specific analysis or assessment frameworks is highly desired (FAIR, NIST CSF, etc.)Experience in banking / financial industry is strongly preferredFormalized training in cyber security analysis or assessment techniquesWHAT'S IN IT FOR YOU?CompensationStarting base salary : $111,408 - $189,738 per year. Exact compensation may vary based on skills, experience, and location. This job is eligible for bonus and / or commissions.Benefits and PerksAt City National, we strive to be the best at whatever we do, including the benefits and perks we offer our colleagues including :Comprehensive healthcare coverage, including Medical, Dental and Vision plans, available the first of the month following start dateGenerous 401(k) company matching contributionCareer Development through Tuition Reimbursement and other internal upskilling and training resourcesValued Time Away benefits including vacation, sick and volunteer timeSpecialized health and family planning benefits including fertility benefits, and cancer, diabetes and musculoskeletal support programsCareer Mobility support from a dedicated recruitment teamColleague Resource Groups to support networking and community engagement Get a more detailed look at our [Benefits and Perks](https : / / careers.cnb.com / benefits). ABOUT US Since day one we've always gone further than the competition to help our clients, colleagues and communities flourish. City National Bank was founded in 1954 by entrepreneurs for entrepreneurs and that legacy of integrity, community and unparalleled client relationships continues today. City National is a subsidiary of Royal Bank of Canada, one of North America's leading diversified financial services companies. To learn more about City National and our dynamic company culture, visit us at [About Us](https : / / www.cnb.com / about-us.html).INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENTCity National Bank fosters an inclusive environment where all forms of diversity are valued and leveraged to make us a better company and employer. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, veteran status or other basis protected by law. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.Represents basic qualifications for the position. To be considered for this position, you must at least meet the required qualifications. careers.cnb.com accepts applications on an ongoing basis, until filled.