Job Title : Risk and Control Self-Assessment (RCSA) Analyst
Duration : Contract through the end of the year
Location : Remote (US-based candidates preferred)
Role Overview :
This role focuses on the coordination, design, and development of Risk and Control Self-Assessments (RCSAs), specifically emphasizing authentication processes across multiple digital and communication channels.
Key Responsibilities :
- Coordinate with various business units and stakeholders to design and develop robust Risk and Control Self-Assessments (RCSAs).
- Specifically target authentication processes across multiple channels including web, mobile applications, and telephonic systems.
- Leverage deep understanding of authentication technologies and tools such as Single Sign-On (SSO), Federation, Directory Services, Encryption / Key Exchange, and Privileged Access Management (PAM).
- Analyze and understand context and data crucial for authentication and post-authentication risk evaluations, such as geolocation, device / channel identification, last login activities, and related factors.
- Collaborate effectively with stakeholders to document and enhance risk identification, evaluation processes, control assessments, and formulate comprehensive risk treatment plans.
- Ensure alignment of RCSAs with business objectives, regulatory compliance, Service Level Agreements (SLAs), and other pertinent requirements.
Qualifications :
Strong experience in designing and conducting Risk and Control Self-Assessments (RCSAs).Solid understanding of authentication mechanisms and security frameworks including SSO, Federation, Privileged Access, Encryption methodologies, and Directory Services.Knowledge and experience in evaluating context-driven authentication risks and developing corresponding controls.Experience working with cross-functional teams and stakeholders to facilitate risk identification and control assessment processes.Familiarity with regulatory compliance standards applicable to financial institutions or similar sectors.Excellent communication, documentation, and stakeholder management skills.