- Location
- PR
- Type
- Full-time
- Department
- IT
- Experience
- 3+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Vincere
Description
Risk and Control Analyst
Location: Puerto Rico (SJU Airport)
Department: Information Technology
Position Summary
The Risk and Control Analyst is responsible for supporting IT governance, risk management, compliance, and change management initiatives. This role helps ensure that IT systems, processes, and controls operate effectively while meeting internal policies, regulatory requirements, and industry best practices. The position also supports audit activities, risk assessments, control testing, and continuous improvement efforts across the IT organization.
Key Responsibilities
- Coordinate and execute control testing activities, documenting findings and tracking remediation efforts.
- Review and validate IT changes to ensure proper justification, approvals, testing, and documentation.
- Perform IT General Controls (ITGC) and application control reviews.
- Monitor risks related to systems, applications, user access, and operational processes.
- Support internal and external audits by gathering evidence, documentation, and remediation plans.
- Track and follow up on audit findings and control deficiencies.
- Partner with IT, security, and business teams to support risk assessments and compliant solution deployments.
- Maintain and update IT policies, procedures, and departmental documentation.
- Contribute to continuous improvement initiatives related to risk, compliance, and operational effectiveness.
Qualifications
- Bachelor's degree in Information Technology, Information Systems, Computer Science, or a related field preferred.
- Equivalent experience supporting regulated systems or compliance-driven environments will be considered.
- 3–5 years of experience in IT Audit, Risk Management, Compliance, Change Management, Information Security, or Information Systems.
- Experience working in regulated industries or highly controlled environments is preferred.
Preferred Certifications
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- ITIL Foundation
- CISM or other related governance, risk, and compliance certifications
Skills & Knowledge
- Understanding of IT controls, risk assessments, and compliance frameworks.
- Knowledge of change management processes and ITIL best practices.
- Experience supporting audit and regulatory activities.
- Strong analytical, documentation, and problem-solving skills.
- Excellent communication and stakeholder management abilities.
- Ability to manage multiple priorities and work effectively across technical and business teams.