Risk Information Technology Data Analyst positions focus on delivering results in their domain. This page aggregates open Risk Information Technology Data Analyst roles and what employers typically expect.
Thank you for your interest in a career at Regions. At Regions, we believe associates deserve more than just a job. We believe in offering performance-driven individuals a place where they can build a career --- a place to expect more opportunities. If you are focused on results, dedicated to quality, strength and integrity, and possess the drive to succeed, then we are your employer of choice. Regions is dedicated to taking appropriate steps to safeguard and protect private and personally identifiable information you submit. The information that you submit will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and experience for job opportunities and will not be used for marketing purposes, sold, or shared outside of Regions unless required by law. Such information will be stored in accordance with regulatory requirements and in conjunction with Regions’ Retention Schedule for a minimum of three years. You may review, modify, or update your information by visiting and logging into the careers section of the system. ## Job Description: At Regions, the Risk Information Technology and Data Analyst is a key member of the IT and Data Risk Management organization and performs general activities consistent with the second line of defense, including IT and Data risk identification, measurement, mitigation, monitoring, and reporting. This position supports the implementation of Regions’ Risk Management Framework aligned with regulatory expectations (FFIEC, NIST, GLBA) and internal policies. The analyst collaborates with Technology, Cyber Security, Data and Analytics, Compliance, Business Risk Teams, and Internal Audit to proactively manage IT and Data risks. **Primary Responsibilities** - Assists in conducting IT and Data Risk Targeted Risk Assessments, Continuous Monitoring, and Testing as identified across all aspects of Information Technology and Data, including application development, cyber security, enterprise architecture, business continuity and disaster recovery, data governance, data quality, and change management, etc - Contributes to core risk assessments, including the enterprise risk assessment, payment network attestations, and the cyber security risk assessment which evaluates the company’s compliance with key regulatory requirements - Evaluates the design and effectiveness of technology and data controls aligned to regulatory and industry requirements - Creates and revises IT and Data Risk Management methodology, including procedures - Monitors trends and regulatory changes in IT and Data and advises leadership on technology and data initiatives that support these trends - Reviews IT and Data policies and standards to ensure they are in alignment with regulations and industry best practices - Monitors, tracks, validates, and reports mitigation and resolution of IT and Data risk issues - Produces reporting to effectively communicate key risks, findings, and recommendations for improvement and participates in discussions of results with key stakeholders - Supports annual planning, including staffing assessments and identifying training opportunities - Participates in audit and regulatory examinations, including providing risk insights, collecting evidence, and preparing verbal and written materials. - Collaborates with key stakeholders within strategic business groups and technology to provide credible challenge of Technology and Data’s execution of the risk management framework This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay. This position may be filled at a higher level depending on the candidate’s qualifications and relevant experience. **Requirements** - Bachelor’s degree in related field - Three (3) years of relevant experience in IT risk, IT audit, technology, cybersecurity, or operational risk - Intermediate understanding of risk management, cybersecurity/technology, a…