IT Operational Risk Analyst
The IT Operational Risk Analyst will support the Technology Risk team in identifying, assessing, and mitigating risks associated with IT operations. This includes evaluating internal controls, monitoring compliance with regulatory requirements, and assisting in the development of risk management strategies. The role involves collaboration across departments to ensure risk awareness and adherence to best practices in cybersecurity, data governance, and operational resilience.
ABOUT THE JOB
• Week 1–2 (80 hours): Orientation & Introduction to Technology Risk- Overview of Synovus IT environment- Introduction to risk management frameworks (NIST, COBIT, ISO 27001)• Week 3–6 (160 hours): Risk Assessment & Control Evaluation- Hands-on training in risk identification and assessment- Control testing and documentation• Week 7–10 (160 hours): Regulatory Compliance & Audit Support- Training on FFIEC, GLBA, SOX, and other relevant regulations- Support for internal and external audits• Week 11–14 (160 hours): Cybersecurity Risk & Incident Response- Exposure to cybersecurity risk management practices- Participation in tabletop exercises and incident simulations• Week 15–17 (160 hours): Data Governance & Third-Party Risk- Training in data classification, privacy, and vendor risk management• Week 18 (80 hours): Capstone Project & Final Evaluation- Completion of a risk assessment project- Presentation to Technology Risk leadership
RESPONSIBILITIES
- Support the Technology Risk team in identifying, assessing, and mitigating risks associated with IT operations
- Evaluate internal controls
- Monitor compliance with regulatory requirements
- Assist in the development of risk management strategies
- Collaborate across departments to ensure risk awareness and adherence to best practices in cybersecurity, data governance, and operational resilience
QUALIFICATIONS
- Orientation & Introduction to Technology Risk
- Risk Assessment & Control Evaluation
- Regulatory Compliance & Audit Support
- Cybersecurity Risk & Incident Response
- Data Governance & Third-Party Risk
- Capstone Project & Final Evaluation
TARGET MOCS
All MOCs
OTHER
N/A