Popular, Inc

Senior Risk Analyst

Popular, Inc • $80K — $95K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in relevant fields such as Business Administration, IT, Cybersecurity, or related areas.
  • Minimum of 5 years in IT risk management, cybersecurity, or IT audit roles.
  • Experience with cybersecurity frameworks and regulatory expectations such as NIST and COBIT.
  • Knowledge of risk governance processes, including Risk Control Self-Assessments and issue management.
  • Preferred certifications like CISA, CISM, CISSP, or CRISC.

Responsibilities

  • Lead governance enhancement of the IT & Cyber Risk and Control Matrix.
  • Advise IT and Cybersecurity leadership on consistent risk management practices.
  • Prepare and deliver risk reporting materials to management and committees.
  • Monitor remediation efforts and assess risk sustainability and appetite compliance.
  • Review and challenge policies and control implementations to ensure alignment with best practices.
  • Conduct IT and Cyber Risk Control Self-Assessments including issue identification and action planning.
  • Design and govern Key Risk Indicators (KRIs) and perform trend analyses.

Benefits

  • Hybrid work model subject to organizational needs.
  • Professional development opportunities.
  • Collaborative work environment with cross-functional teams.
Full Job Description
General Description

The Senior Risk Analyst will play a key role in advancing the second-line IT and Cyber Risk Monitoring and Assurance Program. This position provides independent oversight and effective challenge across technology and cybersecurity risk domains, partnering with first line and control functions to strengthen risk governance, and supports senior management and committees through actionable risk insights, reporting, and regulatory readiness.

Essential Duties and Responsibilities

IT & Cyber Risk Framework & Governance:
  • Lead the ongoing enhancement and governance of the IT & Cyber Risk and Control Matrix, ensuring alignment with regulatory requirements and industry frameworks such as NIST, COBIT, FFIEC, CCM, PCI, and others.
  • Serve as a trusted second-line advisor to IT and Cybersecurity leadership to ensure risk management practices are implemented consistently across the organization.
  • Prepare, generate, and provide materials (e.g., risk scorecards, dashboards, and metrics) required for various Risk Committees, Senior Management Team and Executives by the required due dates.
  • Independently monitor remediation commitments and provide credible challenge on timeliness, sustainability of remediation, and residual risk calculation and escalate concerns when risks remain outside of the organization's risk appetite.

Risk Oversight & Advisory:
  • Perform second-line review and challenge of policies, standards, risk acceptances, risk escalations, and control implementations to ensure alignment with control expectations and the IT & Cyber Risk and Control Matrix.
  • Lead the execution of the IT and Cyber Risk and Control Self-Assessments (RCSAs), including scoping, control evaluation, issue identification, action-plan development, and residual risk assessments.
  • Translate control weaknesses into clear risk statements, validate root cause, and recommend solutions aligned with the organization's risk appetite.
  • Support regulatory exams and audits by coordinating activities, reviewing evidence packages, ensuring consistent narratives, and tracking commitments and responses through closure.
  • Develop and deliver targeted training for business and technology stakeholders (e.g., RCSA processes, risk acceptance standards, key controls, evidence expectations, etc.).

Key Risk Indicators (KRIs):
  • Design, enhance, and govern KRIs, including metric definitions, thresholds, data lineage, data quality controls, and exception handling.
  • Perform trends analysis to identify potential issues and perform root cause analysis to provide recommendations to Management on how to better manage their IT & Cyber risk posture.


Education

Bachelor's degree in Business Administration, Information Technology, Computer Engineering, Computer Science, Cybersecurity or related field.

Experience

  • At least 5 years of working experience in IT controls testing, IT Risk, IT Audit and/or Cybersecurity positions; or in a consulting IT/Cyber role with a broad view of Information Technology or Information Security controls.
  • Demonstrated experience applying IT and cybersecurity frameworks and regulatory expectations (e.g., NIST, COBIT, FFIEC, CRI, CCM, etc.) including Policy and Standards review and control design assessments.
  • Experience with risk governance processes such as RCSAs, Issue Management, Risk Acceptances, and committee/board level reporting.
  • IT or Cyber certifications preferred (e.g. CISA, CISM, CISSP, CGEIT, CRISC


Other Qualification

  • Strong analytical skills with ability to synthesize complex technical topics into clear risk narratives for executives.
  • Advanced Excel skills preferred; experience with reporting/dashboard tools is a plus.
  • Excellent written and verbal communication in English and Spanish, including executive-level communication.
  • Strong judgement, critical thinking, and ability to operate independently with minimal direction.
  • Excellent organizational skills are required to establish priorities, multitask, work under pressure, and meet deadlines.
  • Excellent interpersonal skills and teamwork.
  • Proficient in Microsoft Office: Word, Excel, PowerPoint, and Outlook

Important: The candidate must provide evidence of academic preparation or courses related to the job posting, if necessary.

Our hybrid work model benefit applies to certain positions and is subject to changes based on the organizational needs.

Applicants must be authorized to work for any employer in the United States. This position is not open to applicants who need visa sponsorship or transfer of visa sponsorship at this time.

About Popular, Inc

Popular, Inc. is a financial holding company that operates in Puerto Rico, the United States, and the Caribbean. The company provides retail, mortgage, and commercial banking services through its principal banking subsidiary, Banco Popular de Puerto Rico, as well as auto and equipment leasing and financing, investment banking, broker-dealer, and insurance services through specialized subsidiaries.
Learn more about Popular, Inc
Size
8,500 employees
Market Cap
$4.6 billion
Industry
Net Income
$506.6 million
5 Year Trend
+5.4%
NASDAQ

Similar Jobs

More Jobs at Popular, Inc

More Information Technology Jobs

Find similar Senior Risk Analyst jobs: