BRMi

Risk Analyst-Control Testing

Job Locations US-VA-Vienna | US-FL-Pensacola
Posted Date 9 hours ago(8/19/2026 2:09 PM)
ID
2026-4398
# of Openings
1
Category
Security

Overview

BRMi is seeking a Risk Analyst – Control Testing who will support the Risk Control Self-Assessment (RCSA) process by performing control design assessments and control performance testing across security-related business areas, with a primary focus on fraud operations and information security. This role is responsible for evaluating the design and effectiveness of internal controls, documenting testing results, identifying deficiencies, and supporting the development of appropriate remediation plans.

 

The ideal candidate will have prior experience conducting control testing within an internal audit or RCSA environment and a strong understanding of audit methodologies, risk management frameworks, sampling techniques, and control effectiveness. This position requires strong analytical and documentation skills and the ability to communicate findings clearly to stakeholders and management.

 

**Hybrid in Vienna, VA or Pensacola, FL**

**In person interviews will be required for this role**

**6 month contract with posibilty of extension**

 

Benefits:
• Comprehensive Medical, Dental, and Vision Insurance
• Employer-Paid Life Insurance
• Employer-Paid Short-Term and Long-Term Disability Insurance
• 401(k) 
• Paid Time Off (PTO) that includes Vacation Leave, Sick Leave, and 11 Paid Holidays
• Educational Assistance

 

Vienna Salary Max: 110k

Pensacola Salary Max: 97k 

 

Click here to learn about BRMi's culture.

 

Click here to see BRMi’s Glassdoor reviews

Responsibilities

  • Participate in the Risk Control Self-Assessment (RCSA) process and related control testing activities.
  • Execute design assessments on assigned controls to determine whether controls are appropriately designed to mitigate identified risks.
  • Perform control performance and operating effectiveness testing on assigned controls.
  • Follow enterprise testing guidelines, methodologies, and documentation standards.
  • Apply accepted sampling techniques to select appropriate populations and samples for control testing.
  • Review supporting documentation, evidence, processes, and procedures to evaluate control effectiveness.
  • Analyze testing results and determine whether controls are operating as intended.
  • Document testing procedures, analysis, conclusions, findings, and supporting evidence in accordance with enterprise guidelines.
  • Identify control deficiencies, exceptions, gaps, and other areas of risk discovered through testing.
  • Perform root-cause analysis for identified control deficiencies.
  • Assist business and risk stakeholders in developing appropriate remediation plans to address identified deficiencies.
  • Communicate testing results and findings clearly to business partners, risk stakeholders, and various levels of management.
  • Track testing activities, findings, remediation efforts, and related deliverables to ensure established timelines are met.
  • Maintain organized and complete testing documentation to support internal review, audit, and regulatory requirements.
  • Collaborate with stakeholders across security, fraud operations, information security, risk management, and other business areas.
  • Manage multiple control testing assignments and priorities within established deadlines.
  • Support continuous improvement of control testing processes, documentation, and risk management practices.
  • Perform other duties as required.

Qualifications

  • Three to five years of experience performing control testing within internal audit, Risk Control Self-Assessment (RCSA), risk management, or a similar control assurance environment.
  • Advanced understanding of internal audit and control testing techniques.
  • Strong understanding of risk management frameworks and control assessment methodologies.
  • Experience conducting control design assessments and control performance or operating effectiveness testing.
  • Knowledge of sampling methodologies and techniques used to support control testing.
  • Experience identifying, documenting, and communicating control deficiencies and testing findings.
  • Ability to perform root-cause analysis and support the development of remediation plans.
  • Strong analytical and critical-thinking skills with the ability to evaluate processes, controls, documentation, and supporting evidence.
  • Strong organizational skills and attention to detail.
  • Ability to manage multiple priorities and testing assignments under tight timeframes.
  • Strong written communication skills with the ability to clearly document testing procedures, analysis, conclusions, and findings.
  • Strong verbal communication skills with the ability to discuss findings with stakeholders and various levels of management.
  • Ability to work independently while collaborating effectively with business, risk, security, and audit stakeholders.

Desired:

  • Prior experience evaluating controls within security-related business areas.
  • Experience supporting or evaluating fraud operations and associated controls.
  • Experience evaluating information security controls.
  • Experience working within a large enterprise or highly regulated environment.
  • Familiarity with governance, risk, compliance, and internal control programs.
  • Certified Internal Auditor (CIA), Certified Information Systems Auditor (CISA), Certified Public Accountant (CPA), or another relevant professional certification.

** BRMi will not sponsor applicants for work visas for this position.**

**This is a W2 opportunity only**

 

EOE/Minorities/Females/Vet/Disabled 

We are an equal opportunity employer that values diversity and commitment at all levels. All individuals, regardless of personal characteristics, are encouraged to apply. Employment policies and decisions on employment and promotion are based on merit, qualifications, performance, and business needs. The decisions and criteria governing the employment relationship with all employees are made in a nondiscriminatory manner, without regard to race, religion, color, national origin, sex, age, marital status, physical or mental disability, medical condition, veteran status, or any other factor determined to be unlawful by federal, state, or local statutes. 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed