> Markdown version of [/jobs/ext/868600-it-risk-controls-analyst-controls-testing](https://www.wearedevelopers.com/jobs/ext/868600-it-risk-controls-analyst-controls-testing). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Risk & Controls Analyst (Controls Testing) - **Company:** Shawbrook - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Data Governance, Identity and Access Management, Information Technology Audit, Information Technology Operations, Systems Development Life Cycle, Data Logging, Test Scripts - **Published:** June 10, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=b9cfc5a4027b8a1e ## About the Role Do you have experience in NIST standards?, * Experience in IT risk, technology controls, internal controls testing, or IT audit (First, Second, Third Line, or IT External Audit). * Strong understanding of technology and cyber risk domains (e.g. access management, change management, IT operations, security, SDLC, incident management, data governance). * Experience documenting and executing control tests, including evidence gathering and evaluation. * Strong written skills, with the ability to produce clear, structured documentation and reports. * Familiarity with GRC tooling (e.g. AuditBoard or equivalent). * Good understanding of risk management principles within a regulated environment. * Strong stakeholder engagement skills with the confidence to challenge constructively. * Analytical mindset with strong attention to detail. * Operate autonomously while maintaining alignment with team objectives. Desirable * Experience within a UK regulated bank, financial services firm, or a Consultancy. * Awareness of FRC (UK Corporate Governance Code)/PRA/FCA regulatory expectations, Operational Resilience, and SMCR. * Knowledge of control frameworks (e.g. SOx, COBIT, ITIL, NIST, ISO 27001). * Professional qualifications (or working towards) such as CISA, CRISC, CISSP, or equivalent. * Experience supporting change / transformation risk oversight. ## Description This role is critical in strengthening Shawbrook's first line technology control environment. By delivering robust control testing and effective risk management support, the IT Risk & Controls Analyst helps ensure that Technology and Cyber risks are understood, managed and reported appropriately, protecting the Bank, supporting regulatory compliance, and enabling safe and sustainable growth. The IT Risk & Controls Analyst supports the effective management of technology and cyber risk within the CTO function. The role is responsible for executing and documenting control testing across the different technology departments, including Technology & Cyber, Data Governance & Quality, and Transformation (Change), ensuring risks and issues are accurately recorded and tracked, and contributing to high-quality risk reporting. The individual will operate within the First Line of Defence, working collaboratively with Technology, Cyber Security, Data and Change teams, as well as the central Risk and Controls and Second Line Risk functions, to ensure Shawbrook maintains a strong and well-evidenced control environment aligned to regulatory expectations (PRA/FCA/FRC) and internal risk management standards. This is a fantastic opportunity to sit at the heart of Technology in a growing specialist bank and play a visible role in strengthening how we manage risk. As IT Risk & Controls Analyst, you will move beyond traditional controls testing to directly influence how Technology, Cyber, Data and Change departments operate safely and effectively at scale., Control Testing & Assurance * Plan, document and execute control testing across the different technology functions, including Technology & Cyber, Data Governance & Quality, and Transformation / Change. * Assess control design and operating effectiveness, clearly evidencing outcomes and identifying control gaps. * Produce concise test reports, agree remediation actions with control owners, and track issues to closure. * Coordinate testing schedules with the central Controls function and ensure consistency of methodology and documentation. * Support continuous improvement of the Technology control environment, identifying opportunities for automation and maturity uplift. Risk & Issue Management * Support the accurate logging, maintenance and quality assurance of risks and issues within AuditBoard (GRC tool). * Monitor remediation activity, ensuring actions are tracked, evidenced and escalated where required. * Support audit and regulatory engagement by ensuring risk and control artefacts are complete, current and defensible. Risk Reporting & Governance * Contribute to monthly Technology risk reporting, including control testing results, risk profile movements, issue status and key themes. * Support preparation of materials for CTO and Risk governance forums. * Support RCSA cycles, risk assessments for new initiatives, and oversight of material change. * Contribute to regulatory, audit and assurance interactions as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Are Classical Automation Frameworks Dead? How AI Agents Are Transforming QA](https://www.wearedevelopers.com/videos/100243-are-classical-automation-frameworks-dead-how-ai-agents-are-transforming-qa) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)