Senior IT Risk Analyst - IT General Controls
ESP Madrid- 39 hours, Spain
The Cigna Group
Discover The Cigna Group, a global health company committed to improve the health and vitality of those we serve.ABOUT US:
Cigna healthcare is a global health service company with roots in the US, serving more than 180 million customers and patients throughout the world. We deliver quality health care through choice, predictability, affordability and through integrated capabilities and connected, personalized solutions that advance whole person health.
Cigna’s mission is to help our customers improve their health, well-being and sense of security by providing access to care. With our whole health approach, we’re focused on addressing health concerns, improving resilience, reducing stress levels and emotional health issues. Our employer promise is to remain steadfast in our commitment to fostering growth and improving lives by offering meaningful work within a positive, inclusive culture that prioritizes our colleagues. We champion teamwork and collaboration and empower our people with cutting-edge technology to drive efficiency and amplify their impact in everything we do. Together we strive to create an environment where every individual thrives and contributes to meaningful change”
The Job:
We are seeking a proactive and detail-oriented Technology Risk Lead Analyst to join our Technology Risk & Controls organization. This role is pivotal in ensuring the integrity, reliability, and security of our IT environment by leading the development, articulation, and testing of IT General Controls (ITGCs). The ideal candidate will act as a trusted advisor to key stakeholders, driving effective risk management practices across the organization.
Key Responsibilities:
ITGC Development & Articulation:
Develop and document a comprehensive ITGC framework tailored to the organization’s technological landscape.
Ensure alignment of ITGCs with regulatory requirements, industry standards (e.g., SOX, ISO 27001, COBIT), and internal policies.
Evaluate the design effectiveness and identify and communicate gaps or weaknesses in existing ITGCs, recommending practical solutions for remediation.
ITGC Testing & Validation:
Design and execute testing plans to evaluate the operational effectiveness of ITGCs, ensuring compliance and audit readiness.
Coordinate with internal and external auditors to facilitate ITGC assessments and audits.
Track and validate remediation efforts for identified control deficiencies, ensuring timely resolution.
Stakeholder Collaboration & Reporting:
Act as a liaison between technology, compliance, and risk management teams to promote a shared understanding of IT risks.
Develop and deliver reports, dashboards, and presentations to senior management, highlighting key risks and control performance metrics.
Provide training and guidance to teams on ITGC processes, ensuring consistent implementation and awareness.
Qualifications and Experience:
Bachelor’s degree in Information Technology, Computer Science, Risk Management, Business Administration or a related field.
3-5 years of experience in IT Risk management, IT audit, or IT controls. Experience within the Insurance Industry will be a plus.
Strong understanding of ITGC domains: access controls, change management, data integrity, and IT operations.
Knowledge of regulatory and compliance frameworks (e.g., SOX, GDPR, PCI-DSS, NIST).
Experience with GRC (Governance, Risk, and Compliance) tools and frameworks.
Excellent analytical and problem-solving skills with the ability to manage complex data and processes.
Effective communication and stakeholder management skills, with the ability to influence and educate diverse audiences.
Certifications (Preferred): i) Certified Information Systems Auditor (CISA), ii) Certified Risk and Information Systems Control (CRISC), iii) Certified in Governance of Enterprise IT (CGEIT), iv) Certified Information Systems Security Professional (CISSP)
Key Competencies:
Analytical thinking and problem-solving, with the ability to identify issues or risks that require escalation.
- Demonstrated ability to work independently with minimal supervision.
- Attention to detail and ability to manage multiple priorities.
- Strategic mindset with a focus on continuous improvement.
- Proactive and self-motivated, with a keen sense of ownership and accountability.
- Adaptable in a fast-paced, evolving regulatory landscape.
WHAT WE OFFER:
- Permanent contract.
- Multicultural working environment with Hybrid working.
- Great Social Benefits.
- Private Medical Insurance.
- Educational Development Program.
What we are looking for
We are seeking individuals who thrive in collaborative environments, are passionate about driving meaningful change, and are excited to grow in a company that prioritizes its people.
Join us and be part of a company where your growth, ideas and contributions are valued. Let’s create something extraordinary together. It’s time to look to your future and apply to work for Cigna today!
About Cigna Healthcare
Cigna Healthcare, a division of The Cigna Group, is an advocate for better health through every stage of life. We guide our customers through the health care system, empowering them with the information and insight they need to make the best choices for improving their health and vitality. Join us in driving growth and improving lives.Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.
If you require reasonable accommodation in completing the online application process, please email: SeeYourselfEMEA@cigna.com for support. Do not email SeeYourselfEMEA@cigna.com for an update on your application or to provide your resume as you will not receive a response.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CISA CISSP COBIT Compliance Computer Science CRISC GDPR Governance ISO 27001 NIST Risk management SOX
Perks/benefits: Career development Health care Insurance
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.