... ERM/RCSA and risk appetite. Maintains and evolves the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exception workflows. Leads risk ...
... ERM/RCSA and risk appetite. Maintains and evolves the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exception workflows. Leads risk ...
May help to conduct RCSA and facilitate sessions where risks and Controls are rated. * May, if applicable, assist in the external change management for credit bureau working with centralized team and ...
May help to conduct RCSA and facilitate sessions where risks and Controls are rated. * May, if applicable, assist in the external change management for credit bureau working with centralized team and ...
Support audit, regulatory, and compliance deliverables, including action plans within the Risk Control Self-Assessment (RCSA) framework * Coordinate team activities and prepare materials for town ...
Support audit, regulatory, and compliance deliverables, including action plans within the Risk Control Self-Assessment (RCSA) framework * Coordinate team activities and prepare materials for town ...
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. Proven ability to communicate complex risk topics clearly to senior leaders and governance forums. Strong ...
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. Proven ability to communicate complex risk topics clearly to senior leaders and governance forums. Strong ...
Segment Risk Manager, Sr. Commercial Digital & AI Risk
Columbus, OH · On-site
$120 - $180/hr
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. * Proven ability to communicate complex risk topics clearly to senior leaders and governance forums.
Segment Risk Manager, Sr. Commercial Digital & AI Risk
Columbus, OH · On-site
$120 - $180/hr
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. * Proven ability to communicate complex risk topics clearly to senior leaders and governance forums.
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. * Proven ability to communicate complex risk topics clearly to senior leaders and governance forums.
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. * Proven ability to communicate complex risk topics clearly to senior leaders and governance forums.
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. * Proven ability to communicate complex risk topics clearly to senior leaders and governance forums.
Demonstrated experience with RCSA frameworks, risk appetite alignment, and issue management. * Proven ability to communicate complex risk topics clearly to senior leaders and governance forums.
Directs the enterprise technology risk assessment program (annual and event-driven) across infrastructure, applications, data, cloud, and third-party environments; ensuremethodologyaligns to ERM/RCSA ...
Directs the enterprise technology risk assessment program (annual and event-driven) across infrastructure, applications, data, cloud, and third-party environments; ensuremethodologyaligns to ERM/RCSA ...
Support audit, regulatory, and compliance deliverables, including action plans within the Risk Control Self-Assessment (RCSA) framework * Coordinate team activities and prepare materials for town ...
Support audit, regulatory, and compliance deliverables, including action plans within the Risk Control Self-Assessment (RCSA) framework * Coordinate team activities and prepare materials for town ...
CBB Financial Crimes Controls Advisor
Cincinnati, OH · On-site
$86 - $102/hr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
CBB Financial Crimes Controls Advisor
Cincinnati, OH · On-site
$86 - $102/hr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
CBB Financial Crimes Controls Advisor
Columbus, OH · Hybrid
$86K - $101K/yr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
CBB Financial Crimes Controls Advisor
Columbus, OH · Hybrid
$86K - $101K/yr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
Lead Privacy Compliance Advisor
Columbus, OH · On-site +1
$129K - $224K/yr
Champions and educates business partners on the Risk and Control Self-Assessment program (RCSA). - (25%) * Understands the short- and long-term goals of the organization. Applies strategic thinking ...
Lead Privacy Compliance Advisor
Columbus, OH · On-site +1
$129K - $224K/yr
Champions and educates business partners on the Risk and Control Self-Assessment program (RCSA). - (25%) * Understands the short- and long-term goals of the organization. Applies strategic thinking ...
CBB Financial Crimes Controls Advisor
Cincinnati, OH · Hybrid
$86K - $101K/yr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
CBB Financial Crimes Controls Advisor
Cincinnati, OH · Hybrid
$86K - $101K/yr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
CBB Financial Crimes Controls Advisor
Cincinnati, OH · On-site
$86 - $102/hr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
CBB Financial Crimes Controls Advisor
Cincinnati, OH · On-site
$86 - $102/hr
Knowledge of RCSA and processes * Understanding of Issue Management processes * Advanced knowledge of applicable laws, regulations, financial services, and regulatory trends that impact Consumer ...
Rcsa information
See Ohio salary details
$17.60 - $22.87
2% of jobs
$22.87 - $28.15
14% of jobs
$29.91 is the 25th percentile. Wages below this are outliers.
$28.15 - $33.43
28% of jobs
The median wage is $35.69 / hr.
$33.43 - $38.71
15% of jobs
$38.71 - $43.98
6% of jobs
$48.78 is the 75th percentile. Wages above this are outliers.
$43.98 - $49.26
11% of jobs
$49.26 - $54.54
11% of jobs
$54.54 - $59.81
8% of jobs
$59.81 - $65.09
4% of jobs
$65.09 - $70.37
0% of jobs
$70.37 - $75.64
0% of jobs
$17
$41
$75
How much do rcsa jobs pay per hour?
What is an RCSA?
An RCSA (Risk and Control Self-Assessment) job involves identifying, assessing, and mitigating risks within an organization. Professionals in this role work to ensure regulatory compliance, improve internal controls, and minimize operational risks. They collaborate with various departments to evaluate risk exposure and implement corrective actions. RCSA analysts often develop risk management frameworks and report findings to senior management. This role is essential in financial institutions, insurance companies, and other regulated industries.
What does an RCSA do?
As an RCSA professional, your typical day involves facilitating risk assessment workshops, evaluating existing controls, and documenting processes to identify potential risk areas. You'll regularly collaborate with different business units to gather relevant information and ensure that all assessments are comprehensive and up to date. Preparing detailed reports, monitoring remediation activities, and presenting findings to management are also key components of the role. This work ensures your organization maintains strong internal controls and is well-prepared for both internal and external audits.
What are the key skills and qualifications needed to thrive as an RCSA, and why are they important?
To excel as an RCSA (Risk and Control Self-Assessment) professional, you need a strong background in risk management, internal controls, auditing, and compliance, often supported by a relevant bachelor’s degree and certifications such as CRSA, CIA, or CISA. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) software, and data analytics platforms is frequently required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for this role. These skills and qualifications help ensure thorough risk identification, accurate process evaluation, and the development of effective mitigation strategies within an organization.
What skills are needed for Rcsa?
What are the most commonly searched types of Rcsa jobs in Ohio?
The most popular types of Rcsa jobs in Ohio are:
What are popular job titles related to Rcsa jobs in Ohio?
For Rcsa jobs in Ohio, the most frequently searched job titles are:
What job categories do people searching Rcsa jobs in Ohio look for?
The top searched job categories for Rcsa jobs in Ohio are:
What cities in Ohio are hiring for Rcsa jobs?
Cities in Ohio with the most Rcsa job openings:

Full-time
Posted 20 days ago
WesBanco rating
7.4
Based on 14 frontline employees who took The Breakroom Quiz
108th of 175 rated banks
Job description
Provides strategic leadership and operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison among Technology, Risk, Audit, and executive leadership to ensure the technology risk posture aligns to regulatory expectations, enterprise risk appetite, and industry frameworks. Requires deep expertise in banking technology regulations, enterprise risk frameworks, and control design, balanced with the executive presence to communicate complex risk themes to technical and non-technical audiences, including Board-level committees.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Owns and matures the enterprise IT GRC program, including policies, standards, procedures, and control frameworks aligned to NIST CSF 2.0, CIS Controls v8, FFIEC CAT/Architecture, and applicable regulatory guidance (OCC, FDIC, Federal Reserve).
Establishes and maintains the technology policy hierarchy (policy → standard → procedure → control) with defined ownership and periodic review cadence.
Serves as program owner for the technology governance council structure (e.g., IT Steering, Technology Risk), including agenda-setting, reporting, and action item tracking.
Operationalizes AI governance standards (NIST AI RMF, ISO/IEC 42001), including AI inventory, risk tiering, lifecycle controls, and oversight of vendor AI use cases.
Directs the enterprise technology risk assessment program (annual and event-driven) across infrastructure, applications, data, cloud, and third-party environments; ensure methodology aligns to ERM/RCSA and risk appetite.
Maintains and evolves the IT risk register, including risk identification, scoring, ownership, treatment plans, and risk acceptance/exception workflows.
Leads risk assessment and advisory activities for emerging technologies (AI/ML, cloud, RPA), translating technical exposures into business impact and decision options.
Develops and reports technology risk metrics and KRIs for senior leadership and Board committees; drive a data-driven risk culture.
Serves as the primary IT GRC point of contact for regulatory examinations (OCC, FDIC, Federal Reserve) and internal/external audit engagements related to technology, cybersecurity, and operational risk.
Monitors and interprets evolving regulatory requirements and supervisory guidance (FFIEC, SR letters, OCC bulletins, GLBA Safeguards, privacy laws) and translate them into actionable obligations and control updates.
Manages technology audit and exam finding remediation: track issue aging, validate evidence, and ensure sustainable control improvements with clear ownership and timelines.
Partners cross-functionally to support intersecting risk programs (e.g., model risk governance/SR 11-7 alignment, BSA/AML technology controls, and data governance) as applicable.
Leads the technology and cybersecurity components of Third-Party Risk Management (TPRM), including onboarding due diligence, periodic reviews, and ongoing monitoring for critical/high-risk vendors.
Defines vendor risk tiering criteria and control requirements for SaaS, cloud, and AI providers; ensure contract provisions address security, privacy, SLAs, and right-to-audit.
Coordinates with Procurement and Legal to ensure contractual risk provisions (e.g., DPA, data handling, incident notification) are implemented and enforced.
Design and implement a continuous controls monitoring (CCM) approach leveraging GRC tooling to automate evidence collection, control attestations, and targeted testing.
Oversees control self-assessments (CSA) across IT domains (identity and access management, change management, vulnerability management, data protection) and validate remediation effectiveness.
Partners with Cybersecurity on security control maturity assessments (CIS Controls, NIST SP 800-53) and annual FFIEC CAT completion.
Leads or co-leads the annual SOC 1/SOC 2 review process for material service providers and support SOX ITGC scoping, testing coordination, and remediation tracking (as applicable).
Builds, leads, and mentors a team of GRC analysts/specialists; establish performance expectations, succession coverage, and professional development pathways.
Drives GRC tool strategy and platform optimization (e.g., ServiceNow GRC, Archer, or equivalent) to enable scalable risk and compliance workflows.
Develops and manages the IT GRC program budget, including tooling, vendor contracts, and staffing plans.
Champions a risk-aware culture through executive communications, training, and proactive engagement with Technology and business teams.
OTHER REQUIREMENTS:
Banking is a highly regulated industry and you will be expected to acquire and maintain a proficiency in the Bank's policies and procedures, and adhere to all laws, rules and regulations that are applicable to your conduct and the work you will be performing. You will also be expected to complete all assigned compliance training in a timely manner.
Proficient in Microsoft Office products including Outlook, Word, PowerPoint and Excel.
Deep working knowledge of FFIEC IT Examination Handbook, NIST CSF , CIS Controls , , and NIST SP 800-63B.
Strong familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001.
Proficiency with ITGC/SOX (as applicable) and SOC 2 review processes.
Working knowledge of cloud risk and compliance considerations (AWS, Azure, or GCP) and shared responsibility models.
Experience configuring and operating GRC platforms (ServiceNow, Archer, or equivalent).
Understanding of networking concepts (e.g., firewalls, VPNs, DNS) and security protocols (e.g., TLS, SSH). ,
Ability to learn other banking systems
Ability to manage or materially contribute to regulatory examinations and audit cycles, including remediation of findings.
Ability to learn new technologies and keep up with industry trends.
Professional demeanor in appearance, interpersonal relations, work ethic and attitude.
Ability to interact effectively across all levels of the organization.
Demonstrated ability to manage multiple priorities and delegate effectively to meet critical deadlines under difficult time restraints.
Understanding of account documentation and retention requirements.
Excellent verbal and written skills and presentation skills with the ability to define and solve problems.
Team player with a positive outlook
Demonstrated leadership ability and skills.
Ability to work independently and meet communicated deadlines.
Excellent analytical, problem-solving and decision-making skills.
Willingness to travel quarterly for onsite meetings.
Bachelor's degree in Information Systems, Computer Science, Business, or related field and/or equal education or experience required
Minimum of 10 years of progressive experience in IT risk, GRC, cybersecurity, or technology audit required.
Minimum of 3 years in a leadership or program management required.
Minimum of 5 years of experience in a regulated financial institution (bank, credit union, or bank holding company); community or regional bank experience preferred.
Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM), Certified Information Systems Auditor (CISA), or Certified Risk & Information Systems Control (CRISC) are desirable.
About WesBanco
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
1,001 - 5,000 Employees
Headquarters location
Wheeling, WV, US
Year founded
1968