IT Risk & Compliance Specialist
$110k - $165kNORC at the University of Chicago
Job no: 503946 Work type: Regular Full-Time Location: Chicago - 300 E Randolph St Capability Area: IT DSS Security and Compliance
JOB SUMMARY:
NORC at the University of Chicago is seeking a seasoned IT Risk and Compliance Specialist to join our Information Technology Department within the DSS Security and Compliance team. This critical role will focus primarily on continuous monitoring of security controls, risks, vulnerabilities, and compliance activities , with additional responsibility for supporting and administering compliance activities within ServiceNow GRC/IRM and conducting internal and external compliance assessments and audits. The ideal candidate will bring strong experience in continuous monitoring, governance, risk, and compliance activities within regulated environments, particularly those supporting Government security requirements such as FedRAMP, CMMC, NIST 800-171, NIST SP 800-53, and ISO 27001. Preferably, this position will have a hybrid work schedule of one or two days a week in either our Washington, DC or Chicago, IL office. Remote applicants may also be considered. DEPARTMENT:Digital Services & Solutions Security & Compliance NORC's Digital Services & Solutions group provides technology services to our staff and clients. Given the critical role technology plays in our day-to-day lives, we are committed to providing professional, high-quality solutions in order to further our collective goal of advancing social science research.RESPONSIBILITIES:
Perform and support continuous monitoring activities across NORC systems and environments to assess the ongoing effectiveness of security controls and identify changes that may impact system risk or compliance. Monitor security and compliance findings, vulnerabilities, control deficiencies, remediation activities, exceptions, and other risk indicators to ensure issues are appropriately documented, assigned, tracked, and resolved. Review continuous monitoring outputs from security and IT tools and work with Security Engineers, system owners, and other stakeholders to evaluate findings, determine compliance impact, and coordinate remediation. Track and report on Corrective Action Plans (CAPs), Plans of Action and Milestones (POA&Ms), control deficiencies, vulnerabilities, exceptions, and remediation activities , including aging, status, ownership, and closure. Perform recurring reviews of security controls and supporting evidence to validate continued compliance with requirements such as FedRAMP, CMMC, NIST 800-171, NIST SP 800-53, ISO 27001, FISMA, HITRUST, and applicable contractual requirements. Conduct Security Impact Analyses (SIAs) and risk assessments for system, infrastructure, application, and configuration changes to determine potential impacts to security controls, compliance requirements, and organizational risk. Utilize and support ServiceNow GRC/IRM to manage controls, risks, issues, findings, evidence, remediation activities, exceptions, and other compliance-related workflows. Maintain accurate and complete GRC records within ServiceNow, ensuring compliance activities, control assessments, findings, risks, and remediation efforts are appropriately documented and traceable. Support the development, configuration, and improvement of ServiceNow GRC/IRM workflows, dashboards, reporting, control mappings, and automated compliance processes to improve visibility and efficiency across the compliance program. Develop and maintain compliance metrics, dashboards, and reporting that provide visibility into control effectiveness, outstanding findings, remediation progress, risk trends, and overall compliance posture. Support internal and external IT compliance audits and assessments , including evidence collection, control validation, documentation review, auditor coordination, and remediation tracking for frameworks such as FedRAMP, CMMC, NIST 800-171, and ISO 27001. Develop, review, and maintain key security and compliance documentation, including System Security Plans (SSPs), Corrective Action Plans (CAPs), POA&Ms, Contingency Plans, control implementation documentation, policies, procedures, and supporting evidence . Collaborate with Security Engineers, system owners, application teams, and other stakeholders to remediate security and compliance issues and maintain alignment with applicable regulatory and contractual requirements. Assist in the development and improvement of policies, procedures, control processes, and automated compliance activities for hybrid and multi-tenant infrastructures. Translate regulatory, contractual, and security control requirements into actionable technical and operational steps for IT teams and system owners. Foster strong, collaborative relationships with NORC’s research community, IT teams, and other key stakeholders to support a culture of security, risk awareness, and continuous compliance.REQUIRED SKILLS:
Bachelor’s Degree in Management Information Systems, Computer Science, Business Administration, or a related field. Equivalent experience in IT security, risk, or compliance may be considered. Current certification in IT security, risk, or compliance, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) . Minimum of 6+ years of experience in IT security, continuous monitoring, risk assessment, compliance, or auditing, with significant experience supporting government security frameworks and contractual requirements. Demonstrated experience performing continuous monitoring activities , including security control reviews, vulnerability and finding management, remediation tracking, compliance evidence review, risk identification, and reporting. Experience performing Security Impact Analyses, risk assessments, and control assessments for information systems and technology changes. Hands-on experience working with ServiceNow GRC/IRM or comparable Governance, Risk, and Compliance platforms , including managing controls, risks, issues, findings, evidence, and remediation activities. Experience developing or maintaining GRC workflows, dashboards, metrics, reporting, and compliance tracking processes . Experience supporting internal and external audits and assessments, including preparing and reviewing System Security Plans (SSPs), Corrective Action Plans (CAPs), POA&Ms, Contingency Plans, and control evidence . Strong working knowledge of security and compliance frameworks, including FedRAMP, CMMC, NIST 800-171, NIST SP 800-53, ISO 27001, FISMA, and HITRUST . Strong understanding of information security controls across infrastructure layers, including networks, servers, databases, cloud environments, and applications. Experience supporting compliance within hybrid and multi-tenant infrastructures and familiarity with privacy requirements such as GDPR, CCPA/CPRA, HIPAA Security Rule, and HIPAA Privacy Rule. Qualified applicants must be eligible to work in the U.S. We regret that we are unable to offer visa sponsorship for this position.SALARY AND BENEFITS:
The pay range for this position is $110,000 – $165,000. This position is classified as regular. Regular staff are eligible for NORC’s comprehensive benefits program. Benefits include, but are not limited to: Generously subsidized health insurance, effective on the first day of employment Dental and vision insurance A defined contribution retirement program, along with a separate voluntary 403(b) retirement program Group life insurance, long-term and short-term disability insurance Benefits that promote work/life balance, including generous paid time off, holidays; paid parental leave, bereavement leave, tuition assistance, and an Employee Assistance Program (EAP). NORC is committed to equity and transparency in its pay practices. We publish salary ranges and benefit information for every job. The listed hiring range reflects what we, in good faith, expect to pay at the time of posting, though actual compensation may vary and may be adjusted over time. A candidate’s placement within the range depends on factors such as competencies, education, qualifications, experience, skills, performance, and organizational needs.WHAT WE DO:
NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions. Since 1941, our teams have conducted groundbreaking studies, created and applied innovative methods and tools, and advanced principles of scientific integrity and collaboration. Today, government, corporate, and nonprofit clients around the world partner with us to transform increasingly complex information into useful knowledge.WHO WE ARE:
For over 80 years, NORC has evolved in many ways, moving the needle with research methods, technical applications and groundbreaking research findings. But our tradition of excellence, passion for innovation, and commitment to collegiality have remained constant components of who we are as a brand, and who each of us is as a member of the NORC team. With world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale.EEO STATEMENT:
NORC is an equal opportunity employer. NORC evaluates qualified applicants without regard to race, color, religion, sex, gender, national origin, disability, status as a protected veteran, sexual orientation, and other legally protected characteristics. Advertised: August 19, 2026 Central Daylight Time Applications close: Open until filled Central Daylight Time #J-18808-Ljbffr NORC at the University of ChicagoVacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Risk & Compliance Specialist in Brooklyn, NY vacancy
$65k - $75k
Customs Compliance Risk Assessment Specialist Job Category : Compliance Requisition Number : COMPL002112 Posted : August 7, 2026 Full-Time Remote Locations Showing 1 location Remote United States Description At Deringer, we are committed to integrity, expertise,...SuggestedFull timeWork at officeRemote work- ...a Contact Center Representative The primary role of this position is to identify, mitigate and prevent fraud risk and financial loss while supporting Compliance with BSA/AML regulations in the Credit Union. This role reviews fraud and compliance alert investigations and...SuggestedApprenticeshipWork at office
$55 - $80 per hour
...IT GRC Analyst Remote, USA Compensation: $55 – $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time... ...a key role in supporting the organization’s IT Governance, Risk, and Compliance (GRC) program, focusing on security governance, regulatory compliance...SuggestedHourly payFull timeContract workWork at officeImmediate startRemote workFlexible hours- Medasource is seeking an IT GRC Analyst to join our IT Security and Governance team on a 6-month contract-to-hire basis, working... ...the USA. The role focuses on security governance, regulatory compliance, risk management, audit readiness, policy administration, and control...SuggestedRemote jobContract work
- Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy,...SuggestedRemote jobContract work
- New American Funding in Santa Ana, CA seeks a Cybersecurity GRC Analyst I, II, or III to support TPCRM through risk assessments, monitoring, and reporting across the vendor ecosystem. The role scales by experience, offering hands-on assessments, SARs, AI risk reviews,...
- ...Cyber Risk AnalystThe Cyber Risk Analyst will serve in the Cyber Command Risk Program under the direction of the Senior Advisor. They... ...following: 2-3 years of experience in cybersecurity risk management, IT auditing, or policy Familiarity with cybersecurity framework(s) (...Full time
- Blue Cross NC is seeking an IT Governance Analyst to help identify, assess, monitor, and mitigate third-party vendor risks across technology, cybersecurity, data privacy, and regulatory... ..., information security, legal and compliance to ensure risk controls align with our...Remote jobFlexible hours
- Blue Cross NC is seeking an IT Governance Analyst to assist in identifying, assessing, monitoring, and mitigating risks from third-party vendors, suppliers, and outsourced providers... ..., information security, legal, and compliance. You’ll develop dashboards and reporting...
$70.8k - $130.5k
...learn, grow, and make an impact. Join us! Job Description: This job is responsible for executing second line of defense compliance and operational risk oversight for CFO Capital activities in Bank of America's US and EMEA entities, with a particular focus on market risk...Full timeWork at officeFlexible hoursShift workDay shift- ...Financial Services Industry. Position Summary: The Information Risk Analyst/Cybersecurity Risk Analyst will be responsible for... ...risks related to how business and technology teams utilize IT systems and supporting technological infrastructure. Key Responsibilities...
- ...Cybersecurity Risk AnalystWe are seeking a Cybersecurity Risk Analyst to join our Information Security Risk team. This role focuses on... ...deficiencies in business processes and technology systems, partnering with IT and business units to communicate risks and agree on findings and...
- Air Liquide in Houston, TX seeks an Information Security Analyst - Business Security and Compliance to uphold governance, risk management, and compliance across Digital & IT environments. Focus on protecting sensitive data and aligning with Global Cyber security Framework...
- We are looking for a Data Analyst with strong expertise in financial risk analysis, refinancing, and ladder management to join our Cloud Commitment Automation team. This person will own the data modeling and analytics required to continuously optimize commitment portfolios...
- Capital One seeks a Senior Risk Associate for the MADI team to model and analyze data, delivering dashboards and insights that inform AML and risk management decisions. The role emphasizes program management, process standardization, and strong stakeholder communication...
$67k - $127k
...Analyst, Quantitative Risk AnalysisNote: Fidelity will not provide immigration sponsorship for this position.The RoleAs an Analyst within Fidelity Risk Group's Quantitative Risk Analysis team, you will be working in a team-based, fast-paced environment. This role will...Full time- ...SMEs, and technology teams to enhance the organization’s data risk posture while supporting both U.S. and Japan-based stakeholders... ...technical stakeholders ~ Highly detail-oriented, organized, and comfortable operating in structured, compliance-driven environments...
- Cohu, Inc. is seeking an IT Risk & Security Specialist to guide on IT risk management for applications and infrastructure, maintain IT risk assessments... ...discussions, and collaborate with cross-functional teams to ensure compliance with corporate #J-18808-Ljbffr Cohu, Inc.
- Regions Financial Corporation in Birmingham, AL seeks a Risk Information Technology and Data Analyst to join IT and Data Risk Management. You will lead risk assessments, monitor controls, and prepare reporting for senior leadership, ensuring alignment with FFIEC, NIST,...
- Provo City is hiring a Cybersecurity Analyst I-II to protect information systems and data. The role analyzes incidents, investigates risks, and coordinates security across departments. The position offers employer-paid health insurance, 401k with matching, generous paid...
- ...strategic direction of the Security GRC team. Leading our security risk management program to prioritize security risks and ensure... ...and high impact goes a long way here. As our Governance, Risk, & Compliance Analyst you should have a minimum of 5+ years of relevant...Local areaRemote workWork from homeHome office
- Job Title: IT Compliance Analyst Location: Tempe, AZ Division: Operations Department: IT Operations About Us Quantum Computing Inc. (QCi... ..., and assessed for effectiveness to reduce overall compliance risk across the organization. This includes performing continuous...Remote work
- CRC Group is seeking an Underwriting Analyst to support underwriters by gathering data, performing preliminary risk assessments, and ensuring accurate documentation. This role emphasizes collaboration with brokers, agents, and internal systems to drive efficient underwriting...Remote job
$160k - $185k
...around the world. Senior Quantitative Analyst, Quantitative & Risk Analytics The Quantitative and Risk Analytics group is hiring a... ...appropriate controls, validation, documentation, and adherence to compliance and data privacy requirements. Maintain strong operational...Local areaFlexible hours3 days per week- Fiduciary Trust International, a premier wealth management firm, seeks a Senior Quantitative Analyst to support portfolio analytics, risk models, and data operations. The role blends quantitative analysis with software development, translating questions into scalable...
$67.13k - $89.52k
## Risk SpecialistBewerbenlocations: Irving, TXtime type: Vollzeitposted on: Gestern... ...Range: $67,130.00 – $89,516.66The Risk Specialist I supports the administration and execution... ...and ensuring accurate documentation and compliance across the organization.**About Us**...Temporary workWork at officeFlexible hours- SCA and DBA Compliance Analyst R0160615 Remote Remote, United States Full time No Clearance Amentum is a global leader in advanced engineering... ...departments to promote organizational integrity, mitigate risks, and ensure adherence to Code of Conduct. The ideal candidate is...Hourly payFull timeContract workWork experience placementFor subcontractorWork at officeLocal areaRemote work
- F.N.B. Corporation in Pittsburgh, PA is seeking a Sanctions Compliance Program Analyst 2. The role supports the Risk - BSA/AML unit, reviewing sanctions alerts and maintaining compliant records. Hours are 9 AM - 6 PM, with a focus on regulatory obligation at the transactional...
- First Fed is seeking a BSA Specialist I to monitor and review alerts, conduct CDD/EDD reviews, and file CTRs to support regulatory compliance. The role involves gathering information from customers and internal systems, escalating complex cases, and maintaining accurate...
- Capital One is seeking a Compliance Advisor Principal Associate to assess regulatory alignment of code/script logic in CoDIR reviews and... ...compliance requirements to scripting activities and support MoCIRA risk assessments. The role requires a bachelor’s degree and 2+ years...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Risk & Compliance Specialist. Be the first to apply!
Related searches
- entry level IT support specialist Brooklyn, NY
- senior IT support specialist Brooklyn, NY
- IT support specialist Brooklyn, NY
- computer operator Brooklyn, NY
- IT technician Brooklyn, NY
- executive IT support specialist Brooklyn, NY
- IT specialist Brooklyn, NY
- third party risk analyst Brooklyn, NY
- senior quantitative risk analyst Brooklyn, NY
- it risk analyst Brooklyn, NY


