IT Risk and Compliance Analyst
$80k - $90kHugeInc
Location: This position is remote within the United States. The role. We are looking for an IT Risk and Compliance Analyst to join the IT Risk and Compliance team and carry the day-to-day execution of the program. This is a generalist role spanning client contracts and security questionnaires, control evidence and gap remediation, vendor risk, data retention and privacy, and the policies that tie it all together.
The program is being rebuilt from the ground up, so you will help shape how the work gets done. The ideal candidate is organized, comfortable with legal and technical language, and able to keep many threads moving at once.
What you’ll be doing. Review client MSAs, SOWs, DPAs, and security addenda using our contract analysis tooling; identify clauses that need Legal, IT, or Delivery attention and coordinate redlines through to signature.
Translate signed contractual obligations (security, privacy, data handling, audit rights, breach notification, sub-processor terms) into tracked commitments and confirm they are being met operationally.
Respond to client security questionnaires, due diligence requests, and audit inquiries; maintain the reusable answer library so responses get faster and more consistent over time.
Collect, organize, and maintain control evidence in the GRC platform; track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks as they are adopted.
Support vendor risk assessments for SaaS and AI providers: review vendor security documentation, DPAs, and sub-processor lists, and record and monitor findings in the vendor register.
Operationalize the data retention and disposal policy: track department retention schedules, document exceptions and legal holds, and verify retention settings across platforms with IT.
Support the privacy program including data mapping, data subject request handling, and GDPR and CCPA obligation tracking.
Draft and maintain compliance policies, SOPs, and process documentation; keep them current, published (for internal use where applicable) and actually followed.
Prepare risk and compliance status reporting for leadership.
Participate in business continuity and disaster recovery planning and tabletop exercises.
Participate in security incident response management.
Maintain and monitor risk register and prepare for annual risk assessment.
Administer security awareness training and track compliance.
Support internal audits, access reviews, and periodic control testing.
What we’d like to see. Bachelor’s degree required or equivalent practical experience.
3–5 years of experience in compliance, GRC, contract management, privacy, or a related field.
Hands-on experience reading and reviewing commercial contracts, ideally MSAs, DPAs, or security addenda, and working with legal counsel on redlines.
Experience responding to client security questionnaires or vendor due diligence requests.
Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, NIST CSF) and what evidence looks like in practice.
Foundational understanding of data privacy regulations (GDPR, CCPA) and how they show up in contracts.
Exceptional organization and follow-through; you can run many parallel threads and nothing slips.
Clear, concise written communication; you can summarize a 40-page contract into the three things that matter.
Comfortable working with SaaS tools and learning new platforms quickly; you like using software to make process better.
Self-directed and effective in a small team where you own outcomes end to end.
This role is currently not available for hire or work in New Mexico, Montana, Alaska and Hawaii, USA.
About Huge. Huge is an independent, human-first AI-native design and technology company. We make things that matter by bringing AI, people, design and technology together as one system. With more than 1,000 design and technology experts working in hub cities around the world, including Bogotá, Chicago, Ho Chi Minh City, London, Los Angeles, Medellín, New York, San Francisco, and Washington, DC, we partner with some of the world’s most ambitious brands, including Google, NBCU, PepsiCo, Vail Resorts, Atlantic Health, and Candescent. Learn more at hugeinc.com.
Huge is committed to creating an inclusive employee experience for all. Regardless of race, gender, religion, sexual orientation, age, disability, or if you’re parenting the next generation of innovators, we firmly believe that our work is at its best when everyone feels free to be their most authentic self.
Huge is an equal opportunity employer (EOE). We strongly support diversity in the workforce. We are committed to an inclusive, barrier-free recruitment and selection process and work environment. If you are contacted for a job opportunity, please advise us of any accommodation needed to ensure you have access to a fair and equitable process. Any information received relating to accommodation will be addressed confidentially.
Workers shall not be required to pay employers’ or agents’ recruitment fees or other related fees for their employment. If any such fees are found to have been paid by workers, such fees shall be repaid to the worker. #LI-POST #LI-Remote
The salary range for this position is as listed below. Exactly where a prospective employee will be paid within this range will depend on, among other factors, the actual salary ranges for current and former employees who are either currently filling a similar role or did in the past; the candidate’s depth of experience and qualifications; the level of specialization the role requires; budgetary considerations; the market demand for that role and the local market conditions that exist where the employee will be based. For current Huge employees, tenure will also be a consideration.
Wage Disclosure
$80,000—$90,000 USD
Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the IT Risk and Compliance Analyst in Remote vacancy
$80k - $90k
...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IT Risk and Compliance Analyst based in United States . This role supports the day-to-day execution of a growing IT risk, compliance, privacy, and...SuggestedContract workRemote work$138.84k - $208k
...ImpactMarvell is seeking an AI Security Compliance Analyst to drive security and compliance across... ...closely cross functionally to identify risks, assess security controls, and support alignment... ...8 years of experience in cybersecurity, IT risk management, security compliance, or...SuggestedPermanent employmentFull timeInternshipWork from home- ...in the insurance space and is looking for an experienced IT Procurement and Compliance Analyst to contribute to the success of this work. This role... ...IT procurement, vendor management, compliance, privacy, risk, governance, audit readiness, and business continuity activities...SuggestedFull timeContract workWork at office
- ...Applicants who now or may in the future require visa sponsorship to work in the United States are not eligible. As our Senior IT Risk & Compliance Analyst, you will help guide how the University of Alaska (UA) manages risk, compliance, and governance across UA's 20+...SuggestedFull timeWork at officeImmediate startRemote workVisa sponsorshipFlexible hoursShift work
$115.5k - $180.53k
ResponsibilitiesPosition OverviewWe are seeking a detail-oriented cybersecurity compliance professional to support system authorization and continuous... ...for one or more information systems in accordance with Federal Risk Management Framework (RMF) requirements.Coordinate activities...SuggestedPermanent employmentFull timeContract workPart timeWork at officeLocal areaRemote work- PATRIOTCLAIMS LLC is seeking a Cybersecurity Risk & Compliance Analyst to strengthen operational security in a HIPAA‑regulated SaaS environment. This remote role reports to the CISO and supports risk governance, incident work, and audit readiness across the organization...Remote job
- ...through tailored solutions based on industry leading practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness, Energy & Sustainability, and Talent Management. We help forward thinking clients solve problems...Full timeContract workTemporary workFor contractorsFor subcontractorWork at officeRemote workFlexible hours
- ...tailored solutions based on industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management | Compliance | Business Process | IT Effectiveness | Engineering | Environmental | Sustainability | Human Capital. We help forward-thinking...Full timeContract workTemporary workFor contractorsFor subcontractorWork at officeRemote workFlexible hours
- ...Privacy, Security, and AI Compliance Specialist Napster Location: Remote - Anywhere... ...incident handling, data mapping, vendor/privacy risk, and AI governance compliance programs... ...in privacy, security compliance, IT audit, GRC, or a related field, including...Full timeRemote workFlexible hours
$80k - $100k
...Information Security, the Information Security Compliance Analyst supports the execution, administration,... ...compliance, governance, and risk management programs. This role is responsible... ...partners with Information Security, IT, Engineering, Product, Legal, Privacy, and...Full timeRemote work- ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- A client with Kforce is seeking a Network Security Risk & Compliance Analyst to join their team in Newport Beach, CA. Summary: This position serves as the primary liaison between Network Security, Cyber Risk, Operational Risk & Resilience (OR&R), Audit, Vulnerability Management...Temporary workRemote work
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more reliable AI systems - and we need practitioners who know how GRC actually works in the real world. If you...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...questionnaires, and audits, documenting evidence and performing risk assessments as needed. Create, maintain, and... ...processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements. Serve as an Information Security subject...Permanent employmentFull timeWork experience placementRemote work
- ...Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance... ...requirements through monitoring and reporting. Collaborate with IT stakeholders to monitor cybersecurity exceptions and other...Hourly payPermanent employmentFull timeLocal areaRemote work
- ...exceptions and data breaks ✅ Collaborate with Treasury, Liquidity Risk, Finance, and IT teams ✅ Maintain reporting controls, procedures, and data... ...Reporting FR 2052a FDIC Reporting Risk & Regulatory Compliance Analytics Data Analysis & Reconciliation...Temporary work
- ...Job Description Job Description Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security...Casual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...ProSidian provides enterprise services/solutions for Risk Management, Compliance, Business Process, IT Effectiveness, Engineering, Environmental, Sustainability... ...at DescriptionProSidian Seeks a Contract Compliance Analyst | Compliance / Risk / Regulatory: Risk, Compliance &...Full timeContract workTemporary workFor contractorsWork at officeRemote workFlexible hours
- ...Corporate, which includes Finance, People and Places, General Counsel, Risk, Internal Audit, Strategy and Development, and Corporate... ....com. Job Description SummaryContribute to an effective compliance program by mitigating legal, regulatory, operational, and reputational...Full timeContract workWork at officeRemote workWorldwideVisa sponsorshipRelocation package3 days per week
- ...practices. ProSidian services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness, Energy & Sustainability, and Talent... ...DescriptionProSidian Seeks a Radiological Compliance Analyst [DOE0111110] for Program Support on a Exempt W2: No...Full timeContract workTemporary workFor contractorsFor subcontractorWork at officeRemote workFlexible hours
- GRC (Governance, Risk & Compliance) Analyst Job Title: GRC (Governance, Risk & Compliance) Analyst Location: India Fully Remote Duration: 12 Months... ...for a GRC (Governance, Risk & Compliance) Analyst to support IT compliance, risk, governance, and controls activities. The...Contract workRemote work
$94k - $104k
...opportunity to work for one of the top law firms in the U.S.! Davis Wright Tremaine LLP is looking for a Junior Governance, Risk & Compliance (GRC) Analyst to join our team in our Seattle, Portland, Anchorage, San Francisco, Los Angeles, New York or Washington D.C. offices....Full timeTemporary workWork at officeRemote workFlexible hours- ...IT Compliance Analyst The IT Compliance Analyst for our client is responsible for ensuring our compliance with Sarbanes-Oxley 404 (SOX) reporting requirements, and assisting in our other Information Technology initiatives, such as implementation of SOX framework, reviewing...Remote work
$67k - $90k
...Senior Compliance Analyst Guild Mortgage Company, closing loans and opening doors since 1960. As a mortgage banking firm we are dedicated... ...agency examinations, and assists in the design and execution of risk-based and other compliance monitoring reviews. This role...Minimum wageWork at officeLocal areaRemote workMonday to FridayNight shift$113.6k - $142k
...Senior Compliance Analyst At SimplePractice, we are improving access to quality care by equipping health and wellness clinicians with all... ...operationalize that interpretation, monitor execution, and escalate risk. Responsibilities Product Compliance Serve as the...Summer workPrivate practiceRemote workFlexible hours- ...Experience of which at least 5 years are of risk and compliance experience at a large company or... ...skilled and experienced Risk & Compliance Analyst to join our dynamic team supporting a... ...fields of cybersecurity, development, IT infrastructure, supply chain management...Temporary workRemote workFlexible hours
- ...millions of Americans to achieve more.About the RoleHappen Bank’s Compliance Team is looking for an experienced compliance data analytics... ...Collaborate with partners across Compliance, Technology, Model Risk Management, and Data Engineering to support deliverablesPerform...Full timeWork at officeLocal areaRemote workRelocationFlexible hours
- ...individual in this position is responsible for administering a compliance program in conjunction with a Chief Compliance Officer, participating... ...Pet Insurance. About ACA: ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We empower...Summer workCasual workWork at officeRemote workFlexible hours2 days per week
- ...every OK-er. #### About the Team The Compliance function is responsible for promoting a... ...sustainable growth of OKX. We are a team of risk-minded problem solvers who advise the... ...Opportunity As the Senior Compliance Analyst for OKX Europe Markets Limited, you will...Full timeLocal area
- ...Kong. \n \n The Role \n \n We are hiring a Senior Compliance & Underwriting Analyst to own merchant underwriting end to end and to strengthen... ...is a hands-on individual reporting directly to the Chief Risk & Compliance Officer. \n We use AI-assisted tooling...Work experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Risk and Compliance Analyst. Be the first to apply!






