IT Risk & Compliance Analyst
National Opinion Research Center - NORC
JOB SUMMARY:
NORC at the University of Chicago is seeking an IT Risk & Compliance Analyst to join our DSS Security & Compliance team. This role is primarily responsible for supporting NORC's FedRAMP Continuous Monitoring Program , ensuring the ongoing effectiveness of security controls and maintaining compliance with FedRAMP requirements. Working closely with engineering, cloud operations, infrastructure, development, and business teams, the analyst will help assess security control effectiveness, coordinate compliance activities, collect and validate evidence, track remediation efforts, and support ongoing audit readiness. In addition to FedRAMP, the role supports NORC's enterprise governance, risk, and compliance (GRC) program across NIST SP 800-53 Rev. 5, CMMC, ISO 27001, SOC 2, HIPAA, and customer-specific security requirements. The successful candidate will contribute to the continued maturity of NORC's security compliance program by improving continuous monitoring processes, strengthening governance practices, developing compliance metrics, and identifying opportunities to automate and streamline compliance activities. Citizenship: U.S. Citizenship required due to federal project requirements. DEPARTMENT: Digital Data Services & Solutions (DDS) NORC's Digital Services & Solutions (DSS) organization provides enterprise technology services that enable research, innovation, and client success. The Security & Compliance team partners across the organization to strengthen cybersecurity, reduce organizational risk, and maintain compliance with government, client, and industry security requirements.RESPONSIBILITIES:
Serve as a primary contributor to NORC's FedRAMP Continuous Monitoring Program , coordinating recurring activities required to maintain FedRAMP authorization. Coordinate monthly, quarterly, annual, and ongoing FedRAMP Continuous Monitoring activities, including evidence collection, security control assessments, vulnerability management, POA&M management, metrics reporting, and security documentation updates. Monitor the effectiveness of administrative, technical, and operational security controls across cloud and enterprise environments. Partner with engineering, cloud, infrastructure, and operations teams to validate security controls, resolve compliance findings, and improve overall security posture. Track security findings, vulnerabilities, and remediation efforts to ensure compliance with FedRAMP and other applicable security requirements. Develop, review, validate, and maintain security documentation, including policies, standards, procedures, System Security Plans (SSPs), control implementation statements, and supporting compliance evidence. Support internal and external audits by coordinating evidence requests, responding to assessor questions, and managing remediation activities. Assist in developing compliance dashboards, metrics, and executive reporting that measure security posture, control effectiveness, and continuous monitoring performance. Support governance and compliance initiatives across NIST SP 800-53 Rev. 5, CMMC, ISO 27001, SOC 2, HIPAA, and customer-specific requirements. Identify opportunities to improve compliance processes through automation, standardization, and continuous improvement. Provide guidance to technical and business teams regarding security requirements, compliance obligations, and cybersecurity best practices. Support Authorization to Operate (ATO) activities, annual assessments, and significant system changes as needed.REQUIRED SKILLS:
Education & Certifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent professional experience). CAP, CGRC, CISSP, CISM, CISA or other cybersecurity certification preferred. 1. FedRAMP Continuous Monitoring & Compliance (Primary Focus) Minimum of two years of experience supporting cybersecurity, governance, risk, or compliance programs. Experience supporting or maintaining a FedRAMP Authorized or FedRAMP Ready cloud environment is strongly preferred. Knowledge of FedRAMP Continuous Monitoring requirements, including monthly, quarterly, annual, and significant change activities. Experience coordinating evidence collection, security control assessments, vulnerability management, remediation tracking, POA&M management, and compliance reporting. Experience monitoring security control effectiveness and partnering with technical teams to resolve compliance findings. Experience supporting internal or external assessments and audit activities.REQUIRED SKILLS: ... we have Education & Certifications, then 1..5 sections. We'll produce exactly as previous drafting but trimmed. Ensure we don't use ellipsis. Let's create final content fully. I'll write entire string inside JSON #J-18808-Ljbffr National Opinion Research Center - NORCVacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the IT Risk & Compliance Analyst in Chicago, IL vacancy
- 247Hire is seeking a Senior IT Risk and Compliance Analyst to support the Bank's GRC, Enterprise Risk Management, and SOX compliance. The role involves collaborating with IT teams to map processes, identify technology risk, and design controls aligned with COSO, COBIT,...Suggested
- Job Description - add details here Job Description: The Senior IT Risk and Compliance Analyst will aid in supporting the Information Technology department’s adherence to the Bank’s Governance, Risk & Compliance (GRC) framework, Enterprise Risk Management framework, and...Suggested
- Jobtailor is seeking a detail-oriented professional to support compliance, privacy, and risk management initiatives. This role involves coordinating annual training, reporting, and stakeholder attestation, while ensuring documentation accuracy across the policy landscape...Suggested
- ...GRC Analyst The GRC Analyst is a member of the IT Security team and works closely with other IT teams and business... ...program through the development and compliance of IT Security policies and... ...in onsite and virtual audits and risk remediation. Support the GRC program...Suggested
$77k - $202k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior AssociateJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining regulatory compliance and managing risks for clients,...SuggestedFull timeH1b- Above Lending, a next-generation financial services company, seeks a detail‑oriented professional to support compliance testing and third‑party risk processes. This hybrid Chicago role offers cross‑functional exposure and growth opportunities, focusing on BSA/AML/OFAC controls...
- recruit22 is looking for a Governance, Risk & Compliance (GRC) Analyst to join one of our clients in the healthcare sector. The Governance, Risk & Compliance... .... 2 or more years of experience in Information Security, IT Security, or IT Risk Management. Familiarity with GRC...
$130k - $160k
...your unique viewpoint matter. Learn about the Danaher Business System which makes everything possible.The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk activities across the vendor lifecycle and contributing to enterprise...Full timeRemote workWork from homeFlexible hours- TC Energy is seeking an Environmental Analyst to develop and manage environmental programs, ensuring compliance with federal and state regulations across Illinois, Iowa... ...Management and Operations to communicate goals, manage risks, and deliver regulatory reports and...
$105k - $130k
...help to manage and reduce the organization’s information security risks through continuous management & reporting relating to the NIST... ...supporting resource for the timely completion of Internal & External IT audit evidence requests, questions, and action items. The...Work at officeLocal areaFlexible hours3 days per week- Early Warning Services LLC in Chicago, IL is seeking a Sr. Data Analyst - Risk Management to support the enterprise risk program across the... ...reports for ERM committees, collaborating with Product, Legal, IT, Operations, and Finance. A bachelor’s degree in accounting/finance...
$85k - $100k
...possible, full time / part time, permanent About the role As a Risk Market Data Analyst at RWEST, you will be responsible for the daily provision of... ...with other Risk departments, Front Office, Back Office, and IT teams in a cross-functional environment. In addition, you...Permanent employmentFull timePart timeImmediate startFlexible hours- ...hiring a skilled Information Assurance and Compliance Analyst to join our cybersecurity team. This is... ...the stringent requirements of federal IT environments. Its flagship offering, KeeperPAM... ...’s commitment to data protection, risk management, and regulatory compliance. Responsibilities...Temporary workRemote work
- Information Assurance and Compliance Analyst Remote, US Keeper is hiring a skilled Information Assurance... ...the stringent requirements of federal IT environments. Its flagship offering,... ...organization’s commitment to data protection, risk management, and regulatory compliance....Temporary workRemote work
- Information Assurance and Compliance Analyst Remote, US Keeper is hiring a skilled Information Assurance... ...the stringent requirements of federal IT environments. Its flagship offering,... ...organization’s commitment to data protection, risk management, and regulatory compliance....Temporary workRemote work
- Invenergy LLC in Chicago is seeking an Analyst II, Information and Cyber Security to join a growing governance, risk, and compliance program. You will support security controls, policy... ...across the enterprise, working with Legal, IT, and security teams. This role offers...
$57k - $113k
..., MI Chicago, IL Charlotte, NC Summary The Sr GRC Programmer/Analyst modifies existing software/application programs, which are typically... ...on customer service, and the ability to work well with other IT, vendor, and business groups. Microsoft Office experience....Full timeH1bWork at officeRemote workWork from homeFlexible hours$90k
...Today, Akuna operates from additional offices in Sydney, Shanghai, London and Singapore. What you'll do as a Junior Quantitative Risk Analyst at Akuna We are looking for a motivated and talented individual to join our growing Risk Department. This role is part of a...Work at office$77k - $202k
...AssociateJob Description & SummaryThe OpportunityAs a Data Validation Risk - Senior Associate, you will play a pivotal role in transforming... ...cloud platforms such as AWS and Azure- Experience related to IT Audit/SOX or Data Migration/Conversion/Integration - Embracing change...Full timeH1b- A leading recruitment firm is seeking a Governance, Risk & Compliance (GRC) Analyst in Chicago to enhance risk management strategies within the healthcare... ...and security policies. Ideal candidates have 2+ years in IT Security and familiarity with cybersecurity frameworks...
- Bank of America is seeking a Quantitative Financial Analyst within Global Risk Analytics. The role focuses on developing and validating models,... ...delivering analytic solutions for risk measurement and regulatory compliance. You will work with FLU model owners and stakeholders to...
- Akuna Capital in Chicago is seeking a Junior Quantitative Risk Analyst to join the Risk Department. You will work on measuring and controlling market and execution risks, collaborating with developers and analysts to build protections around trading and to enhance risk...
$90k - $110k
...candidate will lead projects with 2-3 levels of Cyber Security Analysts under them as related to technology refresh/evaluation such as Load... ...during normal times. REQUIREMENTS Minimum of 4-5 years of IT auditing and systems experience with a focus on information security...Work experience placementSummer work- ...role focused on managing and reporting information security risks. This position, based in Chicago, requires at least three... ...onsite. You'll collaborate with global teams to enhance IT controls and ensure compliance with audit requirements. Successful candidates will have...3 days per week
- ...environment, business leaders face constantly shifting risks. Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with... ...development, enterprise risk management, and IT and cybersecurity risk assessment. The...Full timeContract workShift work
- BCG Attorney Search is seeking an associate with 3-6 years of experience to join its Digital Risk Advisory and Cybersecurity Team in Chicago, IL. The attorney will advise clients on cybersecurity incidents, regulatory investigations, and related advisory services such...
$74k - $138k
...development and continuous improvement of the data management risk governance framework, including standards, controls, and risk appetite... ...by evaluating risk exposures, control effectiveness, and compliance, and identifying emerging risks to inform decision‑making and escalation...Local area$84k - $105k
...employment Visa sponsorship. Overall Purpose The Sr. Data Analyst - Risk Management will support the Senior Director of Enterprise... ...an organization, including Product Development, Legal/Compliance, Operations, IT, and Accounting/Finance. Excellent interpersonal skills....Hourly payWork at officeImmediate startVisa sponsorshipWork visaFlexible hours$119k - $193k
Phase2 Technology is seeking a Senior Analyst to conduct research and provide strategic advice to risk management leaders. The ideal candidate will possess a deep... ...of risk management trends, practices, and compliance management. This role involves producing reports...$80 per hour
Position OverviewWe are seeking an experienced Risk Management Consultant to support our Information Technology Risk Management (ITRM... ...methodologies.Experience working with governance, risk, and compliance (GRC) platforms, preferably OneTrust.Ability to collaborate with...Full timeContract workTemporary workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Risk & Compliance Analyst. Be the first to apply!
Related searches
- risk compliance officer Chicago, IL
- it risk analyst Chicago, IL
- governance risk & compliance analyst Chicago, IL
- transaction risk analyst Chicago, IL
- senior quantitative risk analyst Chicago, IL
- operational risk specialist Chicago, IL
- operational risk consultant Chicago, IL
- third party risk analyst Chicago, IL
- information risk analyst Chicago, IL
- risk analyst Chicago, IL

