Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Risk and Compliance Analyst

$80k - $90k
Full-time

jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IT Risk and Compliance Analyst based in United States .

This role supports the day-to-day execution of a growing IT risk, compliance, privacy, and governance program.
You will work across contracts, security questionnaires, control evidence, vendor risk, data retention, and compliance policies.
The position offers the opportunity to help shape a program being rebuilt from the ground up and establish scalable ways of working.
You will collaborate with Legal, IT, Delivery, leadership, vendors, and other stakeholders to translate requirements into practical controls and actions.
The role combines technical and legal concepts with hands-on program coordination, risk management, and process improvement.
Success requires exceptional organization, strong written communication, sound judgment, and the ability to manage multiple priorities independently.
This is an ideal opportunity for a compliance professional who enjoys ownership, variety, and building effective processes within a collaborative environment.

Accountabilities:

  • Review client MSAs, SOWs, DPAs, security addenda, and related agreements using contract analysis tools, identifying provisions requiring attention from Legal, IT, Delivery, or other stakeholders and coordinating redlines through completion.
  • Translate contractual security, privacy, data handling, audit, breach notification, and sub-processor requirements into trackable operational commitments and verify that obligations are being met.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries while maintaining and improving a reusable knowledge base to make future responses faster and more consistent.
  • Collect, organize, maintain, and manage control evidence within the GRC platform, tracking remediation activities against frameworks such as SOC 2, ISO 27001, NIST CSF, and other applicable standards.
  • Support vendor risk management activities for SaaS and AI providers by reviewing security documentation, DPAs, sub-processor information, and findings, while maintaining accurate vendor risk records.
  • Operationalize data retention and disposal requirements by tracking departmental retention schedules, documenting exceptions and legal holds, and working with IT to verify retention settings across relevant platforms.
  • Support privacy program activities including data mapping, data subject request processes, and monitoring obligations associated with GDPR, CCPA, and other applicable privacy requirements.
  • Draft, maintain, publish, and improve compliance policies, standard operating procedures, and process documentation, ensuring that requirements remain current and are effectively implemented.
  • Prepare risk and compliance reporting for leadership, highlighting program status, emerging risks, remediation progress, and areas requiring attention.
  • Maintain and monitor the risk register, support annual risk assessments, and contribute to the identification, evaluation, and treatment of organizational risks.
  • Participate in business continuity and disaster recovery planning, tabletop exercises, security incident response, internal audits, access reviews, and periodic control testing.
  • Administer security awareness training programs and monitor completion and compliance across the organization.

Requirements

  • Bachelor’s degree or equivalent practical experience, with 3–5 years of professional experience in compliance, GRC, contract management, privacy, risk, or a related field.
  • Hands-on experience reviewing commercial agreements, ideally including MSAs, DPAs, security addenda, or similar documents, with the ability to collaborate effectively with legal counsel on contractual redlines.
  • Experience responding to client security questionnaires, vendor due diligence requests, audit inquiries, or comparable compliance information requests.
  • Working knowledge of at least one major security or compliance framework, such as SOC 2, ISO 27001, or NIST CSF, including a practical understanding of the evidence required to demonstrate control effectiveness.
  • Foundational understanding of data privacy regulations such as GDPR and CCPA, particularly how privacy requirements translate into contracts, operational processes, and compliance obligations.
  • Exceptional organizational and follow-through skills, with the ability to manage numerous parallel workstreams, deadlines, stakeholders, and remediation activities without losing attention to detail.
  • Clear, concise, and confident written communication skills, including the ability to interpret complex technical or legal information and distill it into practical priorities and recommendations.
  • Strong analytical, problem-solving, and judgment skills, with the ability to identify gaps, assess risks, coordinate solutions, and follow issues through to resolution.
  • Comfortable working with SaaS platforms, GRC systems, contract analysis tools, and other technology, with a demonstrated ability to learn new systems quickly and use technology to improve processes.
  • Self-directed and accountable, with the ability to own outcomes end to end while working effectively within a small, collaborative team.
  • Comfortable working across technical, legal, operational, and business functions and translating requirements between different stakeholder groups.

Benefits

  • Salary range of $80,000–$90,000 USD .
  • Remote working arrangement within the United States.
  • Opportunity to help build and shape an IT risk and compliance program from the ground up.
  • Broad exposure to IT risk, compliance, privacy, vendor management, contracts, security operations, and governance.
  • Collaborative and inclusive work environment that values diverse perspectives and authentic contributions.
  • Opportunities to work closely with cross-functional teams across legal, technology, delivery, security, and leadership functions.
  • Meaningful ownership and autonomy within a growing compliance program.
  • Opportunity to contribute to process improvement and the development of scalable compliance practices.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IT Risk and Compliance Analyst in United States vacancy
  • $74.28k - $98.5k

     ...of Denver (CCD) approaches Governance, Risk, and Compliance (GRC) holistically ensuring that risks...  ...The Governance, Risk, and Compliance Analyst position is a key stakeholder on the CCD...  ...Everything Else Job Profile CI3432 IT Data Protection Analyst Associate To... 
    Suggested
    Full time
    Contract work
    Work at office
    Local area
    2 days per week

    City and County of Denver

    Denver, CO
    4 days ago
  • $70k - $85k

     ...the control processes to ensure Canopy's compliance with ITGC and ICFR. Assist in the integration...  ...resources as required to facilitate IT controls evaluation. Liaise with...  ...Experience (3+ years) with IT governance, risk, and compliance management. Excellent... 
    Suggested
    Full time
    Remote work

    Canopy Growth

    United States
    2 days ago
  • $100k - $130k

     ...company) is growing its Information Technology Compliance (ITC) team, and we’re looking for an IT Compliance Analyst to help build what comes next. ITC owns the development...  ..., implementation, and management of NYSE’s risk-based IT compliance program, keeping our... 
    Suggested
    Full time
    Work at office
    Monday to Friday

    Ice Services

    New York, NY
    4 days ago
  • $138.84k - $208k

     ...ImpactMarvell is seeking an AI Security Compliance Analyst to drive security and compliance across...  ...closely cross functionally to identify risks, assess security controls, and support alignment...  ...8 years of experience in cybersecurity, IT risk management, security compliance, or... 
    Suggested
    Permanent employment
    Full time
    Internship
    Work from home

    Marvell

    Santa Clara, CA
    3 days ago
  • $111.2k - $139k

     ...future together. The Crown Is Yours As a Senior Technical Compliance Analyst, you’ll strengthen our technical compliance programs and help...  ...you’ll shape evidence strategies, validate controls, address risks, and provide clear guidance to stakeholders. Your work will also... 
    Suggested
    Full time
    Immediate start

    National Geographic

    Boston, MA
    5 days ago
  • $80k - $90k

     ...Location: This position is remote within the United States. The role. We are looking for a Compliance Officer to join the IT Risk and Compliance team and carry the day-to-day execution of the program. This is a generalist role spanning client contracts and security... 
    Contract work
    Currently hiring
    Local area
    Remote work

    HugeInc

    Remote
    1 day ago
  • $143k - $218k

     ...from a LinkedIn office on select days, as determined by the business needs of the team. LinkedIn is seeking a Senior Technical Risk & Compliance Engineer to support the end-to-end GRACE lifecycle across Security. Governance, Risk, Automation, Compliance & Engineering (... 
    For contractors
    Work at office
    Flexible hours

    Linkedin

    Mountain View, CA
    2 days ago
  •  ...communities are what push us forward and make this a truly special place to be. The Senior Technical Compliance Analyst is an integral team member of the QTS Security Risk & Compliance Team and reports to the Manager, Information Security Compliance & Risk. QTS has... 
    Immediate start

    QTS Realty Trust

    Overland Park, KS
    4 days ago
  • $131.3k - $177.6k

     ...practices, optimizing performance, and managing risks throughout the project. The AWS...  ...PREFERRED QUALIFICATIONS - 5+ years of IT implementation experience - degree in advanced...  ...- Knowledge of security and compliance standards including HIPAA and GDPR - Experience... 
    Flexible hours

    Amazon Web Services, Inc.

    Herndon, VA
    23 hours ago
  •  ...Description We are seeking a Cybersecurity Analyst to join our team! You will support...  ...below) Minimum 5 years of NIST Risk Management Framework experience Minimum...  ...: ·         Analyze IT environments for compliance with NIST security controls. ·... 
    Remote work

    Trubest Enterprise Solutions LLC

    Norfolk, VA
    a month ago
  •  ...in the insurance space and is looking for an experienced IT Procurement and Compliance Analyst to contribute to the success of this work. This role...  ...IT procurement, vendor management, compliance, privacy, risk, governance, audit readiness, and business continuity activities... 
    Full time
    Contract work
    Work at office

    Northwest Partners

    Remote
    2 days ago
  •  ...Applicants who now or may in the future require visa sponsorship to work in the United States are not eligible. As our Senior IT Risk & Compliance Analyst, you will help guide how the University of Alaska (UA) manages risk, compliance, and governance across UA's 20+... 
    Full time
    Work at office
    Immediate start
    Remote work
    Visa sponsorship
    Flexible hours
    Shift work

    University of Alaska Fairbanks

    Fairbanks, AK
    6 days ago
  •  ...Cybersecurity Risk & Compliance AnalystVoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst to help formalize and scale our risk governance, compliance, and policy framework across both IT and operational environments.This role is central to evolving our cybersecurity... 
    Local area

    VoltaGrid

    Houston, TX
    3 days ago
  • $87.5k - $109.35k

     ...position. The anticipated pay for new hires entering as a Sr. IT Procurement & Compliance Analyst is between $87,500 to $109,350. Pay is based on non-...  ..., procurement, vendor management, compliance, privacy, risk, and governance activities through effective coordination... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work visa

    USAble Life

    Remote
    6 days ago
  • $70k - $90k

    Join to apply for the Cybersecurity Compliance Analyst role at New York eHealth Collaborative Pay Range This range is provided by New York eHealth...  .... The analyst collaborates across departments to assess risk, support audits, and drive continuous improvement in... 
    Full time
    Work at office
    1 day per week

    New York eHealth Collaborative

    Albany, NY
    3 days ago
  • $65k - $85k

     ...most. Role Description The Cybersecurity Compliance Analyst is responsible for supporting and...  ...role works closely with Cybersecurity, IT, Engineering, DevOps, Legal, and other business...  ...artifacts within applicable Governance, Risk, and Compliance (GRC) platforms or... 
    Work at office
    Local area
    Flexible hours
    Night shift

    ICEYE US

    Herndon, VA
    5 days ago
  •  ...has an exciting full‑time employment opportunity for an IT Third Party and Compliance Analyst in the Technology Department of various office locations...  ...an excellent benefits package. Position Summary The IT Risk and Compliance Analyst will take a lead in the ongoing design... 
    Full time
    Work experience placement
    Work at office

    100KCrossing

    Boston, MA
    2 days ago
  • $56 per hour

     ...IT Risk And Compliance Analyst Hybrid Chicago, NY Rate: $56 Experience 7+ Must Haves: ~ Strong communication skills to all levels, with previous experience of writing reports for senior staff ~ Experience of ITIL ~ Project Management experience ~ Degree... 

    Kasmo Global

    Chicago, IL
    5 days ago
  •  ...IT Risk and Compliance Analyst Location: New York/Chicago, IL office at least 2-3 days a week Duration: 6+ months Contract Must Haves: ~ Strong communication skills to all levels, with previous experience of writing reports for senior staff ~ Experience of... 
    Contract work
    Work at office
    2 days per week
    3 days per week

    Veracity Solutions

    Chicago, IL
    2 days ago
  • Job Requirements Position SummaryThe Senior IT GRC Coordinator, reporting to the Chief Information Security Officer (CISO), leads the Information Technology Governance, Risk, and Compliance program within Information Technology. This role is responsible for IT documentation... 

    Spartanburg Regional Medical Center

    Spartanburg, SC
    1 day ago
  • Risk and Compliance Systems Analyst - Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid - 3 days per week on site at HDQ (Vienna, VA) preferred; team will consider GPO (Pensacola, FL) for the right candidate.... 
    For contractors
    3 days per week

    Apex Systems

    Merrifield, VA
    3 days ago
  • City of Phoenix is seeking a Cybersecurity Risk and Compliance Analyst (Sr. BSA) to join the Information Security Office in a hybrid role. You will bridge security with business goals, manage risk assessments, audit prep, remediation tracking, and policy implementation... 
    Work at office

    City of Phoenix

    Phoenix, AZ
    4 days ago
  • $70k - $100k

     ...Bank is seeking a highly motivated and detail-oriented Compliance Reporting & Regulatory Change Analyst to support compliance reporting, governance, and...  ...Board. Analyze data and trends; develop and refine key risk indicators, dashboards, metrics, and reporting methodologies... 
    Work experience placement
    Work at office
    Local area
    Flexible hours

    Provident Bank

    Woodbridge, NJ
    4 days ago
  • $90k - $105k

     ...and detail-oriented Information Security compliance analyst to be responsible for monitoring the...  ...Will You Be Doing? Manage cybersecurity risk processes, including risk registers, findings...  ...in partnership with Legal, Compliance, IT, and business leaders. Support... 
    Contract work
    For subcontractor
    Work at office
    Local area

    Vestwell

    Austin, TX
    19 days ago
  •  ...Position Summary: The Information Security & Compliance Analyst supports the organization's cybersecurity governance, risk management, and compliance initiatives. This role...  .... The analyst will work closely with IT, business leaders, project teams, customers, and... 
    Full time

    Barnhart Crane & Rigging

    Memphis, TN
    20 days ago
  • $80k - $100k

     ...Information Security, the Information Security Compliance Analyst supports the execution, administration,...  ...compliance, governance, and risk management programs. This role is responsible...  ...partners with Information Security, IT, Engineering, Product, Legal, Privacy, and... 
    Full time
    Remote work

    ImageTrend

    Eagan, MN
    a month ago
  • $80k - $100k

     ...Cybersecurity/GRC Compliance Analyst Location: 100% Onsite – Candidates must already reside within commuting distance of the Orlando...  ...Analyst with 5+ years of experience in cybersecurity compliance, IT audit, risk, governance, or a highly regulated environment. You’ll... 
    Full time
    Work at office
    Orlando, FL
    13 hours ago
  •  ...Job Description Job Description NETWORK SECURITY RISK AND COMPLIANCE ANALYST II   Location; Newport Beach, CA   JOB DESCRIPTION   The Network Security Risk and Compliance Analyst serves as the primary liaison between Network Security, Cyber Risk... 
    Contract work
    Interim role
    Remote work

    Platinum Resource Group

    Los Angeles, CA
    12 days ago
  • A client with Kforce is seeking a Network Security Risk & Compliance Analyst to join their team in Newport Beach, CA. Summary: This position serves as the primary liaison between Network Security, Cyber Risk, Operational Risk & Resilience (OR&R), Audit, Vulnerability Management... 
    Temporary work
    Remote work
    Newport Beach, CA
    13 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Risk and Compliance Analyst. Be the first to apply!