IT Risk & Compliance Analyst (Hybrid)
$75k - $107kIntact Services USA LLC
Job Description
Job Description
Our employees are at the heart of what we do: helping people, businesses and society prosper in good times and be resilient in bad times. When you join our team, you are bringing this purpose to life alongside a passionate community.
Feel empowered to learn and grow while being valued for who you are. At Intact, we commit to supporting you in reaching your goals with tools, opportunities, and flexibility. It’s our promise to you.
Who we are
At Intact Insurance Specialty Solutions, we are experts at what we do in protecting what makes businesses unique. Our deep understanding of the specialty insurance market is the foundation for our customized solutions, backed by targeted risk control and claims services. Our employees are passionate about providing insurance coverage that’s aligned to our targeted customer groups.
Intact’s Global Specialty Lines business spans across more than 20 verticals in four distinct markets: U.S., Canada, UK and Europe. The following opportunity is for our U.S. team.
The opportunity
We currently have an opportunity for an IT Risk & Compliance Analyst to join our Corporate IT team based in our Canton, MA; Boston, MA; Farmington, CT or Raleigh, NC offices on a hybrid schedule. The IT Risk & Compliance Analyst supports the organization’s IT Risk / GRC function by collecting, organizing, analyzing, and reporting information related to cybersecurity risk, control performance, audit response, remediation tracking, and security metrics. This is a hands-on individual contributor role where one person may support multiple related activities across governance, risk, compliance, cybersecurity metrics, and audit coordination all aligned with the NIST framework.
The analyst works with and contributes to IT, cybersecurity, infrastructure, identity and access management, vulnerability management, and audit stakeholders to help organize evidence, track action items, maintain accurate status reporting, and translate technical information into clear management-ready reporting. The ideal candidate is highly organized, analytical, comfortable learning new cybersecurity domains, and able to follow up consistently across multiple teams and deadlines. Some of the IT Risk & Compliance Analyst responsibilities include but are not limited to:
- Maintain organized records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status.
- Collect and validate information from control owners and technical teams to support risk reviews, control assessments, compliance activities, cybersecurity metrics, and management reporting.
- Coordinate audit response activities across internal and external auditors in multiple geographic regions and IT, security, infrastructure, compliance, and business stakeholders.
- Track audit requests, evidence, responses, findings, remediation actions, retesting, risk acceptances, compensating controls, owners, deadlines, and closure; identify blockers and escalate overdue or unclear items as appropriate.
- Help IT and security teams develop clear, well-supported responses to audit findings and maintain evidence in an organized, repeatable, and auditable manner.
- Collect, organize, and analyze cybersecurity and IT risk metrics across vulnerability management, identity and access management, endpoint protection, incident response, infrastructure operations, logging, and monitoring.
- Develop accurate reports, dashboards, and management-ready summaries using tools such as Excel, PowerPoint, SharePoint, ticketing systems, and other available reporting platforms.
- Analyze trends, gaps, aging items, control exceptions, and remediation progress, and translate technical security information into business-relevant insights for leadership, risk committees, auditors, and non-technical audiences.
- Define and maintain consistent metric definitions, data owners, source systems, refresh schedules, assumptions, and limitations.
- Create and maintain trackers, checklists, evidence logs, reporting calendars, process maps, and follow-up routines that improve consistency, accuracy, timeliness, and repeatability of risk, audit, and security reporting.
- Coordinate application security and penetration testing for internally developed, SaaS, web, mobile, API, cloud, and vendor-hosted applications, including scoping, scheduling, execution support, findings tracking, remediation validation, and retesting through closure.
- Support application security governance by maintaining application inventories, promoting secure software development practices, preparing management reporting, and aligning testing with organizational and regulatory requirements.
- Apply recognized cybersecurity and control frameworks, including NIST-based terminology, under leadership guidance.
- Clarify ownership, next steps, and response dates; follow up consistently and communicate professionally with stakeholders while maintaining a collaborative, service-oriented approach.
- Escalate material risks, delays, unresolved ownership, and data quality concerns, and promote accountability and continuous improvement across IT risk and security operations.
The expertise you bring
- Management, Audit, Accounting, or a related field, or equivalent relevant experience.
- Three (3) to five (5) years of experience in IT risk, GRC, information security, IT audit, technology controls, security operations, or a related function.
- Experience in insurance, financial services, healthcare, utilities, or another regulated or compliance-intensive industry is preferred.
- Relevant professional certifications, such as Security+, CISA, CRISC, CISM, CISSP, CGRC, or ITIL Foundation, are preferred but not required.
Our salary ranges are determined by many factors including location, role, experience and skillset of the candidate. The following ranges displayed reflect the target base salary for new hires; however, your recruiter will provide more specific compensation details during the hiring process. The typical base salary range for this position is: $75,000 - $107,000, based on the factors aforementioned. For candidates located in San Francisco, CA; Washington DC; our Massachusetts based offices and the New York City metro area, the base salary range is $95,000 - $110,000. In addition to base salary, full time Intact employees are also eligible for bonus potential and a full range of benefits to include but not limited to:
- Comprehensive medical, dental and vision insurance with no waiting period
- Competitive paid time off programs
- 401(k) savings and annual contributions of up to 12% of annual salary
- Mental health support programs, life and disability insurance, paid parental leave and a variety of additional voluntary benefits
This position will remain posted until a final candidate is selected. Once the role is filled, this job posting will be removed.
Why choose Intact
We live our Values: We are committed to acting with the highest of ethical standards through our five core values: integrity, respect, customer driven, excellence and social responsibility.
Our commitment to Diversity: Founded in our values, we see diversity as a strength and aspire to create an environment where everyone can be themselves, grow and succeed. Together, we will stand up for what’s right to build an inclusive society.
Manage your Time: What you accomplish matters more than hours in the office. We are committed to creating a positive and supportive environment in which you perform your best. Our Time-Off and Flexible Work Arrangement options help foster a healthy work-life balance.
Check out our Glassdoor reviews to see why people love working for Intact!
Our promise to you
Our Values are foundational to our success at Intact. You’ll make a difference every day when you live our Values, do your best work, are open to change, and invest in yourself.
In return, we promise you support, opportunities and performance-led financial rewards in a flexible work environment where you can:
- Shape the future: Help us lead an insurance transformation to better protect people, businesses and society.
- Win as a team: Collaborate with inspiring people to do your best work every day and together, stand up for what is right.
- Grow with us: Refresh and reinvent your skills, learn from our diverse teams, lift others up, and grow.
About Intact
At Intact Insurance Specialty Solutions we are experts at what we do. Our deep understanding of the specialty insurance market is the foundation for our customized solutions, backed by targeted risk control and claims services. Our employees are passionate about providing insurance coverage that’s aligned to our targeted customer groups. Today, we help protect over a dozen industries with tailored coverages and services.
#LI-DNP
- ...Flexibility: Remote or Hybrid or OnsiteWhy ARA at Stryker?The Assurance & Risk Advisory (ARA) function... ...Senior Technology Risk Analyst to play a critical role... ...engagements, including SOX compliance testing, system implementation... ...in the auditing of IT general controls (ITGCs)...SuggestedFull timeFor contractorsRemote work
- Work Flexibility: Remote or Hybrid or OnsiteWhy ARA at Stryker... ...someone with technology risk acumen. Are you interested... ...As the Lead Technology Risk Analyst, you will be responsible for... ...with a strong emphasis on IT risk and SOX compliance. This individual serves as...SuggestedFull timeFor contractorsRemote work
$100k - $140k
At WHOOP, we're on a mission to unlock and inspire performance for life.WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation and support the ongoing risk management program at GRC in a fast-paced, high-growth environment. This...SuggestedFull timeWork at officeRelocation$111k - $189k
...management practices.Communicate security risks and recommendations effectively to technical... ...stakeholders.Extensive knowledge of IT Risk Management and/or Information Systems... ...position unless specified in the postingIn this hybrid role you are expected to work a minimum of...SuggestedFull timeLocal areaRelocation package- We are looking for a Performance & Risk Reporting Analyst to join a long-term contract assignment in Boston, Massachusetts. In this role, you will partner with business stakeholders and technical teams to translate operational and reporting needs into clear requirements...SuggestedLong term contract
$145.9k - $234.2k
The Role:Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the end-to-end third-party cybersecurity risk review process across Moderna. This role will help strengthen Moderna’s third-party cybersecurity risk management...Permanent employmentFull timeContract workWork experience placementFor subcontractorWork at officeWork from home- CVS Health is seeking a Senior Analyst in IT Compliance & Risk focused on IAM. You will develop governance, support application teams, and ensure... ...plus a strong focus on risk reduction and policy adherence. Hybrid work options and a comprehensive benefits package are...
$77.7k - $168.4k
...Stryker seeks a Lead Technology Risk Analyst to direct IT-focused internal audits and risk advisory engagements, with emphasis on SOX compliance and IT general controls. The role involves assessing control effectiveness across multiple ERP platforms and enterprise applications...Remote work$128k - $218k
...information, trade secrets, and inventionsSponsorship will not be considered for this position unless specified in the postingIn this hybrid role you will be expected to work a minimum of 10 days per month out of the Boston, MA or Madison, WI offices. We provide benefits...Full timeLocal areaRelocation package$109.04k - $163.56k
Sr Risk Analyst - KR07DEWe’re determined to make a difference and are proud to be an insurance... ...efforts.Collaborate with underwriting and IT to improve exposure capture processes.Contribute... ...leadership roles.This role can have a Hybrid or Remote work schedule. Candidates who...Full timeTemporary workWork at officeRemote work3 days per week- ...data-driven decisions in a rapidly evolving risk landscape. Here, you’ll be part of a team... ...-track your career as a Catastrophe Risk Analyst through our REACH Program.This is a 24-... .... This is a full-time role with a hybrid work schedule. You will have in-office days...Full timeWork experience placementInternshipWork at officeLocal areaRemote workHome office
- The Catastrophe and Risk Solution team within Verisk is looking... ...passionate and ambitious Risk Analyst to join our Consulting and... ...reach, timing,relevance, and compliance of every consumer engagementLife... ...Spanish is a plus#LI-ZP1#LI-Hybrid• Perform sophisticated risk analyses...
$79.31k - $173.04k
...Functions & Pharmacy Consumer Wellness (PCW) IT Compliance Team is looking for a resource to become... ...enable business operations, and reduce risk. Assess and interpret IT policies and... ...IAM strategy and solutions. Location Hybrid schedule in Woonsocket RI or Wellesley MA...Hourly payFull timeTemporary workWork experience placementLocal areaRemote work$69.5k - $110.9k
...Senior Technology Risk Analyst role focused on executing technology-enabled internal audit and risk advisory engagements. The position involves assessing IT controls, supporting SOX compliance testing, and managing technology risk across enterprise systems in a remote...Remote workFlexible hours$82.6k - $162.8k
Position Summary Cyber Security & Risk Strategy Consultant Our Deloitte Cyber team understands the unique challenges and opportunities... ...expertise and supportExperience with governance, risk, and compliance tools, identity and access management solutions, security...Local areaVisa sponsorship- State Street Corporation is seeking an AVP, Cyber Risk Advisor to strengthen the firm's cyber defense through proactive risk management and design-led security practices. You will partner with Technology, Security Operations, and Engineering to translate complex cyber...
- ...Job Description Job Description Job Title: IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor/ Cybersecurity Compliance Specialist /IT Security Compliance Analyst/ IT Security Auditor Duration: 36 Months (High Possibility of Extension) Location...Work experience placementInterim roleLocal areaRemote work2 days per week3 days per week
$110k - $140k
...contribute to our clients’ success.This is a HYBRID position which requires 3 days per week... ....About the DepartmentThe Performance, Risk, and Attribution Team is responsible for... ...regulation.Job SummaryJob number: 868362Profession: Legal, Compliance, and Risk, Data GovernanceWork at officeLocal area3 days per week$160k - $180k
...to join their Boston-based Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology... ...career as a key contributor to our evolving global IT risk program, we’re interested in speaking with...Temporary workFlexible hours- ...Fintech Risk Analyst Department: Risk Management Employment Type: Full Time Location: Remote Description Grasshopper Bank is a client-... ...approval prior to onboarding Track pre and post-launch risk and compliance requirements for newly onboarded partners Conduct ongoing...Full timeWork experience placementRemote work
$145.9k - $234.2k
The Role: Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the identification, assessment, monitoring, and... ...technology risk management, enterprise risk management, IT controls, compliance, or GRC. Experience supporting...Permanent employmentFull timeWork experience placementWork from home- The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing... ..., etc.)What You Can Offer UsAct as a liaison between IT and business units to support the development and...Work experience placementWork at officeLocal area
- Milliman, Inc. is seeking an experienced Actuarial Analyst for the Atlantic Region P&C practice. Based in the Boston Wakefield, MA area or Burlington, VT, this hybrid role focuses on complex data analyses, reporting, and client communications across insurance and reinsurance...Remote jobWork at office
$67.6k - $152.61k
...funding and healthcare financing, risk management and regulatory compliance, data analytics and business transformation... ...all members of the team, from Analysts to the Principals who serve as... ...and PowerPoint Location This is a hybrid position for candidates with under...Remote jobFull timeTemporary workWork experience placementWork at officeLocal areaWorldwideFlexible hours- Security, Risk and Compliance Consultant WHO WE LOOK FOR An SEI-er is amaster communicator and active listenerwho understands how to navigate an audience.Self-aware, almost to a fault, SEI-ers keenly understand how to adjust their support and problem solving based on the...Permanent employmentWork experience placement
- Verisk's Catastrophe and Risk Solutions (CRS) team provides risk modeling software and consulting services to insurers, reinsurers, brokers, and other financial intermediaries. We're looking for aRisk Consultant or Risk Analystto join ourConsulting and Client Service Team...
- Job Description Verisk's Catastrophe and Risk Solutions (CRS) team provides risk modeling software and consulting services to insurers... ...data and insights to improve the reach, timing,relevance, and compliance of every consumer engagement Life Insurance Solutions - offers...Work at office
- ...Harvard’s Office of Research and Academic Compliance (ORAC) within the Office of the Vice... ...operational expertise, including proactive risk assessment, consultation, and mitigation,... ...Harvard-designated location, employees in hybrid positions must work in a Harvard registered...Work at office
$91.7k - $137.53k
...physician initiated studies. Provide Regulatory support to on-going compliance and corporate initiatives.• Partner with Marketing and... ...maintain accurate records.NOTE: This position is eligible for hybrid working arrangements and requires on-site work from an Insulet...Full timeWork at office$150k - $200k
...opportunity employer. Overview The Compliance & Data Science Consultant supports the... ...monitoring engagements, and data-driven risk analytics projects. Responsibilities... ...Working Conditions This position requires hybrid on-site presence as an essential function...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Risk & Compliance Analyst (Hybrid). Be the first to apply!
- it risk analyst Boston, MA
- risk consultant Boston, MA
- risk analyst Boston, MA
- risk officer Boston, MA
- operational risk specialist Boston, MA
- operational risk consultant Boston, MA
- senior quantitative risk analyst Boston, MA
- compliance analyst Boston, MA
- aml compliance analyst Boston, MA
- risk and compliance analyst Boston, MA



