Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Risk & Compliance Analyst (Hybrid)

$75k - $107k

Intact Services USA LLC

Job Description

Job Description

Our employees are at the heart of what we do: helping people, businesses and society prosper in good times and be resilient in bad times. When you join our team, you are bringing this purpose to life alongside a passionate community.

Feel empowered to learn and grow while being valued for who you are. At Intact, we commit to supporting you in reaching your goals with tools, opportunities, and flexibility. It’s our promise to you. 

Who we are

At Intact Insurance Specialty Solutions, we are experts at what we do in protecting what makes businesses unique. Our deep understanding of the specialty insurance market is the foundation for our customized solutions, backed by targeted risk control and claims services. Our employees are passionate about providing insurance coverage that’s aligned to our targeted customer groups.

Intact’s Global Specialty Lines business spans across more than 20 verticals in four distinct markets: U.S., Canada, UK and Europe. The following opportunity is for our U.S. team.

The opportunity

We currently have an opportunity for an IT Risk & Compliance Analyst to join our Corporate IT team based in our Canton, MA; Boston, MA; Farmington, CT or Raleigh, NC offices on a hybrid schedule. The IT Risk & Compliance Analyst supports the organization’s IT Risk / GRC function by collecting, organizing, analyzing, and reporting information related to cybersecurity risk, control performance, audit response, remediation tracking, and security metrics. This is a hands-on individual contributor role where one person may support multiple related activities across governance, risk, compliance, cybersecurity metrics, and audit coordination all aligned with the NIST framework.

The analyst works with and contributes to IT, cybersecurity, infrastructure, identity and access management, vulnerability management, and audit stakeholders to help organize evidence, track action items, maintain accurate status reporting, and translate technical information into clear management-ready reporting. The ideal candidate is highly organized, analytical, comfortable learning new cybersecurity domains, and able to follow up consistently across multiple teams and deadlines. Some of the IT Risk & Compliance Analyst responsibilities include but are not limited to:

  • Maintain organized records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status.
  • Collect and validate information from control owners and technical teams to support risk reviews, control assessments, compliance activities, cybersecurity metrics, and management reporting.
  • Coordinate audit response activities across internal and external auditors in multiple geographic regions and IT, security, infrastructure, compliance, and business stakeholders.
  • Track audit requests, evidence, responses, findings, remediation actions, retesting, risk acceptances, compensating controls, owners, deadlines, and closure; identify blockers and escalate overdue or unclear items as appropriate.
  • Help IT and security teams develop clear, well-supported responses to audit findings and maintain evidence in an organized, repeatable, and auditable manner.
  • Collect, organize, and analyze cybersecurity and IT risk metrics across vulnerability management, identity and access management, endpoint protection, incident response, infrastructure operations, logging, and monitoring.
  • Develop accurate reports, dashboards, and management-ready summaries using tools such as Excel, PowerPoint, SharePoint, ticketing systems, and other available reporting platforms.
  • Analyze trends, gaps, aging items, control exceptions, and remediation progress, and translate technical security information into business-relevant insights for leadership, risk committees, auditors, and non-technical audiences.
  • Define and maintain consistent metric definitions, data owners, source systems, refresh schedules, assumptions, and limitations.
  • Create and maintain trackers, checklists, evidence logs, reporting calendars, process maps, and follow-up routines that improve consistency, accuracy, timeliness, and repeatability of risk, audit, and security reporting.
  • Coordinate application security and penetration testing for internally developed, SaaS, web, mobile, API, cloud, and vendor-hosted applications, including scoping, scheduling, execution support, findings tracking, remediation validation, and retesting through closure.
  • Support application security governance by maintaining application inventories, promoting secure software development practices, preparing management reporting, and aligning testing with organizational and regulatory requirements.
  • Apply recognized cybersecurity and control frameworks, including NIST-based terminology, under leadership guidance.
  • Clarify ownership, next steps, and response dates; follow up consistently and communicate professionally with stakeholders while maintaining a collaborative, service-oriented approach.
  • Escalate material risks, delays, unresolved ownership, and data quality concerns, and promote accountability and continuous improvement across IT risk and security operations.

The expertise you bring

  • Management, Audit, Accounting, or a related field, or equivalent relevant experience.
  • Three (3) to five (5) years of experience in IT risk, GRC, information security, IT audit, technology controls, security operations, or a related function.
  • Experience in insurance, financial services, healthcare, utilities, or another regulated or compliance-intensive industry is preferred.
  • Relevant professional certifications, such as Security+, CISA, CRISC, CISM, CISSP, CGRC, or ITIL Foundation, are preferred but not required.

Our salary ranges are determined by many factors including location, role, experience and skillset of the candidate. The following ranges displayed reflect the target base salary for new hires; however, your recruiter will provide more specific compensation details during the hiring process. The typical base salary range for this position is: $75,000 - $107,000, based on the factors aforementioned. For candidates located in San Francisco, CA; Washington DC; our Massachusetts based offices and the New York City metro area, the base salary range is $95,000 - $110,000. In addition to base salary, full time Intact employees are also eligible for bonus potential and a full range of benefits to include but not limited to:

  • Comprehensive medical, dental and vision insurance with no waiting period
  • Competitive paid time off programs
  • 401(k) savings and annual contributions of up to 12% of annual salary
  • Mental health support programs, life and disability insurance, paid parental leave and a variety of additional voluntary benefits

This position will remain posted until a final candidate is selected. Once the role is filled, this job posting will be removed.    

Why choose Intact

We live our Values:  We are committed to acting with the highest of ethical standards through our five core values: integrity, respect, customer driven, excellence and social responsibility.

Our commitment to Diversity: Founded in our values, we see diversity as a strength and aspire to create an environment where everyone can be themselves, grow and succeed. Together, we will stand up for what’s right to build an inclusive society.

Manage your Time: What you accomplish matters more than hours in the office. We are committed to creating a positive and supportive environment in which you perform your best. Our Time-Off and Flexible Work Arrangement options help foster a healthy work-life balance. 

Check out our Glassdoor reviews to see why people love working for Intact!

Our promise to you

Our Values are foundational to our success at Intact. You’ll make a difference every day when you live our Values, do your best work, are open to change, and invest in yourself.

In return, we promise you support, opportunities and performance-led financial rewards in a flexible work environment where you can:

  • Shape the future: Help us lead an insurance transformation to better protect people, businesses and society.
  • Win as a team: Collaborate with inspiring people to do your best work every day and together, stand up for what is right.
  • Grow with us: Refresh and reinvent your skills, learn from our diverse teams, lift others up, and grow.

About Intact 

At Intact Insurance Specialty Solutions we are experts at what we do. Our deep understanding of the specialty insurance market is the foundation for our customized solutions, backed by targeted risk control and claims services. Our employees are passionate about providing insurance coverage that’s aligned to our targeted customer groups. Today, we help protect over a dozen industries with tailored coverages and services.

 

#LI-DNP

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the IT Risk & Compliance Analyst (Hybrid) in Boston, MA vacancy
  •  ...Flexibility: Remote or Hybrid or OnsiteWhy ARA at Stryker?The Assurance & Risk Advisory (ARA) function...  ...Senior Technology Risk Analyst to play a critical role...  ...engagements, including SOX compliance testing, system implementation...  ...in the auditing of IT general controls (ITGCs)... 
    Suggested
    Full time
    For contractors
    Remote work

    Stryker

    Boston, MA
    5 days ago
  • Work Flexibility: Remote or Hybrid or OnsiteWhy ARA at Stryker...  ...someone with technology risk acumen. Are you interested...  ...As the Lead Technology Risk Analyst, you will be responsible for...  ...with a strong emphasis on IT risk and SOX compliance. This individual serves as... 
    Suggested
    Full time
    For contractors
    Remote work

    Stryker

    Boston, MA
    5 days ago
  • $100k - $140k

    At WHOOP, we're on a mission to unlock and inspire performance for life.WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation and support the ongoing risk management program at GRC in a fast-paced, high-growth environment. This... 
    Suggested
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    1 day ago
  • $111k - $189k

     ...management practices.Communicate security risks and recommendations effectively to technical...  ...stakeholders.Extensive knowledge of IT Risk Management and/or Information Systems...  ...position unless specified in the postingIn this hybrid role you are expected to work a minimum of... 
    Suggested
    Full time
    Local area
    Relocation package

    American Family Insurance

    Boston, MA
    2 days ago
  • We are looking for a Performance & Risk Reporting Analyst to join a long-term contract assignment in Boston, Massachusetts. In this role, you will partner with business stakeholders and technical teams to translate operational and reporting needs into clear requirements... 
    Suggested
    Long term contract

    Robert Half

    Boston, MA
    3 days ago
  • $145.9k - $234.2k

    The Role:Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the end-to-end third-party cybersecurity risk review process across Moderna. This role will help strengthen Moderna’s third-party cybersecurity risk management... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Work at office
    Work from home

    Moderna Therapeutics

    Somerville, MA
    4 days ago
  • CVS Health is seeking a Senior Analyst in IT Compliance & Risk focused on IAM. You will develop governance, support application teams, and ensure...  ...plus a strong focus on risk reduction and policy adherence. Hybrid work options and a comprehensive benefits package are... 

    Signal Corps Regimental Association

    Wellesley, MA
    2 days ago
  • $77.7k - $168.4k

     ...Stryker seeks a Lead Technology Risk Analyst to direct IT-focused internal audits and risk advisory engagements, with emphasis on SOX compliance and IT general controls. The role involves assessing control effectiveness across multiple ERP platforms and enterprise applications... 
    Remote work

    Stryker

    Boston, MA
    5 days ago
  • $128k - $218k

     ...information, trade secrets, and inventionsSponsorship will not be considered for this position unless specified in the postingIn this hybrid role you will be expected to work a minimum of 10 days per month out of the Boston, MA or Madison, WI offices. We provide benefits... 
    Full time
    Local area
    Relocation package

    American Family Insurance

    Boston, MA
    2 days ago
  • $109.04k - $163.56k

    Sr Risk Analyst - KR07DEWe’re determined to make a difference and are proud to be an insurance...  ...efforts.Collaborate with underwriting and IT to improve exposure capture processes.Contribute...  ...leadership roles.This role can have a Hybrid or Remote work schedule.  Candidates who... 
    Full time
    Temporary work
    Work at office
    Remote work
    3 days per week

    The Hartford Financial Services Group

    Boston, MA
    3 days ago
  •  ...data-driven decisions in a rapidly evolving risk landscape. Here, you’ll be part of a team...  ...-track your career as a Catastrophe Risk Analyst through our REACH Program.This is a 24-...  .... This is a full-time role with a hybrid work schedule. You will have in-office days... 
    Full time
    Work experience placement
    Internship
    Work at office
    Local area
    Remote work
    Home office

    Arthur J. Gallagher & Co.

    Boston, MA
    5 days ago
  • The Catastrophe and Risk Solution team within Verisk is looking...  ...passionate and ambitious Risk Analyst to join our Consulting and...  ...reach, timing,relevance, and compliance of every consumer engagementLife...  ...Spanish is a plus#LI-ZP1#LI-Hybrid• Perform sophisticated risk analyses... 

    Verisk Analytics

    Boston, MA
    2 days ago
  • $79.31k - $173.04k

     ...Functions & Pharmacy Consumer Wellness (PCW) IT Compliance Team is looking for a resource to become...  ...enable business operations, and reduce risk. Assess and interpret IT policies and...  ...IAM strategy and solutions. Location Hybrid schedule in Woonsocket RI or Wellesley MA... 
    Hourly pay
    Full time
    Temporary work
    Work experience placement
    Local area
    Remote work

    Koitecc Solutions

    Wellesley, MA
    3 days ago
  • $69.5k - $110.9k

     ...Senior Technology Risk Analyst role focused on executing technology-enabled internal audit and risk advisory engagements. The position involves assessing IT controls, supporting SOX compliance testing, and managing technology risk across enterprise systems in a remote... 
    Remote work
    Flexible hours

    Stryker

    Boston, MA
    12 days ago
  • $82.6k - $162.8k

    Position Summary Cyber Security & Risk Strategy Consultant Our Deloitte Cyber team understands the unique challenges and opportunities...  ...expertise and supportExperience with governance, risk, and compliance tools, identity and access management solutions, security... 
    Local area
    Visa sponsorship

    Deloitte

    Boston, MA
    1 day ago
  • State Street Corporation is seeking an AVP, Cyber Risk Advisor to strengthen the firm's cyber defense through proactive risk management and design-led security practices. You will partner with Technology, Security Operations, and Engineering to translate complex cyber... 

    State Street Corporation

    Quincy, MA
    2 days ago
  •  ...Job Description Job Description Job Title: IT Security Risk Auditor / Compliance Specialist/IT Compliance Auditor/ Cybersecurity Compliance Specialist /IT Security Compliance Analyst/ IT Security Auditor Duration: 36 Months (High Possibility of Extension) Location... 
    Work experience placement
    Interim role
    Local area
    Remote work
    2 days per week
    3 days per week

    sgsconsulting

    Lexington, MA
    2 days ago
  • $110k - $140k

     ...contribute to our clients’ success.This is a HYBRID position which requires 3 days per week...  ....About the DepartmentThe Performance, Risk, and Attribution Team is responsible for...  ...regulation.Job SummaryJob number: 868362Profession: Legal, Compliance, and Risk, Data Governance
    Work at office
    Local area
    3 days per week

    Franklin Templeton

    Boston, MA
    4 days ago
  • $160k - $180k

     ...to join their Boston-based Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology...  ...career as a key contributor to our evolving global IT risk program, we’re interested in speaking with... 
    Temporary work
    Flexible hours

    Berkshire Hathaway Specialty Insurance

    Boston, MA
    3 days ago
  •  ...Fintech Risk Analyst Department: Risk Management Employment Type: Full Time Location: Remote Description Grasshopper Bank is a client-...  ...approval prior to onboarding Track pre and post-launch risk and compliance requirements for newly onboarded partners Conduct ongoing... 
    Full time
    Work experience placement
    Remote work

    Grasshopper Bank

    Boston, MA
    1 day ago
  • $145.9k - $234.2k

    The Role: Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the identification, assessment, monitoring, and...  ...technology risk management, enterprise risk management, IT controls, compliance, or GRC. Experience supporting... 
    Permanent employment
    Full time
    Work experience placement
    Work from home

    Moderna Therapeutics

    Cambridge, MA
    21 hours ago
  • The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing...  ..., etc.)What You Can Offer UsAct as a liaison between IT and business units to support the development and... 
    Work experience placement
    Work at office
    Local area

    American Tower

    Boston, MA
    5 days ago
  • Milliman, Inc. is seeking an experienced Actuarial Analyst for the Atlantic Region P&C practice. Based in the Boston Wakefield, MA area or Burlington, VT, this hybrid role focuses on complex data analyses, reporting, and client communications across insurance and reinsurance... 
    Remote job
    Work at office

    Milliman, Inc

    Wakefield, MA
    5 days ago
  • $67.6k - $152.61k

     ...funding and healthcare financing, risk management and regulatory compliance, data analytics and business transformation...  ...all members of the team, from Analysts to the Principals who serve as...  ...and PowerPoint Location This is a hybrid position for candidates with under... 
    Remote job
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area
    Worldwide
    Flexible hours

    Milliman, Inc

    Wakefield, MA
    5 days ago
  • Security, Risk and Compliance Consultant WHO WE LOOK FOR An SEI-er is amaster communicator and active listenerwho understands how to navigate an audience.Self-aware, almost to a fault, SEI-ers keenly understand how to adjust their support and problem solving based on the... 
    Permanent employment
    Work experience placement

    SEI

    Boston, MA
    1 day ago
  • Verisk's Catastrophe and Risk Solutions (CRS) team provides risk modeling software and consulting services to insurers, reinsurers, brokers, and other financial intermediaries. We're looking for aRisk Consultant or Risk Analystto join ourConsulting and Client Service Team... 

    Verisk Careers | Verisk

    Boston, MA
    1 day ago
  • Job Description Verisk's Catastrophe and Risk Solutions (CRS) team provides risk modeling software and consulting services to insurers...  ...data and insights to improve the reach, timing,relevance, and compliance of every consumer engagement Life Insurance Solutions - offers... 
    Work at office

    Verisk

    Boston, MA
    2 days ago
  •  ...Harvard’s Office of Research and Academic Compliance (ORAC) within the Office of the Vice...  ...operational expertise, including proactive risk assessment, consultation, and mitigation,...  ...Harvard-designated location, employees in hybrid positions must work in a Harvard registered... 
    Work at office

    Harvard University

    Cambridge, MA
    5 days ago
  • $91.7k - $137.53k

     ...physician initiated studies. Provide Regulatory support to on-going compliance and corporate initiatives.• Partner with Marketing and...  ...maintain accurate records.NOTE: This position is eligible for hybrid working arrangements and requires on-site work from an Insulet... 
    Full time
    Work at office

    Insulet Corporation

    Boston, MA
    4 days ago
  • $150k - $200k

     ...opportunity employer. Overview The Compliance & Data Science Consultant supports the...  ...monitoring engagements, and data-driven risk analytics projects. Responsibilities...  ...Working Conditions This position requires hybrid on-site presence as an essential function... 

    Ropes & Gray

    Boston, MA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Risk & Compliance Analyst (Hybrid). Be the first to apply!