IT Risk & Compliance Specialist
$110k - $165kNORC at the University of Chicago
Job no: 503946 Work type: Regular Full-Time Location: Chicago - 300 E Randolph St Capability Area: IT DSS Security and Compliance
JOB SUMMARY:
NORC at the University of Chicago is seeking a seasoned IT Risk and Compliance Specialist to join our Information Technology Department within the DSS Security and Compliance team. This critical role will focus primarily on continuous monitoring of security controls, risks, vulnerabilities, and compliance activities , with additional responsibility for supporting and administering compliance activities within ServiceNow GRC/IRM and conducting internal and external compliance assessments and audits. The ideal candidate will bring strong experience in continuous monitoring, governance, risk, and compliance activities within regulated environments, particularly those supporting Government security requirements such as FedRAMP, CMMC, NIST 800-171, NIST SP 800-53, and ISO 27001. Preferably, this position will have a hybrid work schedule of one or two days a week in either our Washington, DC or Chicago, IL office. Remote applicants may also be considered. DEPARTMENT:Digital Services & Solutions Security & Compliance NORC's Digital Services & Solutions group provides technology services to our staff and clients. Given the critical role technology plays in our day-to-day lives, we are committed to providing professional, high-quality solutions in order to further our collective goal of advancing social science research.RESPONSIBILITIES:
Perform and support continuous monitoring activities across NORC systems and environments to assess the ongoing effectiveness of security controls and identify changes that may impact system risk or compliance. Monitor security and compliance findings, vulnerabilities, control deficiencies, remediation activities, exceptions, and other risk indicators to ensure issues are appropriately documented, assigned, tracked, and resolved. Review continuous monitoring outputs from security and IT tools and work with Security Engineers, system owners, and other stakeholders to evaluate findings, determine compliance impact, and coordinate remediation. Track and report on Corrective Action Plans (CAPs), Plans of Action and Milestones (POA&Ms), control deficiencies, vulnerabilities, exceptions, and remediation activities , including aging, status, ownership, and closure. Perform recurring reviews of security controls and supporting evidence to validate continued compliance with requirements such as FedRAMP, CMMC, NIST 800-171, NIST SP 800-53, ISO 27001, FISMA, HITRUST, and applicable contractual requirements. Conduct Security Impact Analyses (SIAs) and risk assessments for system, infrastructure, application, and configuration changes to determine potential impacts to security controls, compliance requirements, and organizational risk. Utilize and support ServiceNow GRC/IRM to manage controls, risks, issues, findings, evidence, remediation activities, exceptions, and other compliance-related workflows. Maintain accurate and complete GRC records within ServiceNow, ensuring compliance activities, control assessments, findings, risks, and remediation efforts are appropriately documented and traceable. Support the development, configuration, and improvement of ServiceNow GRC/IRM workflows, dashboards, reporting, control mappings, and automated compliance processes to improve visibility and efficiency across the compliance program. Develop and maintain compliance metrics, dashboards, and reporting that provide visibility into control effectiveness, outstanding findings, remediation progress, risk trends, and overall compliance posture. Support internal and external IT compliance audits and assessments , including evidence collection, control validation, documentation review, auditor coordination, and remediation tracking for frameworks such as FedRAMP, CMMC, NIST 800-171, and ISO 27001. Develop, review, and maintain key security and compliance documentation, including System Security Plans (SSPs), Corrective Action Plans (CAPs), POA&Ms, Contingency Plans, control implementation documentation, policies, procedures, and supporting evidence . Collaborate with Security Engineers, system owners, application teams, and other stakeholders to remediate security and compliance issues and maintain alignment with applicable regulatory and contractual requirements. Assist in the development and improvement of policies, procedures, control processes, and automated compliance activities for hybrid and multi-tenant infrastructures. Translate regulatory, contractual, and security control requirements into actionable technical and operational steps for IT teams and system owners. Foster strong, collaborative relationships with NORC’s research community, IT teams, and other key stakeholders to support a culture of security, risk awareness, and continuous compliance.REQUIRED SKILLS:
Bachelor’s Degree in Management Information Systems, Computer Science, Business Administration, or a related field. Equivalent experience in IT security, risk, or compliance may be considered. Current certification in IT security, risk, or compliance, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) . Minimum of 6+ years of experience in IT security, continuous monitoring, risk assessment, compliance, or auditing, with significant experience supporting government security frameworks and contractual requirements. Demonstrated experience performing continuous monitoring activities , including security control reviews, vulnerability and finding management, remediation tracking, compliance evidence review, risk identification, and reporting. Experience performing Security Impact Analyses, risk assessments, and control assessments for information systems and technology changes. Hands-on experience working with ServiceNow GRC/IRM or comparable Governance, Risk, and Compliance platforms , including managing controls, risks, issues, findings, evidence, and remediation activities. Experience developing or maintaining GRC workflows, dashboards, metrics, reporting, and compliance tracking processes . Experience supporting internal and external audits and assessments, including preparing and reviewing System Security Plans (SSPs), Corrective Action Plans (CAPs), POA&Ms, Contingency Plans, and control evidence . Strong working knowledge of security and compliance frameworks, including FedRAMP, CMMC, NIST 800-171, NIST SP 800-53, ISO 27001, FISMA, and HITRUST . Strong understanding of information security controls across infrastructure layers, including networks, servers, databases, cloud environments, and applications. Experience supporting compliance within hybrid and multi-tenant infrastructures and familiarity with privacy requirements such as GDPR, CCPA/CPRA, HIPAA Security Rule, and HIPAA Privacy Rule. Qualified applicants must be eligible to work in the U.S. We regret that we are unable to offer visa sponsorship for this position.SALARY AND BENEFITS:
The pay range for this position is $110,000 – $165,000. This position is classified as regular. Regular staff are eligible for NORC’s comprehensive benefits program. Benefits include, but are not limited to: Generously subsidized health insurance, effective on the first day of employment Dental and vision insurance A defined contribution retirement program, along with a separate voluntary 403(b) retirement program Group life insurance, long-term and short-term disability insurance Benefits that promote work/life balance, including generous paid time off, holidays; paid parental leave, bereavement leave, tuition assistance, and an Employee Assistance Program (EAP). NORC is committed to equity and transparency in its pay practices. We publish salary ranges and benefit information for every job. The listed hiring range reflects what we, in good faith, expect to pay at the time of posting, though actual compensation may vary and may be adjusted over time. A candidate’s placement within the range depends on factors such as competencies, education, qualifications, experience, skills, performance, and organizational needs.WHAT WE DO:
NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions. Since 1941, our teams have conducted groundbreaking studies, created and applied innovative methods and tools, and advanced principles of scientific integrity and collaboration. Today, government, corporate, and nonprofit clients around the world partner with us to transform increasingly complex information into useful knowledge.WHO WE ARE:
For over 80 years, NORC has evolved in many ways, moving the needle with research methods, technical applications and groundbreaking research findings. But our tradition of excellence, passion for innovation, and commitment to collegiality have remained constant components of who we are as a brand, and who each of us is as a member of the NORC team. With world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we’re known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale.EEO STATEMENT:
NORC is an equal opportunity employer. NORC evaluates qualified applicants without regard to race, color, religion, sex, gender, national origin, disability, status as a protected veteran, sexual orientation, and other legally protected characteristics. Advertised: August 19, 2026 Central Daylight Time Applications close: Open until filled Central Daylight Time #J-18808-Ljbffr NORC at the University of ChicagoVacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IT Risk & Compliance Specialist in Chicago, IL vacancy
$56 per hour
...IT Risk And Compliance Analyst Hybrid Chicago, NY Rate: $56 Experience: 7+ Years Must Haves: ~ Strong communication skills to all levels, with previous experience of writing reports for senior staff ~ Experience of ITIL ~ Project Management experience...Suggested- ...Job Description - add details here Job Description: The Senior IT Risk and Compliance Analyst will aid in supporting the Information Technology department's adherence to the Bank's Governance, Risk & Compliance (GRC) framework, Enterprise Risk Management framework...Suggested
$74k - $138k
...Deadline:08/24/2026Address:320 S Canal StreetJob Family Group:Audit, Risk & ComplianceLeads the development and continuous improvement of... ...by evaluating risk exposures, control effectiveness, and compliance, and identifying emerging risks to inform decision-making and escalation...SuggestedFull timeContract workPart timeLocal area- 247Hire is seeking a Senior IT Risk and Compliance Analyst to support the Bank's GRC, Enterprise Risk Management, and SOX compliance. The role involves collaborating with IT teams to map processes, identify technology risk, and design controls aligned with COSO, COBIT,...Suggested
- JOB SUMMARY: NORC at the University of Chicago is seeking an IT Risk & Compliance Analyst to join our DSS Security & Compliance team. This role is primarily responsible for supporting NORC's FedRAMP Continuous Monitoring Program , ensuring the ongoing effectiveness of...Suggested
- Veritis Group, Inc. is seeking an experienced IT Risk and Compliance Data Reporting Analyst in Chicago. The role supports the GRC, Enterprise Risk Management, and SOX compliance within the IT department, collaborating with IT staff to implement controls and dashboards....
- Jobtailor is seeking a detail-oriented professional to support compliance, privacy, and risk management initiatives. This role involves coordinating annual training, reporting, and stakeholder attestation, while ensuring documentation accuracy across the policy landscape...
$55k - $67.5k
Risk and Compliance Support Specialist Job ID: 2026-15610 Job Locations: US-LA-New Orleans | US-IL-Chicago Overview Employer: Republic Business Credit, a subsidiary of Renasant Bank This position serves Republic Business Credit which is a subsidiary of Renasant Bank...Hourly payContract workWork experience placementWork at officeFlexible hours- Republic Business Credit, a subsidiary of Renasant Bank, is seeking a Risk and Compliance Support Specialist in the Chicago area. You will manage client reviews, due diligence, and compliance reporting to support risk management and governance across the client portfolio...
- ...Information and Cyber Security to join a growing governance, risk, and compliance program. You will support security controls, policy governance... ...compliance across the enterprise, working with Legal, IT, and security teams. This role offers exposure to multiple cybersecurity...
$77k - $202k
...AssociateJob Description & SummaryThe OpportunityAs a Data Validation Risk - Senior Associate, you will play a pivotal role in transforming... ...cloud platforms such as AWS and Azure- Experience related to IT Audit/SOX or Data Migration/Conversion/Integration - Embracing change...Full timeH1b- A leading recruitment firm is seeking a Governance, Risk & Compliance (GRC) Analyst in Chicago to enhance risk management strategies within the... ...and security policies. Ideal candidates have 2+ years in IT Security and familiarity with cybersecurity frameworks such as...
$130k - $160k
...and your unique viewpoint matter. Learn about the Danaher Business System which makes everything possible.The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk activities across the vendor lifecycle and contributing to enterprise...Full timeRemote workWork from homeFlexible hours- Google is seeking a Cyber Security Auditor within Internal Audit to drive risk reduction across the Alphabet. You will monitor the risk environment and advise business and engineering teams to identify cyber-security risks and strengthen controls. You will design audit...Remote work
$105k - $130k
...help to manage and reduce the organization’s information security risks through continuous management & reporting relating to the NIST... ...supporting resource for the timely completion of Internal & External IT audit evidence requests, questions, and action items. The...Work at officeLocal areaFlexible hours3 days per week$101.5k
...and professional growth. Job Title Senior Data Analyst, Risk Management and Compliance Location Atlanta, Boston, Charlotte, Chicago, Dallas,... ...automation and system initiatives, and partners with Risk, IT, and consultants to improve data-driven decision-making. Job...Full timeTemporary workLocal areaFlexible hoursShift work- BCG Attorney Search is seeking an associate with 3-6 years of experience to join its Digital Risk Advisory and Cybersecurity Team in Chicago, IL. The attorney will advise clients on cybersecurity incidents, regulatory investigations, and related advisory services such...
- Early Warning is seeking a Senior Data Analyst - Risk Management in Chicago to support Enterprise Risk Management under the... ...committees, and collaborate with Product Development, Legal/Compliance, Operations, IT, and Finance. Independent, analytical, and communicative...
- PwC is seeking a Data Validation Risk - Senior Associate in the Chicago area to design and implement data pipelines and validation solutions within our Risk & Regulatory practice. You will convert raw data into actionable insights, build scalable data infrastructure, and...
$84k - $105k
...Visa sponsorship. Overall Purpose The Sr. Data Analyst - Risk Management will support the Senior Director of Enterprise Risk... ...an organization, including Product Development, Legal/Compliance, Operations, IT, and Accounting/Finance. Excellent interpersonal skills....Hourly payWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...Warning Services LLC in Chicago, IL is seeking a Sr. Data Analyst - Risk Management to support the enterprise risk program across the... ...risk reports for ERM committees, collaborating with Product, Legal, IT, Operations, and Finance. A bachelor’s degree in accounting/...
$85k - $100k
...part time, permanent About the role As a Risk Market Data Analyst at RWEST, you will be... ..., Front Office, Back Office, and IT teams in a cross-functional environment.... ...PCI system enhancements as the key system specialist Supportive, inclusive team culture that...Permanent employmentFull timePart timeImmediate startFlexible hours$90k
...proud to operate from additional offices in Sydney, Shanghai, London and Singapore. What you'll do as a Junior Quantitative Risk Analyst at Akuna: We are looking for a motivated and talented individual to join our growing Risk Department. This role...Work at office$135k - $175k
...Senior Risk Quantitative Developer (Futures Focus) Founded in 1999, Geneva Trading is a premier global principal trading firm with strategically located offices in Chicago, Dublin, and London. Our relentless focus on trading excellence combined with technological innovation...Night shiftDay shiftEarly shift- ...office for collaborative purposes. (Mon-Thurs) Job Description Summary - We are seeking a skilled and motivated Senior Cyber Risk and Vulnerability Analyst to strengthen our cybersecurity risk management and vulnerability management capabilities. This role will...Work at office2 days per week3 days per week
- ...Financial Service businesses including Capital Markets, Insurance and Payments verticals, supplemented with Data & AI, Cybersecurity, Risk & Compliance, Change Management and Digital Transformation practices. We integrate deep industry expertise with business, technology, and...Temporary workRemote workWorldwide
$85.91k - $162.89k
...service in the area of informational technology risk advisory? If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Senior Consultant (SOC... ...knowledge of risk, governance, internal audit, compliance, IT, and cybersecurity best practices. You Will...Work experience placementLocal areaWorldwide- ...hiring a skilled Information Assurance and Compliance Analyst to join our cybersecurity team.... ...meet the stringent requirements of federal IT environments. Its flagship offering,... ...organization’s commitment to data protection, risk management, and regulatory compliance....Temporary workRemote work
- ...4262 Supervisor-level Data Governance & Compliance Analyst Seeking a Supervisor-level Data... ...support a global banking client within its Risk Consulting practice. This role will focus... ...IIBA. Everforth Apex is a world-class IT services company that serves thousands of...
- ...Analyst The GRC Analyst is a member of the IT Security team and works closely with... ...GRC program through the development and compliance of IT Security policies and procedures and... ...participation in onsite and virtual audits and risk remediation. Support the GRC program...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Risk & Compliance Specialist. Be the first to apply!
Related searches
- entry level IT support specialist Chicago, IL
- senior IT support specialist Chicago, IL
- IT support specialist Chicago, IL
- computer operator Chicago, IL
- field IT technician Chicago, IL
- IT technician Chicago, IL
- executive IT support specialist Chicago, IL
- IT specialist Chicago, IL
- information risk analyst Chicago, IL
- third party risk analyst Chicago, IL


