Information Technology Risk & Compliance Analyst

Ecmc Group

Minneapolis (MN)

Hybrid

USD 90,000 - 100,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health & wellness benefits
Life & disability insurance
401(k) plan with company match
Paid time off
Commuter subsidy
Tuition reimbursement
Student loan repayment

Job summary

ECMC Group, headquartered in Minneapolis, seeks an IT Compliance professional to plan, execute and report on complex IT compliance activities across information systems. The role partners with procurement and legal, reviews vendor contracts, and drives remediation progress to strengthen controls.

The position requires 3+ years in IT risk and compliance, familiarity with FISMA/NIST/ISO frameworks, and a hybrid work schedule in Minneapolis, MN.

Qualifications

  • Bachelor's degree or 2 years of relevant experience in lieu of degree.
  • 3+ years in IT risk and compliance, IT governance, IT auditing or related field.
  • Experience assessing vendor risk and reviewing contracts.
  • Experience with AWS or cloud environments.
  • Advanced knowledge of Microsoft Office and Excel; SharePoint familiarity.
  • Familiarity with frameworks such as NIST, ISO2700, COSO and COBIT.

Responsibilities

  • Leads and performs complex IT compliance activities including planning, risk analysis, testing and reporting.
  • Leads vendor security risk assessments and reviews security and compliance provisions within vendor contracts.
  • Engages management to assess processes, identify control weaknesses and discuss compliance observations and risks.
  • Prepares documentation and draft reports communicating results, risks and recommendations to improve information system controls and practices.
  • Plans and executes IT compliance reviews and supports audits through evidence preparation and auditor coordination.
  • Contributes to enterprise risk assessments by identifying emerging risks and improvement opportunities.

Skills

IT risk & compliance
Vendor risk assessments
Auditing capabilities
Policy development
Data analytics
Security concepts (FISMA, PCI, HIPAA)
NIST/ISO2700/COBIT knowledge

Education

Bachelor’s degree or 2 years of relevant experience in lieu of degree

Tools

Excel
SharePoint
AWS or cloud environments

Job description

ECMC Group is a nonprofit corporation focused on helping students succeed. Headquartered in Minneapolis, ECMC Group and its family of companies provide financial tools and services, as well as funding for innovative programs to help students achieve their academic and professional goals.

Job Summary

Responsible for planning, executing and reporting on complex IT compliance activities and related initiatives across information systems. Performs assigned portions of IT compliance programs, determining compliance with policies and procedures, monitoring, recommending corrective action, preparing findings, and assisting with remediation plans. Reviews and services should be performed in accordance with professional and department standards.

Essential Duties and Responsibilities
  • Leads and performs complex IT compliance activities including planning, risk analysis, testing and reporting in accordance with professional and department standards.
  • Leads vendor security risk assessments and reviews security and compliance provisions within vendor contracts in partnership with procurement and legal teams.
  • Independently engages management to assess processes, identify control weaknesses and discuss compliance observations and risks.
  • Secures management ownership of findings and remediation plans and monitors remediation progress through completion.
  • Prepares clear documentation and draft reports communicating results, risks and recommendations to improve information system controls and practices.
  • Plans and executes IT compliance reviews and supports internal and external audits through evidence preparation and auditor coordination.
  • Contributes to enterprise risk assessments by identifying emerging risks, control gaps and improvement opportunities.
  • Provides guidance and informal coaching to staff on compliance activities of low to medium complexity as assigned.
  • Anticipates and manages stakeholder expectations while ensuring timely, consistent delivery of compliance services.
  • Communicates complex compliance concepts clearly to peers, leaders and business partners.
  • Performs other duties or responsibilities as assigned.
Required Qualifications
  • Bachelor’s degree in computer information systems, information technology, legal studies, or related field or an additional 2 years of relevant experience in lieu of degree.
  • Understanding of IT concepts such as identity and access management, threat and vulnerability management, data loss prevention, change management, data analytics, and software development lifecycle 3+ years of experience in IT risk and compliance, IT governance, IT auditing or an IT related field.
  • Experience assessing vendor risk, performing security assessments, and reviewing contracts.
  • Experience working with procurement and legal teams.
  • Experience assessing security controls for AWS or cloud environments.
  • Experience developing and maintaining policies and/or information management frameworks.
  • Experience creating and assembling evidence for internal or external auditors.
  • Advanced knowledge of Microsoft Office suite, including experience analyzing data using Excel and designing or managing SharePoint sites.
  • General knowledge of security control concepts, principles, risk analysis, FISMA, PCI Compliance, HIPAA, Privacy, process improvement and techniques, including frameworks such as NIST, ISO2700, COSO and COBIT.
Preferred Qualifications
  • Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications preferred.

The pay range for this position is $90,000-$100,000. Actual compensation may vary based on factors such as relevant experience, peer and market benchmarks, and geographic location.

This position is classified as hybrid Monday - Wednesday and requires attendance in Minneapolis, MN. To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Benefits
  • Health & wellness benefits: Medical, dental, and vision insurance plan options, with a generous employer subsidy.
  • Company paid life & disability insurance, pre-tax flexible spending accounts and robust wellness programs.
  • Financial benefits: Generous 401(k) plan with a company match up to 6% and additional discretionary contribution potential, holiday time off, paid time off accrual starting at 20 days/year and commuter subsidy.
  • Education benefits: Tuition reimbursement up to $10,500/year for approved programs and student loan payment reimbursement up to $4,800/year. Up to $5,250 of qualifying education benefits can be reimbursed pre-tax.

In compliance with federal law, all persons hired with ECMC Group and its affiliates will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. ECMC Group participates in E-Verify to verify authorization to work in the U.S.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst Senior
Cybersecurity Analyst Senior

Ecmc Group • Minneapolis (MN)

On-site
USD 115,000 - 125,000
Health & wellness benefits
401(k) with company match
Tuition reimbursement
+2
Financial Analyst
Financial Analyst

Ecmc Group • Minneapolis (MN)

On-site
USD 65,000 - 85,000
Health & wellness benefits
Generous 401(k) with company match
Paid time off and holidays
+1
IT Risk & Compliance Lead: Vendor Security & Controls
IT Risk & Compliance Lead: Vendor Security & Controls

Ecmc Group • Minneapolis (MN)

Hybrid
USD 90,000 - 100,000
Health & wellness benefits
Life & disability insurance
401(k) plan with company match
+4
Senior IT Risk & Compliance Lead (Hybrid)
Senior IT Risk & Compliance Lead (Hybrid)

ECMC Group • Minneapolis (MN)

Hybrid
USD 115,000 - 125,000
Health & wellness benefits
401(k) plan with company match
Tuition reimbursement
Total Rewards Specialist
Total Rewards Specialist

Ecmc Group • Minneapolis (MN)

Hybrid
USD 65,000 - 75,000
Health insurance
Dental & vision insurance
401(k) with company match
+2
Agency Relations Representative
Agency Relations Representative

Ecmc Group • Minneapolis (MN)

Hybrid
USD 32,000 - 34,000
Health & wellness benefits
Company 401(k) with Match
Tuition reimbursement
+1
IT/Security Compliance Manager
IT/Security Compliance Manager

EMCOR Group, Inc. • Norwalk (CT)

On-site
USD 153,000 - 163,000
Bonus eligible
Comprehensive benefits package
Risk Control Specialist - MN
Risk Control Specialist - MN

EMC Insurance • Minnesota

Hybrid
USD 93,000 - 141,000
401(k) plan
Pension plan
Tuition reimbursement
+2
Administrative Coordinator
Administrative Coordinator

EMC Insurance Companies • Minnesota

Hybrid
USD 51,000 - 78,000
IT Compliance Manager (Mid)
IT Compliance Manager (Mid)

Everforth ECS • Quantico (VA)

On-site
USD 80,000 - 105,000
Equal opportunity employer