IT Risk and Compliance Analyst

Jobgether SRL

United States

On-site

USD 80,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote within US
Ownership opportunity
Ground-up program

Job summary

Jobgether SRL is seeking an IT Risk and Compliance Analyst based in the United States to support a growing program across contracts, vendor risk, and governance.

You will translate requirements into practical controls, manage evidence in a GRC platform, and work with Legal, IT, and leadership to drive remediation and improvements.

Qualifications

  • Bachelor’s degree or equivalent with 3–5 years in compliance or risk.
  • Hands-on experience with MSAs, DPAs, or security addenda.
  • Experience responding to client security questionnaires or audits.
  • Working knowledge of SOC 2, ISO 27001, or NIST CSF.
  • Foundational understanding of GDPR/CCPA privacy regs.
  • Strong organization and cross-functional collaboration.

Responsibilities

  • Review client MSAs, DPAs, and security addenda with stakeholders.
  • Translate security and privacy requirements into operational controls.
  • Respond to security questionnaires and audit inquiries.
  • Maintain control evidence in the GRC platform and track remediations.
  • Support vendor risk management for SaaS and AI providers.
  • Track data retention schedules and liaise with IT.
  • Assist privacy program activities including data mapping.
  • Draft and publish compliance policies and SOPs.
  • Prepare risk and compliance reporting for leadership.
  • Maintain risk register and assist annual risk assessments.
  • Participate in BC/DR planning and control testing.
  • Administer security awareness training programs.

Skills

GRC
Contract management
Privacy compliance
Risk management
Policy drafting

Education

Bachelor’s degree

Tools

GRC platforms
Contract analysis tools
Security questionnaires

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IT Risk and Compliance Analyst based in United States.

This role supports the day-to-day execution of a growing IT risk, compliance, privacy, and governance program.
You will work across contracts, security questionnaires, control evidence, vendor risk, data retention, and compliance policies.
The position offers the opportunity to help shape a program being rebuilt from the ground up and establish scalable ways of working.
You will collaborate with Legal, IT, Delivery, leadership, vendors, and other stakeholders to translate requirements into practical controls and actions.
The role combines technical and legal concepts with hands‑on program coordination, risk management, and process improvement.
Success requires exceptional organization, strong written communication, sound judgment, and the ability to manage multiple priorities independently.
This is an ideal opportunity for a compliance professional who enjoys ownership, variety, and building effective processes within a collaborative environment.

  • Review client MSAs, SOWs, DPAs, security addenda, and related agreements using contract analysis tools, identifying provisions requiring attention from Legal, IT, Delivery, or other stakeholders and coordinating redlines through completion.
  • Translate contractual security, privacy, data handling, audit, breach notification, and sub-processor requirements into trackable operational commitments and verify that obligations are being met.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries while maintaining and improving a reusable knowledge base to make future responses faster and more consistent.
  • Collect, organize, maintain, and manage control evidence within the GRC platform, tracking remediation activities against frameworks such as SOC 2, ISO 27001, NIST CSF, and other applicable standards.
  • Support vendor risk management activities for SaaS and AI providers by reviewing security documentation, DPAs, sub-processor information, and findings, while maintaining accurate vendor risk records.
  • Operationalize data retention and disposal requirements by tracking departmental retention schedules, documenting exceptions and legal holds, and working with IT to verify retention settings across relevant platforms.
  • Support privacy program activities including data mapping, data subject request processes, and monitoring obligations associated with GDPR, CCPA, and other applicable privacy requirements.
  • Draft, maintain, publish, and improve compliance policies, standard operating procedures, and process documentation, ensuring that requirements remain current and are effectively implemented.
  • Prepare risk and compliance reporting for leadership, highlighting program status, emerging risks, remediation progress, and areas requiring attention.
  • Maintain and monitor the risk register, support annual risk assessments, and contribute to the identification, evaluation, and treatment of organizational risks.
  • Participate in business continuity and disaster recovery planning, tabletop exercises, security incident response, internal audits, access reviews, and periodic control testing.
  • Administer security awareness training programs and monitor completion and compliance across the organization.
Requirements
  • Bachelor’s degree or equivalent practical experience, with 3–5 years of professional experience in compliance, GRC, contract management, privacy, risk, or a related field.
  • Hands‑on experience reviewing commercial agreements, ideally including MSAs, DPAs, security addenda, or similar documents, with the ability to collaborate effectively with legal counsel on contractual redlines.
  • Experience responding to client security questionnaires, vendor due diligence requests, audit inquiries, or comparable compliance information requests.
  • Working knowledge of at least one major security or compliance framework, such as SOC 2, ISO 27001, or NIST CSF, including a practical understanding of the evidence required to demonstrate control effectiveness.
  • Foundational understanding of data privacy regulations such as GDPR and CCPA, particularly how privacy requirements translate into contracts, operational processes, and compliance obligations.
  • Exceptional organizational and follow‑through skills, with the ability to manage numerous parallel workstreams, deadlines, stakeholders, and remediation activities without losing attention to detail.
  • Clear, concise, and confident written communication skills, including the ability to interpret complex technical or legal information and distill it into practical priorities and recommendations.
  • Strong analytical, problem‑solving, and judgment skills, with the ability to identify gaps, assess risks, coordinate solutions, and follow issues through to resolution.
  • Comfortable working with SaaS platforms, GRC systems, contract analysis tools, and other technology, with a demonstrated ability to learn new systems quickly and use technology to improve processes.
  • Self‑directed and accountable, with the ability to own outcomes end to end while working effectively within a small, collaborative team.
  • Comfortable working across technical, legal, operational, and business functions and translating requirements between different stakeholder groups.
Benefits
  • Salary range of $80,000–$90,000 USD.
  • Remote working arrangement within the United States.
  • Opportunity to help build and shape an IT risk and compliance program from the ground up.
  • Broad exposure to IT risk, compliance, privacy, vendor management, contracts, security operations, and governance.
  • Collaborative and inclusive work environment that values diverse perspectives and authentic contributions.
  • Opportunities to work closely with cross‑functional teams across legal, technology, delivery, security, and leadership functions.
  • Meaningful ownership and autonomy within a growing compliance program.
  • Opportunity to contribute to process improvement and the development of scalable compliance practices.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Risk and Compliance Analyst (Fully Remote)
IT Risk and Compliance Analyst (Fully Remote)

Not Specified • United States

Remote
USD 60,000 - 90,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX Inc. Company • North Carolina

On-site
USD 118,000 - 220,000
Director of Governance, Risk & Compliance
Director of Governance, Risk & Compliance

Jobgether SRL • United States

Remote
USD 140,000 - 210,000
401(k) match
Health insurance (employee)
Paid time off 3 weeks
+3
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Remote IT Risk & Compliance Analyst: Shape the GRC Program
Remote IT Risk & Compliance Analyst: Shape the GRC Program

Not Specified • United States

Remote
USD 60,000 - 90,000
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

On-site
USD 76,000 - 110,000
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

On-site
USD 76,000 - 110,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2