IT Risk and Compliance Analyst

HugeInc

United States

Remote

USD 80,000 - 90,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Huge is seeking an IT Risk and Compliance Analyst to join the IT Risk and Compliance team to drive day-to-day program execution. The role covers contracts, security questionnaires, control evidence, vendor risk, data retention and privacy, and policy alignment.

The candidate should be organized, comfortable with legal and technical language, and capable of managing multiple threads simultaneously. The program is being rebuilt from the ground up, so you will help shape how the work gets done and

Qualifications

  • Bachelor’s degree or equivalent practical experience.
  • 3–5 years in compliance, GRC, contract management, privacy, or related field.
  • Experience reviewing MSAs/DPAs and coordinating with Legal.
  • Experience responding to security questionnaires or due diligence requests.
  • Familiarity with SOC 2, ISO 27001, or NIST CSF.
  • Understanding data privacy regulations (GDPR/CCPA) in contracts.
  • Strong organization and ability to manage multiple threads.
  • Clear written communication and quick learning of new SaaS tools.
  • Self-directed in a small team setting.

Responsibilities

  • Review client MSAs, SOWs, DPAs, and security addenda using our contract analysis tooling; identify clauses that need Legal, IT, or Delivery attention and coordinate redlines through to signature.
  • Translate signed contractual obligations (security, privacy, data handling, audit rights, breach notification, sub-processor terms) into tracked commitments and confirm they are being met operationally.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries; maintain the reusable answer library so responses get faster and more consistent over time.
  • Collect, organize, and maintain control evidence in the GRC platform; track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks as they are adopted.
  • Support vendor risk assessments for SaaS and AI providers: review vendor security documentation, DPAs, and sub-processor lists, and record and monitor findings in the vendor register.
  • Operationalize the data retention and disposal policy: track department retention schedules, document exceptions and legal holds, and verify retention settings across platforms with IT.
  • Support the privacy program including data mapping, data subject request handling, and GDPR and CCPA obligation tracking.
  • Draft and maintain compliance policies, SOPs, and process documentation; keep them current, published (for internal use where applicable) and actually followed.
  • Prepare risk and compliance status reporting for leadership.
  • Participate in business continuity and disaster recovery planning and tabletop exercises.
  • Participate in security incident response management.
  • Maintain and monitor risk register and prepare for annual risk assessment.
  • Administer security awareness training and track compliance.
  • Support internal audits, access reviews, and periodic control testing.

Skills

Contract review
GRC
Privacy
Vendor risk
SOC 2
ISO 27001
NIST CSF
Data mapping
GDPR/CCPA
Security questionnaires

Education

Bachelor’s degree or equivalent

Tools

GRC platform

Job description

Location: This position is remote within the United States.
The role.

We are looking for an IT Risk and Compliance Analyst to join the IT Risk and Compliance team and carry the day-to-day execution of the program. This is a generalist role spanning client contracts and security questionnaires, control evidence and gap remediation, vendor risk, data retention and privacy, and the policies that tie it all together.

The program is being rebuilt from the ground up, so you will help shape how the work gets done. The ideal candidate is organized, comfortable with legal and technical language, and able to keep many threads moving at once.

What you’ll be doing.
  • Review client MSAs, SOWs, DPAs, and security addenda using our contract analysis tooling; identify clauses that need Legal, IT, or Delivery attention and coordinate redlines through to signature.
  • Translate signed contractual obligations (security, privacy, data handling, audit rights, breach notification, sub-processor terms) into tracked commitments and confirm they are being met operationally.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries; maintain the reusable answer library so responses get faster and more consistent over time.
  • Collect, organize, and maintain control evidence in the GRC platform; track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks as they are adopted.
  • Support vendor risk assessments for SaaS and AI providers: review vendor security documentation, DPAs, and sub-processor lists, and record and monitor findings in the vendor register.
  • Operationalize the data retention and disposal policy: track department retention schedules, document exceptions and legal holds, and verify retention settings across platforms with IT.
  • Support the privacy program including data mapping, data subject request handling, and GDPR and CCPA obligation tracking.
  • Draft and maintain compliance policies, SOPs, and process documentation; keep them current, published (for internal use where applicable) and actually followed.
  • Prepare risk and compliance status reporting for leadership.
  • Participate in business continuity and disaster recovery planning and tabletop exercises.
  • Participate in security incident response management.
  • Maintain and monitor risk register and prepare for annual risk assessment.
  • Administer security awareness training and track compliance.
  • Support internal audits, access reviews, and periodic control testing.
What we’d like to see.
  • Bachelor’s degree required or equivalent practical experience.
  • 3–5 years of experience in compliance, GRC, contract management, privacy, or a related field.
  • Hands-on experience reading and reviewing commercial contracts, ideally MSAs, DPAs, or security addenda, and working with legal counsel on redlines.
  • Experience responding to client security questionnaires or vendor due diligence requests.
  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, NIST CSF) and what evidence looks like in practice.
  • Foundational understanding of data privacy regulations (GDPR, CCPA) and how they show up in contracts.
  • Exceptional organization and follow-through; you can run many parallel threads and nothing slips.
  • Clear, concise written communication; you can summarize a 40-page contract into the three things that matter.
  • Comfortable working with SaaS tools and learning new platforms quickly; you like using software to make process better.
  • Self-directed and effective in a small team where you own outcomes end to end.

This role is currently not available for hire or work in New Mexico, Montana, Alaska and Hawaii, USA.

About Huge.

Huge is an independent, human-first AI-native design and technology company. We make things that matter by bringing AI, people, design and technology together as one system. With more than 1,000 design and technology experts working in hub cities around the world, including Bogotá, Chicago, Ho Chi Minh City, London, Los Angeles, Medellín, New York, San Francisco, and Washington, DC, we partner with some of the world’s most ambitious brands, including Google, NBCU, PepsiCo, Vail Resorts, Atlantic Health, and Candescent. Learn more athugeinc.com.

Huge is committed to creating an inclusive employee experience for all. Regardless of race, gender, religion, sexual orientation, age, disability, or if you’re parenting the next generation of innovators, we firmly believe that our work is at its best when everyone feels free to be their most authentic self.

Huge is an equal opportunity employer (EOE). We strongly support diversity in the workforce. We are committed to an inclusive, barrier-free recruitment and selection process and work environment. If you are contacted for a job opportunity, please advise us of any accommodation needed to ensure you have access to a fair and equitable process. Any information received relating to accommodation will be addressed confidentially.

Workers shall not be required to pay employers’ or agents’ recruitment fees or other related fees for their employment. If any such fees are found to be paid by workers, such fees shall be repaid to the worker.

Wage Disclosure

$80,000—$90,000 USD

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Systems Administrator
Systems Administrator

HugeInc • United States

Hybrid
USD 70,000 - 90,000
Hybrid work model
Global team exposure
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
Senior Program Manager - Data Security & Information Governance
Senior Program Manager - Data Security & Information Governance

Qualtrics • United States

On-site
USD 135,000 - 178,000
Office events
Experience Program $1,800
Creative office design
+2
Engineering Manager (GRC Platform)
Engineering Manager (GRC Platform)

Anthropic • San Francisco (CA)

On-site
USD 300,000 - 320,000
Competitive compensation
Generous vacation
Flexible working hours
Director, Security & Compliance
Director, Security & Compliance

MHC • Burnsville (MN)

Remote
USD 180,000 - 240,000
Workplace Flexibility
401(k) Plan
Medical Plans
+3
Data Center Security Compliance Manager
Data Center Security Compliance Manager

Control-Risks • Houston (TX)

Hybrid
USD 140,000 - 150,000
Medical Benefits
Dental Benefits
Vision Benefits
+2
Senior Application Security engineer
Senior Application Security engineer

G-P • United States

Remote
USD 96,000 - 120,000
Paid parental leave
Medical insurance
Dental insurance
+2
Data Center Security Compliance Manager
Data Center Security Compliance Manager

Control Risks • Houston (TX)

On-site
USD 140,000 - 150,000
Medical Benefits
401(k) Retirement
Discretionary bonus
+1
Sr Analyst, Technology Governance & Risk
Sr Analyst, Technology Governance & Risk

The Trade Desk • New York (NY)

On-site
USD 85,300 - 156,400
Healthcare coverage (medical, dental,視
401k with company match
Disability insurance
+6
Freelance Senior Digital Marketing Developer (Content Manager)
Freelance Senior Digital Marketing Developer (Content Manager)

HugeInc • United States

Remote
USD 41,000 - 69,000