Senior IT Risk & Compliance Lead (Hybrid)

ECMC Group

Minneapolis (MN)

Hybrid

USD 115,000 - 125,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health & wellness benefits
401(k) plan with company match
Tuition reimbursement

Job summary

ECMC Group, a nonprofit headquartered in Minneapolis, seeks a senior IT risk and compliance leader to support risk management, regulatory compliance, and information security objectives. You will partner with stakeholders to evaluate risk, strengthen controls, and promote compliance with applicable standards.

You will oversee risk reviews, FISMA readiness, SOC reporting, audits, and security awareness initiatives, while mentoring junior staff and driving governance improvements across the

Qualifications

  • Bachelor's degree in Computer Information Systems, Information Technology, Legal Studies, or related field, or +2 years relevant IT experience in lieu of a degree.
  • 5+ years of IT risk and compliance, IT governance, IT auditing, information security, or related field.
  • Experience supporting SOC reporting, third-party assessments, FISMA readiness activities, and audits.
  • Experience applying security control frameworks (NIST, ISO 27001, COSO, COBIT, PCI DSS, HIPAA).
  • Experience evaluating controls in IAM, vulnerability management, data protection, change management, SDLC, or other IT control domains.
  • Experience assessing security controls in AWS or other cloud environments.
  • Proficiency with Microsoft Office, especially Excel and SharePoint.
  • Experience delivering training/learning content (Articulate Rise).

Responsibilities

  • Leads medium to high complexity IT risk and compliance reviews (planning, risk analysis, testing, reporting).
  • Supports FISMA readiness, SOC reporting, external penetration testing, and audits.
  • Coordinates security awareness initiatives and phishing simulations.
  • Leads vendor security risk assessments within vendor relationships.
  • Engages stakeholders to identify control weaknesses and remediation actions.
  • Documents findings and ensures ownership and progress on remediation.
  • Performs enterprise risk assessments and helps design effective controls.
  • Contributes to development and improvement of risk and compliance standards and governance.

Skills

IT risk
Compliance
SOC reporting
FISMA
NIST
ISO 27001
COSO
COBIT
PCI DSS
HIPAA

Education

Bachelor's degree or higher in CIS/IT/Legal Studies

Tools

Excel
SharePoint
Articulate Rise

Job description

ECMC Group, a nonprofit headquartered in Minneapolis, seeks a senior IT risk and compliance leader to support risk management, regulatory compliance, and information security objectives. You will partner with stakeholders to evaluate risk, strengthen controls, and promote compliance with applicable standards.

You will oversee risk reviews, FISMA readiness, SOC reporting, audits, and security awareness initiatives, while mentoring junior staff and driving governance improvements across the

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Risk & Compliance Lead: Vendor Security & Controls
IT Risk & Compliance Lead: Vendor Security & Controls

Ecmc Group • Minneapolis (MN)

Hybrid
USD 90,000 - 100,000
Health & wellness benefits
Life & disability insurance
401(k) plan with company match
+4
Information Technology Risk & Compliance Analyst
Information Technology Risk & Compliance Analyst

Ecmc Group • Minneapolis (MN)

Hybrid
USD 90,000 - 100,000
Health & wellness benefits
Life & disability insurance
401(k) plan with company match
+4
Senior Cloud Security & Incident Response Analyst
Senior Cloud Security & Incident Response Analyst

Ecmc Group • Minneapolis (MN)

Hybrid
USD 115,000 - 125,000
Health & wellness benefits
401(k) with company match
Tuition reimbursement
+2
Senior ECM Compliance & Risk Strategy Consultant
Senior ECM Compliance & Risk Strategy Consultant

Kaiser Permanente • Denver (CO), Northern (KY)

Hybrid
USD 110,000 - 150,000
Hybrid Senior Cybersecurity Risk & Compliance Lead
Hybrid Senior Cybersecurity Risk & Compliance Lead

Nelnet • Centennial (CO)

Hybrid
USD 85,000 - 130,000
Medical insurance
401K and student loan repayment
Tuition reimbursement
Cybersecurity Analyst Senior
Cybersecurity Analyst Senior

Ecmc Group • Minneapolis (MN)

On-site
USD 115,000 - 125,000
Health & wellness benefits
401(k) with company match
Tuition reimbursement
+2
Senior IT Compliance & Governance Leader
Senior IT Compliance & Governance Leader

Recru, LLC. • Houston (TX)

On-site
USD 140,000 - 180,000
Senior Cybersecurity & IT Risk Leader (Hybrid)
Senior Cybersecurity & IT Risk Leader (Hybrid)

ESP Enterprises, Inc. • The Woodlands (TX), Northern (KY)

Hybrid
USD 140,000 - 210,000
IT Risk & Compliance Consultant — Seattle (Hybrid)
IT Risk & Compliance Consultant — Seattle (Hybrid)

EY • Seattle (WA)

Hybrid
USD 98,000 - 180,000
Hybrid work model
Technology Risk & Compliance Manager
Technology Risk & Compliance Manager

Northwest-Bank • Pittsburgh

On-site
USD 120,000 - 180,000