Turn this role into an interview — a resume and cover letter built around what this employer wants.
ECMC Group in Minneapolis seeks a senior IT Risk and Compliance leader to guide risk management, regulatory compliance, and information security programs. You will partner with stakeholders to drive assessments, control testing, and training across the enterprise.
You will mentor team members, coordinate audits, and promote strong governance practices while advancing risk-based controls. Hybrid work in Minneapolis with growth opportunities within a mission-driven nonprofit.
ECMC Group is a nonprofit corporation focused on helping students succeed. Headquartered in Minneapolis, ECMC Group and its family of companies provide financial tools and services, as well as funding for innovative programs to help students achieve their academic and professional goals.
Serves as a senior member of the IT Risk and Compliance function, providing expertise and independent judgment to support the organization's risk management, regulatory compliance, and information security objectives. Partners with stakeholders across the enterprise to evaluate risk, strengthen controls, and promote compliance with applicable standards and requirements. Acts as a trusted advisor within the organization, contributing to the effectiveness and continuous improvement of risk and compliance practices while serving as a resource to less experienced team members.
Leads and performs medium to high complexity IT risk and compliance reviews, including planning, risk analysis, evidence gathering, control testing, and reporting. Coordinates and supports FISMA readiness assessments, SOC reporting, external penetration testing, and internal and external audit activities. Plans and coordinates security awareness initiatives, including annual training, phishing simulations, security communications, and custom learning content. Leads vendor security risk assessments and evaluates security and compliance requirements within vendor relationships. Independently engages stakeholders to identify control weaknesses, assess compliance risks, and recommend corrective actions. Prepares clear documentation, reports, and recommendations that improve information system controls and risk management practices. Secures stakeholder ownership of findings and remediation plans and monitors progress through resolution. Completes enterprise risk assessments and supports the design and implementation of effective controls to address emerging risks and compliance requirements. Contributes to the development and continuous improvement of risk and compliance standards, policies, procedures, monitoring activities, and governance practices. Mentors less experienced team members, manages stakeholder expectations, and communicates complex compliance concepts to business and technology leaders. Performs other duties or responsibilities as assigned.
Bachelor's degree in Computer Information Systems, Information Technology, Legal Studies, or a related field; or an additional two years of relevant IT experience in lieu of a degree. 5+ years of experience in IT risk and compliance, IT governance, IT auditing, information security, or a related field. Experience supporting SOC reporting, third-party assessments, FISMA readiness activities, and internal or external audits. Experience applying security control frameworks, risk assessment methodologies, and compliance standards, including NIST, ISO 27001, COSO, COBIT, PCI DSS, HIPAA, or similar frameworks. Experience evaluating or supporting controls related to identity and access management, vulnerability management, data protection, change management, software development lifecycle, or other IT control domains. Experience assessing security controls within AWS or other cloud environments. Advanced proficiency with Microsoft Office applications, including Excel data analysis and SharePoint content and site administration. Experience developing and delivering training, awareness content, or learning programs using Articulate Rise or similar learning platforms.
Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications. Big 4 accounting firm experience.
The pay range for this position is $115,000-$125,000. Actual compensation may vary based on factors such as relevant experience, peer and market benchmarks, and geographic location.
This position is classified as hybrid Monday - Wednesday and requires attendance in Minneapolis, MN.
In compliance with federal law, all persons hired with ECMC Group and its affiliates will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire and ECMC Group participates in E-Verify to verify authorization to work in the U.S.
Click here for more information about the company.