Senior Risk & Compliance Analyst

Ecmc Group

Minneapolis (MN)

Hybrid

USD 115,000 - 125,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health & wellness benefits: medical, d
Life & disability insurance
401(k) with company match
Tuition reimbursement

Job summary

ECMC Group in Minneapolis seeks a senior IT Risk and Compliance leader to guide risk management, regulatory compliance, and information security programs. You will partner with stakeholders to drive assessments, control testing, and training across the enterprise.

You will mentor team members, coordinate audits, and promote strong governance practices while advancing risk-based controls. Hybrid work in Minneapolis with growth opportunities within a mission-driven nonprofit.

Qualifications

  • Bachelor's degree in Computer Information Systems, Information Technology, Legal Studies, or a related field; or an additional two years of relevant IT experience in lieu of a degree.
  • 5+ years of experience in IT risk and compliance, IT governance, IT auditing, information security, or a related field.
  • Experience supporting SOC reporting, third-party assessments, FISMA readiness activities, and internal or external audits.
  • Experience applying security control frameworks, risk assessment methodologies, and compliance standards, including NIST, ISO 27001, COSO, COBIT, PCI DSS, HIPAA, or similar frameworks.
  • Experience evaluating or supporting controls related to identity and access management, vulnerability management, data protection, change management, software development lifecycle, or other IT control domains.
  • Experience assessing security controls within AWS or other cloud environments.
  • Advanced proficiency with Microsoft Office applications, including Excel data analysis and SharePoint content and site administration.

Responsibilities

  • Leads medium to high complexity IT risk and compliance reviews, including planning, risk analysis, evidence gathering, control testing, and reporting.
  • Coordinates and supports FISMA readiness assessments, SOC reporting, external penetration testing, and audits.
  • Plans and coordinates security awareness initiatives, including annual training and phishing simulations.
  • Leads vendor security risk assessments and evaluates security and compliance requirements within vendor relationships.
  • Prepares documentation, reports, and remediation plans to improve information system controls and risk management.

Skills

IT risk & compliance expertise
SOC reporting experience
Security frameworks (NIST, ISO 27001,)
IAM controls
Cloud security (AWS)
Audit coordination
Training content development

Education

Bachelor's degree in CIS/IT or related field

Tools

Excel
SharePoint

Job description

About ECMC Group

ECMC Group is a nonprofit corporation focused on helping students succeed. Headquartered in Minneapolis, ECMC Group and its family of companies provide financial tools and services, as well as funding for innovative programs to help students achieve their academic and professional goals.

Job Summary

Serves as a senior member of the IT Risk and Compliance function, providing expertise and independent judgment to support the organization's risk management, regulatory compliance, and information security objectives. Partners with stakeholders across the enterprise to evaluate risk, strengthen controls, and promote compliance with applicable standards and requirements. Acts as a trusted advisor within the organization, contributing to the effectiveness and continuous improvement of risk and compliance practices while serving as a resource to less experienced team members.

Essential Duties and Responsibilities

Leads and performs medium to high complexity IT risk and compliance reviews, including planning, risk analysis, evidence gathering, control testing, and reporting. Coordinates and supports FISMA readiness assessments, SOC reporting, external penetration testing, and internal and external audit activities. Plans and coordinates security awareness initiatives, including annual training, phishing simulations, security communications, and custom learning content. Leads vendor security risk assessments and evaluates security and compliance requirements within vendor relationships. Independently engages stakeholders to identify control weaknesses, assess compliance risks, and recommend corrective actions. Prepares clear documentation, reports, and recommendations that improve information system controls and risk management practices. Secures stakeholder ownership of findings and remediation plans and monitors progress through resolution. Completes enterprise risk assessments and supports the design and implementation of effective controls to address emerging risks and compliance requirements. Contributes to the development and continuous improvement of risk and compliance standards, policies, procedures, monitoring activities, and governance practices. Mentors less experienced team members, manages stakeholder expectations, and communicates complex compliance concepts to business and technology leaders. Performs other duties or responsibilities as assigned.

Required Qualifications

Bachelor's degree in Computer Information Systems, Information Technology, Legal Studies, or a related field; or an additional two years of relevant IT experience in lieu of a degree. 5+ years of experience in IT risk and compliance, IT governance, IT auditing, information security, or a related field. Experience supporting SOC reporting, third-party assessments, FISMA readiness activities, and internal or external audits. Experience applying security control frameworks, risk assessment methodologies, and compliance standards, including NIST, ISO 27001, COSO, COBIT, PCI DSS, HIPAA, or similar frameworks. Experience evaluating or supporting controls related to identity and access management, vulnerability management, data protection, change management, software development lifecycle, or other IT control domains. Experience assessing security controls within AWS or other cloud environments. Advanced proficiency with Microsoft Office applications, including Excel data analysis and SharePoint content and site administration. Experience developing and delivering training, awareness content, or learning programs using Articulate Rise or similar learning platforms.

Preferred Qualifications

Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications. Big 4 accounting firm experience.

Compensation

The pay range for this position is $115,000-$125,000. Actual compensation may vary based on factors such as relevant experience, peer and market benchmarks, and geographic location.

Work Arrangement

This position is classified as hybrid Monday - Wednesday and requires attendance in Minneapolis, MN.

Benefits
  • Health & wellness benefits: Medical, dental, and vision insurance plan options, with a generous employer subsidy.
  • Company paid life & disability insurance, pre-tax flexible spending accounts and robust wellness programs.
  • Financial benefits: Generous 401(k) plan with a company match up to 6% and additional discretionary contribution potential, holiday time off, paid time off accrual starting at 20 days/year and commuter subsidy.
  • Education benefits: Tuition reimbursement up to $10,500/year for approved programs and student loan payment reimbursement up to $4,800/year. Up to $5,250 of qualifying education benefits can be reimbursed pre-tax.
Employment Eligibility Verification

In compliance with federal law, all persons hired with ECMC Group and its affiliates will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire and ECMC Group participates in E-Verify to verify authorization to work in the U.S.

Click here for more information about the company.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst Senior
Cybersecurity Analyst Senior

Ecmc Group • Minneapolis (MN)

On-site
USD 115,000 - 125,000
Health & wellness benefits
401(k) with company match
Tuition reimbursement
+2
Financial Analyst
Financial Analyst

Ecmc Group • Minneapolis (MN)

Hybrid
USD 65,000 - 85,000
Health & wellness benefits
Generous 401(k) with company match
Paid time off and holidays
+1
Senior IT Risk & Compliance Strategist
Senior IT Risk & Compliance Strategist

Ecmc Group • Minneapolis (MN)

Hybrid
USD 115,000 - 125,000
Health & wellness benefits: medical, d
Life & disability insurance
401(k) with company match
+1
Financial Analyst
Financial Analyst

basecamp • Minneapolis (MN)

Hybrid
USD 65,000 - 85,000
Health & wellness benefits
401(k) plan with company match
Paid time off and holidays
Business Application Support Analyst
Business Application Support Analyst

Ecmc Group • Minneapolis (MN)

On-site
USD 80,000 - 90,000
Health & wellness benefits
401(k) plan with match
Tuition reimbursement
Developer Principal
Developer Principal

Ecmc Group • Minneapolis (MN)

Hybrid
USD 180,000 - 200,000
Health & wellness benefits
Company 401(k) with match
Tuition reimbursement
+1
IS Governance, Risk & Compliance Intern
IS Governance, Risk & Compliance Intern

Blaze Credit Union • Northern (KY)

Hybrid
USD 24,000 - 34,000
Outreach Manager
Outreach Manager

Ecmc Group • Minnesota

Hybrid
USD 90,000 - 110,000
Health insurance
401(k) with company match
Tuition reimbursement
IS Governance, Risk & Compliance Intern
IS Governance, Risk & Compliance Intern

Minnesota League of Credit Unions • Northern (KY)

Hybrid
USD 25,000 - 33,000
Manager, Security Compliance
Manager, Security Compliance

CardWorks Servicing LLC • United States

On-site
USD 128,000 - 143,000
Competitive pay
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
+1