Technology Risk & Compliance Analyst

001 Brown & Brown, Inc

Town of Texas (WI)

Hybrid

USD 85,000 - 105,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Benefits: Medical/Rx, Dental, V
401k; ESPP; Student Loan Assistance
Mental Health & Wellness programs
Paid Time Off and Holidays

Job summary

Brown & Brown in Plano, TX, is seeking a Technology Risk & Compliance Analyst to embed risk and regulatory alignment into delivery across applications, infrastructure, and data environments.

The role partners with portfolio leaders, delivery teams, security, and business stakeholders to identify and remediate risks, enforce policies, and support audits. Travel up to 30% may be required.

Qualifications

  • Bachelor's degree in IT, cybersecurity, business, or related field.
  • 3–7 years of IT risk, compliance, audit, or cybersecurity experience.
  • Strong working knowledge of GRC frameworks (e.g., NIST, ISO 27001, COBIT).
  • Knowledge of regulatory standards (SOX, SOC, GDPR, or similar).
  • Experience with risk assessment, control design, and audit support.
  • Ability to translate technical risk into business impact and executive-level messaging.
  • Strong collaboration and stakeholder management across technology and business teams.
  • High attention to detail with disciplined documentation practices.
  • Able to travel up to 30%.

Responsibilities

  • Identify, assess, and document technology risks across projects, products, and platforms within the Retail portfolio.
  • Facilitate risk prioritization based on impact, regulatory exposure, and risk appetite.
  • Conduct risk assessments for new initiatives, including M&A integrations.
  • Partner with project managers and product teams to embed risk mitigation into delivery plans.
  • Ensure risk mitigation aligns to enterprise risk appetite and portfolio priorities.
  • Monitor risk exposure and track remediation through completion.
  • Ensure alignment with internal policies and external regulatory requirements (SOX, SOC, data privacy).
  • Support IT governance, risk, and compliance (GRC) frameworks.
  • Evaluate and ensure policies, standards, procedures are fit for purpose.
  • Recommend updates to policies based on regulatory changes and audits.
  • Maintain compliance documentation, control narratives, and evidence repositories.
  • Monitor adherence to policies and SOPs across the portfolio.
  • Support internal and external audit activities and remediation tracking.
  • Partner with Audit to support SOX compliance, evidence validation, and remediation.
  • Assess IT controls and identify gaps across applications, infrastructure, and processes.
  • Strengthen control design and execution with control owners.
  • Drive timely closure of audit findings and deficiencies.
  • Collaborate with Vendor Management to address third-party risks.
  • Report findings to governance forums and leadership with actionable insights.
  • Track KRIs, control effectiveness, and remediation progress.
  • Identify opportunities to improve GRC processes and tooling.

Skills

IT risk
Compliance
Audit
Cybersecurity
Stakeholder mgmt
Communication
Documentation
Travel up to 30%

Education

Bachelor's degree in IT, cybersecurity, business, or related field

Job description

Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers. Brown & Brown is seeking a Technology Risk & Compliance Analyst to join our growing team in Plano, Texas! This role embeds risk and compliance into delivery as an integrated capability that enables speed, quality, and regulatory alignment. The ideal candidate will partner with portfolio leaders, delivery teams, security, and business stakeholders to proactively identify, prioritize, and manage risks, enforce compliance standards, and drive remediation across applications, infrastructure, and data environments. This role aligns to the Retail OCIO objective of managing risk within defined appetite while enabling scalable, secure technology delivery.

How you will Contribute:
Technology Risk Management
  • Identify, assess, and document technology risks across projects, products, and platforms within the Retail portfolio.
  • Facilitate the prioritization of technology risks based on business impact, regulatory exposure, and defined risk appetite.
  • Conduct risk assessments for new initiatives, including M&A integrations and platform implementations.
  • Partner with project managers and product teams to integrate risk mitigation into delivery plans and milestones.
  • Ensure risk mitigation strategies align to enterprise risk appetite and portfolio priorities.
  • Monitor risk exposure and ensure remediation activities are tracked through completion.
Compliance Oversight & Governance
  • Ensure alignment with internal policies and external regulatory requirements (e.g., SOX, SOC controls, data privacy standards).
  • Support implementation and maintenance of IT governance, risk, and compliance (GRC) frameworks.
  • Evaluate and ensure technology policies, standards, and procedures are fit for purpose and aligned to regulatory and business requirements.
  • Recommend updates to policies and standards based on regulatory changes, audit findings, and evolving risk landscape.
  • Maintain compliance documentation, control narratives, and evidence repositories.
  • Monitor and report adherence to policies, standards, and standard operating procedures across the portfolio.
Audit & Control Effectiveness
  • Support internal and external audit activities, including evidence collection, walkthroughs, and remediation tracking.
  • Partner with internal and external Audit to support successful audit outcomes, including SOX compliance, evidence validation, and timely remediation of findings.
  • Assess effectiveness of IT controls and identify gaps across applications, infrastructure, and processes.
  • Partner with control owners to strengthen control design and execution.
  • Drive timely closure of audit findings and control deficiencies.
Vendor & Third-Party Risk
  • Partner with Vendor Management and enterprise third- and fourth-party risk teams to ensure technology-related vendor risks are identified and addressed.
  • Incorporate vendor-related risks into portfolio-level risk visibility and reporting.
  • Support tracking and remediation of vendor-related control gaps impacting Retail Technology delivery.
Reporting & Decision Support
  • Prepare and deliver transparent, decision-ready reporting for governance forums, including Steering Committees and OCIO leadership.
  • Provide insights that enable leadership to evaluate risk exposure alongside investment, delivery progress, and business outcomes.
  • Highlight trade-offs, emerging risks, and areas requiring leadership attention or decision.
  • Track key risk indicators (KRIs), control effectiveness, and remediation progress.
Continuous Improvement
  • Identify opportunities to streamline and improve GRC processes, tooling, and operating model effectiveness.
  • Contribute to the evolution of OCIO governance, risk, and control frameworks.
Skills and Experience to be Successful:
  • Bachelor's degree in Information Technology, Cybersecurity, Business, or related field.
  • 3–7 years of experience in IT risk, compliance, audit, or cybersecurity.
  • Strong working knowledge of GRC frameworks (e.g., NIST, ISO 27001, COBIT).
  • Knowledge of regulatory standards (SOX, SOC, GDPR, or similar).
  • Experience with risk assessment, control design, and audit support.
  • Ability to translate technical risk into business impact and executive-level messaging.
  • Strong collaboration and stakeholder management across technology and business teams.
  • High attention to detail with disciplined documentation practices.
  • Able to travel up to 30%.

Pay Range $85,000 - $105,000 Annual The pay range provided above is made in good faith and based on our lowest and highest annual salary or hourly rate paid for the role and takes into account years of experience required, geography, and/or budget for the role.

Teammate Benefits & Total Well-Being
  • Health Benefits: Medical/Rx, Dental, Vision, Life Insurance, Disability Insurance
  • Financial Benefits: ESPP; 401k; Student Loan Assistance; Tuition Reimbursement
  • Mental Health & Wellness: Free Mental Health & Enhanced Advocacy Services
  • Beyond Benefits: Paid Time Off, Holidays, Preferred Partner Discounts and more. Not reflective of all benefits. Enrollment waiting periods or eligibility criteria may apply to certain benefits. Benefit details and offerings may vary for subsidiary entities or in specific geographic locations.
Recruiting Vendor Disclosure Statement

Brown & Brown does not accept unsolicited resumes from external recruiters, recruitment vendors or employment agencies ("Recruiting Vendors"). Recruiting Vendors must have a valid written agreement and received prior written authorization from an authorized Brown & Brown representative before submitting candidates for any publicly posted role. Any unsolicited resumes submitted to Brown & Brown or its employees become the property of Brown & Brown, and no fees will be paid for such submissions. Additional information regarding this policy can be found on our careers page.

The Power To Be Yourself

As an Equal Opportunity Employer, we are committed to fostering an inclusive environment comprised of people from all backgrounds, with a variety of experiences and perspectives, guided by our Diversity, Inclusion & Belonging (DIB) motto, “The Power to Be Yourself”. We think of ourselves as a team, so we have teammates - not employees. We strive to attract people who are competitive, driven, and disciplined. Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers. Founded in 1939 as a small, two-partner firm, Brown & Brown (NYSE: BRO) and our team of companies have grown into one of the world’s largest insurance brokerages while staying true to our foundation of trust, resilience, and delivering results. With a team that is as connected locally as it is globally, our high-performing, highly collaborative team delivers innovative risk and insurance solutions. We look for individuals who embrace our culture, thrive in a collaborative environment, are driven to grow and succeed, and are committed to always doing what is right. With a unique culture built on integrity, superior capabilities and grit, we value teamwork, trust and courage. We think of ourselves as a team, so we have teammates—not employees, and leaders—not managers. Everything we do is about the greater “WE”—never “me.” While diverse in abilities and experience, we are all connected through our core values, a commitment to our local communities and a shared mission—always doing what is best for our customers. Brown & Brown and its affiliates maintain an internal recruiting team responsible for filling open roles posted to the public. In certain situations, Brown & Brown may supplement its internal capabilities by engaging external recruiting vendors and employment agencies (“Recruiting Vendors”). Recruiting Vendors are not authorized to submit resumes, share candidate data, or directly or indirectly contact Brown & Brown employees to present candidates for employment opportunities. The only exception applies to Recruiting Vendors with an active Valid Agreement (as defined below) that has been approved by Brown & Brown. In accordance with this policy, and to ensure appropriate authorization for sharing candidate personal information, Brown & Brown will not accept unsolicited resumes from any source other than Authorized Recruiting Vendors with a Valid Agreement in place who have been expressly invited to support a specific role. Any unsolicited resumes, incomplete submissions, or candidate data received through any means (including email or otherwise) will be considered the property of Brown & Brown. Brown & Brown will not pay any placement or related fees for unsolicited submissions or candidate data provided in violation of this policy. Such submissions may be used by Brown & Brown without any obligation to pay fees of any kind to Recruiting Vendors. A Valid Agreement is defined as a written contract signed by an authorized representative of Brown & Brown. In the absence of a Valid Agreement, Brown & Brown assumes no liability under any legal theory, including but not limited to breach of contract, breach of implied contract, tortious interference, quantum meruit, any/or any other contractual or equitable claims in connection with candidates identified through unsolicited submissions made in violation of this policy.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Director, Finance Business Partner - Technology
Sr. Director, Finance Business Partner - Technology

001 Brown & Brown, Inc • Daytona Beach (FL)

On-site
USD 140,000 - 190,000
Health Benefits: Medical/Rx, Dental, V
Financial Benefits: ESPP; 401k; Loan/"
Mental Health & Wellness: Free Mental{
+1
Care Coordinator
Care Coordinator

001 Brown & Brown, Inc • United States

Remote
USD 25,000 - 28,000
Health Benefits
Financial Benefits
Mental Health & Wellness
+1
Geographic Sales Leader - Employee Benefits
Geographic Sales Leader - Employee Benefits

001 Brown & Brown, Inc • Tennessee

Hybrid
USD 200,000 - 300,000
Health benefits (Medical/Rx, Dental, V
Life Insurance
401k; ESPP
+4
Employee Benefits Consulting Analyst
Employee Benefits Consulting Analyst

001 Brown & Brown, Inc • Southborough (MA)

On-site
USD 55,000 - 80,000
Health Benefits
401k
Student Loan Assistance
+1
Geographic Sales Leader - Property and Casualty
Geographic Sales Leader - Property and Casualty

001 Brown & Brown, Inc • Illinois

Hybrid
USD 200,000 - 300,000
Health Benefits
401k
Employee stock purchase plan
+3
Health Actuarial Senior Consultant
Health Actuarial Senior Consultant

001 Brown & Brown, Inc • Minneapolis (MN)

On-site
USD 100,000 - 150,000
Health Benefits
401k
Student Loan Assistance
+3
Compliance Regulatory & Legislative Strategy Attorney
Compliance Regulatory & Legislative Strategy Attorney

Brown & Brown, Inc. • Town of Florida (NY), Northern (KY)

On-site
USD 180,000 - 260,000
Health benefits
401k and ESPP
Student loan assistance
+2
Account Manager, Captives
Account Manager, Captives

001 Brown & Brown, Inc • United States

Remote
USD 70,000 - 85,000
Health Benefits
ESPP
401k
+6
Technical Program Manager - CRM
Technical Program Manager - CRM

Brown & Brown • Plano (TX)

On-site
USD 130,000 - 180,000
Health Benefits
401k
Student Loan Assistance
+5
Lead Claims Advocate
Lead Claims Advocate

001 Brown & Brown, Inc • United States

Remote
USD 84,000 - 157,000
Health benefits
401k & ESPP
Student loan assistance
+3