Information Technology Risk & Compliance Analyst

ECMC Group, Inc.

• $90K — $100K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in IT, computer information systems, legal studies, or equivalent experience.
  • 3+ years of experience in IT risk and compliance or related fields.
  • Experience with vendor risk assessments and contract reviews.
  • Proficient in assessing security controls for AWS or cloud environments.
  • Advanced knowledge of Microsoft Office, particularly Excel and SharePoint management.
  • Familiarity with compliance frameworks like NIST, ISO2700, and COBIT.

Responsibilities

  • Lead IT compliance activities including planning, risk analysis, and reporting.
  • Conduct vendor security risk assessments and review vendor contracts.
  • Engage with management to identify control weaknesses and compliance risks.
  • Monitor remediation progress on compliance findings and plans.
  • Prepare clear documentation and reports of compliance results and recommendations.
  • Support internal and external audits with preparation of evidence and coordination.
  • Identify emerging risks and opportunities during enterprise risk assessments.

Benefits

  • Comprehensive health benefits including medical, dental, and vision insurance with employer subsidies.
  • Generous 401(k) plan with a company match and potential discretionary contributions.
  • Paid time off accrual starting at 20 days per year, plus holiday time off.
  • Tuition reimbursement up to $10,500 per year for approved educational programs.
  • Student loan payment reimbursement up to $4,800 per year.
Full Job Description

Job Summary


Responsible for planning, executing and reporting on complex IT compliance activities and related initiatives across information systems.  Performs assigned portions of IT compliance programs, determining compliance with policies and procedures, monitoring, recommending corrective action, preparing findings, and assisting with remediation plans.  Reviews and services should be performed in accordance with professional and department standards.


Essential Duties and Responsibilities:

  • Leads and performs complex IT compliance activities including planning, risk analysis, testing and reporting in accordance with professional and department standards.
  • Leads vendor security risk assessments and reviews security and compliance provisions within vendor contracts in partnership with procurement and legal teams.
  • Independently engages management to assess processes, identify control weaknesses and discuss compliance observations and risks.
  • Secures management ownership of findings and remediation plans and monitors remediation progress through completion.
  • Prepares clear documentation and draft reports communicating results, risks and recommendations to improve information system controls and practices.
  • Plans and executes IT compliance reviews and supports internal and external audits through evidence preparation and auditor coordination.
  • Contributes to enterprise risk assessments by identifying emerging risks, control gaps and improvement opportunities.
  • Provides guidance and informal coaching to staff on compliance activities of low to medium complexity as assigned.
  • Anticipates and manages stakeholder expectations while ensuring timely, consistent delivery of compliance services.
  • Communicates complex compliance concepts clearly to peers, leaders and business partners.
  • Performs other duties or responsibilities as assigned.

Required Qualifications:

  • Bachelor’s degree in computer information systems, information technology, legal studies, or related field or an additional 2 years of relevant experience in lieu of degree.
  • Understanding of IT concepts such as identity and access management, threat and vulnerability management, data loss prevention, change management, data analytics, and software development lifecycle
  • 3+ years of experience in IT risk and compliance, IT governance, IT auditing or an IT related field
  • Experience assessing vendor risk, performing security assessments, and reviewing contracts
  • Experience working with procurement and legal teams
  • Experience assessing security controls for AWS or cloud environments
  • Experience developing and maintaining policies and/or information management frameworks
  • Experience creating and assembling evidence for internal or external auditors
  • Advanced knowledge of Microsoft Office suite, including experience analyzing data using Excel and designing or managing SharePoint sites
  • General knowledge of security control concepts, principles, risk analysis, FISMA, PCI Compliance, HIPAA, Privacy, process improvement and techniques, including frameworks such as NIST, ISO2700, COSO and COBIT

Preferred Qualifications:

  • Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications preferred

The pay range for this position is $90,000-$100,000. Actual compensation may vary based on factors such as relevant experience, peer and market benchmarks, and geographic location.


This position is classified as hybrid Monday - Wednesday and requires attendance in Minneapolis, MN.


To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

ECMC Group also provides a comprehensive benefits package:  

  • Health & wellness benefits: Medical, dental, and vision insurance plan options, with a generous employer subsidy. Company paid life & disability insurance, pre-tax flexible spending accounts and robust wellness programs.
  • Financial benefits: Generous 401(k) plan with a company match up to 6% and additional discretionary contribution potential, holiday time off, paid time off accrual starting at 20 days/year and commuter subsidy.
  • Education benefits: Tuition reimbursement up to $10,500/year for approved programs and student loan payment reimbursement up to $4,800/year. Up to $5,250 of qualifying education benefits can be reimbursed pre-tax.

Similar Jobs

More Jobs at ECMC Group, Inc.

More Information Technology Jobs

Find similar Information Technology Risk & Compliance Analyst jobs: