IT Risk and Compliance Analyst
Job Details
- Experience
- 3–5 years of professional experience in compliance, GRC, contract management, privacy, risk, or a related field.
Requirements
- Hold a bachelor’s degree or have equivalent practical experience.
- Have 3–5 years of professional experience in compliance, GRC, contract management, privacy, risk, or a related field.
- Have hands-on experience reviewing commercial agreements, ideally including MSAs, DPAs, and security addenda, and collaborating with legal counsel on redlines.
- Have experience responding to client security questionnaires, vendor due diligence requests, audit inquiries, or comparable compliance information requests.
- Have working knowledge of at least one major security or compliance framework, such as SOC 2, ISO 27001, or NIST CSF, including evidence needed to demonstrate control effectiveness.
- Have foundational knowledge of GDPR and CCPA, particularly how privacy requirements apply to contracts, operational processes, and compliance obligations.
- Be able to manage parallel workstreams, deadlines, stakeholders, and remediation activities with attention to detail.
- Be able to interpret complex technical or legal information and communicate practical priorities and recommendations in writing.
- Have analytical, problem-solving, and judgment skills to identify gaps, assess risks, coordinate solutions, and follow issues through to resolution.
- Be comfortable using SaaS platforms, GRC systems, and contract analysis tools, and able to learn new systems quickly.
- Be able to work independently and across technical, legal, operational, and business functions.
Responsibilities
- Review client MSAs, SOWs, DPAs, security addenda, and related agreements, identify provisions requiring attention, and coordinate redlines through completion.
- Translate contractual security, privacy, data handling, audit, breach notification, and sub-processor requirements into operational commitments and verify that obligations are met.
- Respond to client security questionnaires, due diligence requests, and audit inquiries, and maintain a reusable knowledge base.
- Collect and manage control evidence in the GRC platform and track remediation against SOC 2, ISO 27001, NIST CSF, and other applicable standards.
- Review security documentation, DPAs, sub-processor information, and findings for SaaS and AI providers, and maintain vendor risk records.
- Track departmental data retention schedules, document exceptions and legal holds, and work with IT to verify retention settings.
- Support data mapping, data subject request processes, and monitoring obligations associated with GDPR, CCPA, and other privacy requirements.
- Draft, maintain, publish, and improve compliance policies, standard operating procedures, and process documentation.
- Prepare leadership risk and compliance reporting, maintain the risk register, and support annual risk assessments.
- Participate in continuity and disaster recovery planning, tabletop exercises, incident response, internal audits, access reviews, control testing, and security awareness training.