Skip to content

Open nowPosted 9 hours ago

IT Risk and Compliance Analyst

Jobgether3,797 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT Risk and Compliance AnalystJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 5 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.2%30 days
This job: posted 9 hours ago

Jobgether median: 5 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a IT Risk and Compliance Analyst based in United States .

This role supports the day-to-day execution of a growing IT risk, compliance, privacy, and governance program. You will work across contracts, security questionnaires, control evidence, vendor risk, data retention, and compliance policies. The position offers the opportunity to help shape a program being rebuilt from the ground up and establish scalable ways of working. You will collaborate with Legal, IT, Delivery, leadership, vendors, and other stakeholders to translate requirements into practical controls and actions. The role combines technical and legal concepts with hands-on program coordination, risk management, and process improvement. Success requires exceptional organization, strong written communication, sound judgment, and the ability to manage multiple priorities independently. This is an ideal opportunity for a compliance professional who enjoys ownership, variety, and building effective processes within a collaborative environment.

Accountabilities:

  • Review client MSAs, SOWs, DPAs, security addenda, and related agreements using contract analysis tools, identifying provisions requiring attention from Legal, IT, Delivery, or other stakeholders and coordinating redlines through completion.
  • Translate contractual security, privacy, data handling, audit, breach notification, and sub-processor requirements into trackable operational commitments and verify that obligations are being met.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries while maintaining and improving a reusable knowledge base to make future responses faster and more consistent.
  • Collect, organize, maintain, and manage control evidence within the GRC platform, tracking remediation activities against frameworks such as SOC 2, ISO 27001, NIST CSF, and other applicable standards.
  • Support vendor risk management activities for SaaS and AI providers by reviewing security documentation, DPAs, sub-processor information, and findings, while maintaining accurate vendor risk records.
  • Operationalize data retention and disposal requirements by tracking departmental retention schedules, documenting exceptions and legal holds, and working with IT to verify retention settings across relevant platforms.
  • Support privacy program activities including data mapping, data subject request processes, and monitoring obligations associated with GDPR, CCPA, and other applicable privacy requirements.
  • Draft, maintain, publish, and improve compliance policies, standard operating procedures, and process documentation, ensuring that requirements remain current and are effectively implemented.
  • Prepare risk and compliance reporting for leadership, highlighting program status, emerging risks, remediation progress, and areas requiring attention.
  • Maintain and monitor the risk register, support annual risk assessments, and contribute to the identification, evaluation, and treatment of organizational risks.
  • Participate in business continuity and disaster recovery planning, tabletop exercises, security incident response, internal audits, access reviews, and periodic control testing.
  • Administer security awareness training programs and monitor completion and compliance across the organization.
  • Bachelor’s degree or equivalent practical experience, with 3–5 years of professional experience in compliance, GRC, contract management, privacy, risk, or a related field.
  • Hands-on experience reviewing commercial agreements, ideally including MSAs, DPAs, security addenda, or similar documents, with the ability to collaborate effectively with legal counsel on contractual redlines.
  • Experience responding to client security questionnaires, vendor due diligence requests, audit inquiries, or comparable compliance information requests.
  • Working knowledge of at least one major security or compliance framework, such as SOC 2, ISO 27001, or NIST CSF, including a practical understanding of the evidence required to demonstrate control effectiveness.
  • Foundational understanding of data privacy regulations such as GDPR and CCPA, particularly how privacy requirements translate into contracts, operational processes, and compliance obligations.
  • Exceptional organizational and follow-through skills, with the ability to manage numerous parallel workstreams, deadlines, stakeholders, and remediation activities without losing attention to detail.
  • Clear, concise, and confident written communication skills, including the ability to interpret complex technical or legal information and distill it into practical priorities and recommendations.
  • Strong analytical, problem-solving, and judgment skills, with the ability to identify gaps, assess risks, coordinate solutions, and follow issues through to resolution.
  • Comfortable working with SaaS platforms, GRC systems, contract analysis tools, and other technology, with a demonstrated ability to learn new systems quickly and use technology to improve processes.
  • Self-directed and accountable, with the ability to own outcomes end to end while working effectively within a small, collaborative team.
  • Comfortable working across technical, legal, operational, and business functions and translating requirements between different stakeholder groups.
  • Salary range of $80,000–$90,000 USD.
  • Remote working arrangement within the United States.
  • Opportunity to help build and shape an IT risk and compliance program from the ground up.
  • Broad exposure to IT risk, compliance, privacy, vendor management, contracts, security operations, and governance.
  • Collaborative and inclusive work environment that values diverse perspectives and authentic contributions.
  • Opportunities to work closely with cross-functional teams across legal, technology, delivery, security, and leadership functions.
  • Meaningful ownership and autonomy within a growing compliance program.
  • Opportunity to contribute to process improvement and the development of scalable compliance practices.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.