Source Job

$80,000–$90,000/yr
US

  • Support day-to-day execution of IT risk, compliance, privacy, and governance programs.
  • Review client agreements and security questionnaires, coordinating redlines with legal.
  • Manage control evidence, vendor risk, data retention, and compliance policies.

Compliance GRC Risk Management Contract Management Data Privacy

20 jobs similar to IT Risk and Compliance Analyst

Jobs ranked by similarity.

India

  • Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
  • Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
  • Manage third-party risk assessments and track remediation of security findings.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They partner with companies to manage applications and hiring processes, offering remote roles and streamlined recruitment.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

US

  • Plan, implement, and upgrade security controls and architecture to safeguard systems and sensitive information.
  • Conduct risk assessments, penetration testing, and vulnerability assessments, then track mitigation plans.
  • Support compliance with NIST 800-171, develop governance documentation, and deliver security awareness training.

Insitu, a Boeing Company, provides unmanned air systems and software solutions for collecting, processing, and understanding sensor data to support critical decision-making. With over 1 million operational flight hours, the company values integrity, collaboration, and adaptability in a fast-paced, mission-driven environment.

US

  • Lead and mature the organization's governance, risk management, compliance, and audit programs.
  • Own cybersecurity compliance initiatives including CMMC Level 2, SOC audits, and SOX IT General Controls.
  • Partner with business, technology, and executive stakeholders to align security controls with regulatory and business requirements.

Loenbro is a trusted construction lifecycle partner serving thousands of customers across the U.S. with services including electrical, mechanical, structural, inspection, and fabrication. The company has a national presence with a local approach and fosters a culture of integrity, teamwork, and purpose.

US 3w PTO

  • Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
  • Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
  • Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.

The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.

$77,000–$107,000/yr
US

  • Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
  • Support internal and external audits against Federal requirements and organizational policies.
  • Develop and maintain cybersecurity policies, procedures, and compliance documentation.

PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Anovia is an industry-leading technology outsourcing support provider specializing in workflow and knowledge processes, technical support, helpdesk, and multilingual services. With over 200 experts globally, we serve Fortune 500 companies and value growth, learning, and work-life balance.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

US

  • Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
  • Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
  • Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.

9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.

$130,000–$150,000/yr
US

  • Own and mature security, privacy, and compliance programs across HIPAA, SOC 2, and HITRUST.
  • Lead HITRUST certification end to end, including scoping, evidence collection, and assessor coordination.
  • Partner with Engineering, Product, SRE, and IT to integrate security into architecture, SDLC, and cloud infrastructure.

IntusCare is an end-to-end ecosystem built specifically to help PACE programs deliver exceptional care, strengthen financial performance, and stay compliant. It is a growing healthcare SaaS organization that empowers teams to improve outcomes for dual-eligible seniors.

Global 4w PTO

  • Act as part vCISO and account manager, guiding clients through security and compliance programs.
  • Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
  • Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.

Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.

$154,000–$207,000/yr
US 3w PTO

  • Lead security risk assessments across engineering, IT, operations, and business functions.
  • Maintain a risk register and provide leadership with a clear view of the company's risk posture.
  • Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.

Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.

Global

  • Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
  • Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
  • Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.

Duvo builds an AI operations platform for large enterprises, enabling customers to create AI agents that automate business-critical processes across systems like SAP, spreadsheets, and supplier portals. The company is growing fast and values velocity, direct feedback, autonomy, and heavy use of AI tools.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

$100,000–$120,000/yr
US

  • Manage day-to-day privacy compliance program operations, including policies, procedures, records, documentation, and supporting processes.
  • Conduct and coordinate Privacy Impact Assessments (PIAs/DPIAs) and data protection assessments for new products, features, vendors, and business initiatives.
  • Support data subject rights requests and privacy incident response processes.

This company operates in the health technology space, focusing on privacy and compliance. It is a fast-growing, remote-first organization with a collaborative culture emphasizing transparency, empowerment, and evidence-based decisions.

$160,000–$180,000/yr
Global Unlimited PTO

  • Oversee the IT & Security team, including helpdesk workflows, project roadmaps, and cross-functional security initiatives.
  • Maintain audit-ready security and compliance processes, including identity access management, authentication standards, and disaster recovery.
  • Manage vendor relationships, evaluations, and contracts to ensure tools spend is carefully and thoughtfully managed.

People Data Labs is the trusted provider of workforce data, collecting and standardizing data to enable companies to build compliant data solutions. The company is a fully profitable, intentionally smaller remote team that values security and a fun, unhinged workplace.

$104,000–$140,000/yr
US

  • Develops and maintains information security policies, procedures, and controls ensuring compliance with HITRUST, SOC 2, HIPAA, and other frameworks.
  • Leads audit readiness and execution, managing HITRUST and SOC 2 Type II examinations from planning through report issuance.
  • Drives continuous improvement of security processes, risk management, and incident response across the organization.

MRO specializes in information security assurance and regulatory compliance, helping organizations manage risk and maintain audit readiness. The company fosters a security-focused culture with a team of experienced professionals.

US Unlimited PTO

  • Serve as Compliance Officer and HIPAA Security Officer, leading compliance and information security programs.
  • Own HIPAA/HITECH compliance, SOC 2 Type II certifications, and policy framework governance.
  • Partner with Engineering, DevOps, Legal, and other functions to embed security and compliance into operations.

Prompt delivers highly automated modern software to rehab therapy businesses, revolutionizing healthcare technology. As one of the fastest-growing healthcare SaaS companies, it fosters an innovative, remote-friendly culture with a talented team.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.