1

It Risk And Compliance Jobs (NOW HIRING)

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

Scope of Position The IT Risk & Compliance Analyst, as part of the Information Security organization, is responsible for supporting the execution of Watts' IT compliance, audit readiness ...

IT Risk & Compliance

Cranston, RI · On-site

$91K - $92K/yr

Company Description SonSoft is an IT Staffing and consulting firm and duly organized under the laws of the Commonwealth of Georgia. We are growing at a steady pace specializing in the fields of ...

The Director IT Risk and Controls leads Sedgwick's IT risk and control governance activities ... Serves as the senior subject matter expert for IT SOX compliance, ITGCs, automated controls, key ...

The Director IT Risk and Controls leads Sedgwick's IT risk and control governance activities ... Serves as the senior subject matter expert for IT SOX compliance, ITGCs, automated controls, key ...

This high-impact position in the Governance, Risk & Compliance function sits at the center of the ... Strengthen IT Governance & Controls * Lead the development of executive-level reporting on IT risk, ...

next page

Showing results 1-20

It Risk And Compliance information

What is IT Risk and Compliance?

IT Risk and Compliance refers to the process of identifying, assessing, and managing risks associated with an organization's information technology systems, while ensuring that these systems adhere to relevant laws, regulations, and internal policies. Professionals in this field work to protect sensitive data, prevent security breaches, and ensure that the organization's IT practices are compliant with industry standards such as GDPR, HIPAA, or SOX. They often conduct risk assessments, implement controls, monitor compliance, and respond to audits. The goal is to minimize potential threats to IT infrastructure and maintain the trust of customers and stakeholders.

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance professional?

To thrive as an IT Risk and Compliance professional, you need a solid understanding of IT governance, risk management frameworks, regulatory requirements, and a relevant degree such as in information technology, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISA, CRISC, or CISSP, is typically required. Strong analytical thinking, attention to detail, and effective communication help professionals excel in navigating complex regulations and collaborating with cross-functional teams. These skills and qualifications are crucial for ensuring organizational compliance, mitigating security risks, and maintaining trust with stakeholders.

How does an IT Risk and Compliance professional typically collaborate with other departments to ensure regulatory adherence?

IT Risk and Compliance professionals regularly work with teams across the organization—such as IT, legal, audit, and business operations—to identify risks, interpret regulations, and implement compliance controls. They facilitate training, conduct assessments, and coordinate responses to audits or incidents, ensuring that everyone understands their responsibilities. Effective communication and strong relationship-building skills are essential, as much of the role involves translating technical requirements into actionable steps for non-technical staff. This cross-functional collaboration helps maintain a culture of compliance and minimizes organizational risk.

What is the difference between It Risk And Compliance vs Cybersecurity Analyst?

AspectIt Risk And ComplianceCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, risk assessments, compliance auditsMonitoring security threats, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on protecting information, It Risk And Compliance emphasizes establishing policies, ensuring regulatory adherence, and managing overall risk frameworks. Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Understanding these differences helps organizations assign the right responsibilities and professionals for their security needs.

Is IT risk and compliance a good career?

IT risk and compliance is a growing field that involves managing cybersecurity threats, ensuring regulatory adherence, and implementing security controls. Professionals in this area often require certifications like CISSP or CISA and work in environments that demand strong analytical and technical skills. It offers opportunities for career advancement and job stability due to increasing regulatory requirements and cybersecurity concerns.
More about It Risk And Compliance jobs

What cities are hiring for It Risk And Compliance jobs?

Cities with the most It Risk And Compliance job openings:

What states have the most It Risk And Compliance jobs?

States with the most job openings for It Risk And Compliance jobs include:

Infographic showing various It Risk And Compliance job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

IT Risk & Compliance Analyst

North Andover, MA • Remote

$100K - $101K/yr

Full-time

Medical, Dental, Retirement, PTO

Re-posted 20 days ago


Job description

We're Watts. Together, we're reimagining the future of water.

We feel proud every day about what we do. We're all part of the same crucial mission, no matter what function we support -- it's to provide safe, clean water for the world, and to protect our planet's most valuable resource.

What we do:

For 150 years, Watts has built best-in-class products that are trusted bycustomers in residential and commercial settings across the world.We areat theforefront of innovation, working with cutting-edge technology to provide smart andconnected, sustainable water solutions for the future. Watts is a leading brand with aquality reputation - and we have a dynamic future ahead.

Scope of Position

The IT Risk & Compliance Analyst, as part of the Information Security organization, is responsible for supporting the execution of Watts' IT compliance, audit readiness, cybersecurity findings management, and risk management activities. This role coordinates audit and compliance efforts across Information Security, IT, Internal Audit, business stakeholders, and external assessors while supporting SOX IT General Controls (ITGCs), cybersecurity compliance obligations, and continuous process improvement initiatives.

This position reports to the Manager, IT Risk & Compliance. This role is remote and may be based anywhere within the United States.

Primary Job Duties and Responsibilities

  • Coordinate IT compliance, audit-related activities, and cybersecurity findings management efforts across Information Security, IT, Internal Audit, business control owners, and external assessors.

  • Support SOX IT General Controls (ITGC) activities, including planning, evidence collection, documentation review, auditor inquiries, testing support, and issue resolution.

  • Administer and maintain compliance, audit, findings, and risk management information within Optro (AuditBoard) and other systems of record.

  • Track audit findings, remediation plans, risk items, action plans, and stakeholder commitments to ensure timely completion and closure.

  • Support internal and external audits, assessments, walkthroughs, control testing activities, and evidence requests.

  • Assist with compliance and risk management activities related to cybersecurity disclosures, privacy requirements, data protection regulations, and external security assessments.

  • Partner with control owners, process owners, and risk owners to clarify compliance requirements, facilitate evidence collection, and support remediation activities.

  • Monitor timelines, milestones, dependencies, and deliverables across multiple concurrent compliance and audit workstreams.

  • Prepare organized documentation, status reports, metrics, dashboards, and management reporting materials to support decision-making and audit readiness.

  • Maintain accurate records of controls, risks, findings, remediation activities, and supporting evidence.

  • Assist in mapping controls, risks, findings, and supporting documentation to the NIST Cybersecurity Framework and other applicable regulatory frameworks.

  • Identify opportunities to improve compliance processes through workflow enhancements, reporting automation, evidence reuse, standardization, and other process improvements.

  • Support the development of compliance documentation, procedural guidance, stakeholder communications, and training materials as needed.

  • Collaborate with cross-functional teams to promote compliance awareness, accountability, and continuous improvement across the organization.

  • Maintain confidentiality and exercise discretion when handling sensitive compliance, audit, risk, and cybersecurity information.

  • Assume responsibility for other projects and duties as assigned by the Manager, IT Risk & Compliance or Company management.

  • Responsibility directly tied to Watts Value: Integrity, Accountability, Continuous Improvement, and Transparency.

Travel Requirements: Approximately 10% travel for meetings, audits, training, and other business-related activities.

Required Qualifications

  • Bachelor's degree in accounting, Finance, Information Systems, Business Administration, Risk Management, Compliance, Cybersecurity, or a related field; or equivalent combination of education and relevant work experience.

  • Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance.

  • Working knowledge of IT General Controls (ITGCs) and SOX compliance requirements.

  • Experience utilizing GRC, audit management, risk management, ticketing, or evidence management platforms such as Optro (AuditBoard), ServiceNow GRC, Archer, MetricStream, Jira, or similar solutions.

  • Demonstrated ability to coordinate activities across Information Security, IT, Internal Audit, external assessors, and business stakeholders.

  • Strong organizational skills with the ability to manage multiple priorities, deadlines, and workstreams simultaneously.

  • Strong written and verbal communication skills with the ability to present information clearly and professionally.

  • Experience documenting processes, maintaining audit evidence, and supporting compliance activities in a regulated environment.

  • Ability to identify process improvement opportunities and contribute to increased efficiency and standardization.

  • Understanding of and adherence to applicable laws, codes, policies, regulations, and security practices and procedures.

  • Must successfully establish employment eligibility and satisfactorily complete background checks and required pre-employment testing as a condition of employment.

Preferred Qualifications

  • Direct experience administering Optro (AuditBoard), including workflows, evidence requests, testing documentation, issue management, risk tracking, dashboards, and reporting.

  • Familiarity with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, GDPR, U.S. privacy regulations, and SEC cybersecurity disclosure requirements.

  • Experience coordinating external cybersecurity assessments, penetration testing findings, vulnerability remediation efforts, risk reviews, or security exception processes.

  • Professional certification such as CISA, CRISC, CIA, CISSP, or active pursuit of one of these certifications.

  • Experience utilizing automation and reporting tools such as Power Automate, SQL, Python, APIs, or similar technologies.

  • Experience supporting compliance program implementations, procedural documentation development, stakeholder training, or governance initiatives.

General Applicable Company Competencies

  • Commitment to Watts' values of integrity, accountability, continuous improvement and innovation, and transparency.

  • Punctuality and dependability.

  • Ability to be flexible and adapt to changing work priorities and stressful conditions.

  • Adherence to all personnel policies, procedures, and standards of process as implemented by Watts.

  • Maintain productive and collaborative relationships with other Watts employees.

  • Adherence to Watts' seven cultural beliefs: Growth Mindset, Customer-Focused Innovation, Constant Communication, Clear Goals, Collaborate Globally, Be Inclusive, and Take Action.

Working Conditions

While performing the job duties, you will be working remotely in an office environment. You may be required to occasionally travel to and work in the office at the Andover, MA location for meetings, trainings, or as otherwise required by Company management.

Physical Requirements: Specific physical abilities required for this position include, but are not limited to:

  • Ability to remain seated at a desk or workstation for extended periods.

  • Ability to perform repetitive tasks like typing on a keyboard or using a mouse for extended periods.

  • Ability to physically move around the office, organize or transport files, packages, or other office-related materials.

  • Ability to read documents, use a computer, and perform data entry tasks.

  • Ability to communicate clearly with management and coworkers, particularly in meetings or phone calls.

  • Ability to operate standard office equipment such as computers, printers, phones, and copiers.

  • Ability to occasionally lift and carry light objects, such as office supplies, documents, or small equipment.

Pay Range

The expected salary range for this position is $84,000- $94,000 yearly. Actual compensation will be dependent upon individual skills, experience, qualifications, and applicable law.

Nothing in this job description restricts Watts' right to assign or reassign duties, responsibilities, and working hours/conditions to this position at any time. This position is "at will," which means that either the employee or Watts may terminate the employment relationship at any time, with or without notice, and for any lawful reason.

#LIRemote

Watts in it for you:

Please note that the following benefits apply only to permanent roles and do not apply to internship roles.

  • Competitive compensation based on your skills, qualifications and experience
  • Comprehensive medical and dental coverage, retirement benefits
  • Family building benefits, including paid maternity/paternity leave
  • 10 paid holidays and Paid Time Off
  • Continued professional development opportunities and educational reimbursement
  • Additional perks such as fitness reimbursements and employee discount programs
  • Learn more about our benefit offerings here: https://tapintowattsbenefits.com/

How we work:

At Watts, our culture is team-oriented and supportive. Employees here genuinely care about the quality of their work, and about each other. Our people are the heart of who we are and contribute to our longevity and continued success.

And this is a place where you can have a big career. No matter your role, there are opportunities for learning and development, and your daily contributions make a meaningful impact on the lives of people who use our products and on the future of water.

Watts is committed to equal employment opportunity. We follow a policy of administering all employment decisions and personnel actions without regard to race, color, religion, creed, sex, pregnancy, national origin, sexual orientation, age, physical or mental disability, genetic disposition or carrier status, marital status, military or veteran status, minorities, or any other category protected under applicable federal, state, or local law. Consistent with the obligations of state and federal law, Watts will make reasonable accommodations for qualified individuals with disabilities. Any employee who needs a reasonable accommodation should contact Human Resources.