1

It Risk And Compliance Analyst Jobs (NOW HIRING)

Senior IT Risk Analyst

Plymouth, MA · Hybrid

  • Medical

  • Dental

  • Life

  • Retirement

  • PTO

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst ... Experience navigating highly regulated or matrixed environments, interacting with audit, compliance ...

Senior IT Risk Analyst

Plymouth, MA · Hybrid

  • Medical

  • Dental

  • Life

  • Retirement

  • PTO

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst ... Experience navigating highly regulated or matrixed environments, interacting with audit, compliance ...

IT Compliance Analyst

Saint Paul, MN · On-site

$94K - $95K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Title: IT Compliance Analyst (IT Digital Systems & Compliance Analyst) Location: St. Paul, MN Duration: 12 Months 100 % onsite Summary: The IT Digital Analyst supports the company's digital platforms ...

New

Senior Compliance Analyst

Buckhead, GA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

What We Need Corpay is currently looking to hire a Senior Compliance Analyst within our Corporate ... Facilitating IT process risk assessments. * Preparing clear and detailed documentation, including ...

Senior Compliance Analyst

Atlanta, GA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

What We Need Corpay is currently looking to hire a Senior Compliance Analyst within our Corporate ... Facilitating IT process risk assessments. * Preparing clear and detailed documentation, including ...

... internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate compliance efforts and ... Advanced analytical skills with experience using tools like Alteryx, Tableau, Power BI, or Python ...

Senior IT Risk Analyst

Rosemont, IL · On-site

$98K - $110K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Position Overview The Senior IT Risk Analyst (Audit concentration) role supports IT Risk Leadership in maintaining a strong, healthy audit culture across IT globally. This role applies industry best ...

Merchant Risk & Compliance Analyst

Maitland, FL · On-site

$65K - $85K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Medical, Dental and Vision Benefits * 100% Company Paid Life, AD&D Insurance, Short and Long Term Disability General Responsibilities The Merchant Risk & Compliance Analyst position will support our ...

Merchant Risk & Compliance Analyst

Maitland, FL · On-site +1

$65K - $85K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Medical, Dental and Vision Benefits * 100% Company Paid Life, AD&D Insurance, Short and Long Term Disability General Responsibilities The Merchant Risk & Compliance Analyst position will support our ...

The Compliance Assessor of IT Risk & Compliance Management performs Security Risk Assessments on DIRECTV's 3rd party vendors. An assesment would typically involve the following tasks: Communicating ...

Showing results 41-60

It Risk And Compliance Analyst information

See salary details

$15

$40

$65

How much do it risk and compliance analyst jobs pay per hour?

As of Aug 13, 2026, the average hourly pay for it risk and compliance analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What is the difference between It Risk And Compliance Analyst vs It Security Analyst?

AspectIt Risk And Compliance AnalystIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentRisk assessments, policy development, compliance auditsNetwork monitoring, incident response, security infrastructure
Industry UsageFinancial, healthcare, government sectorsTech, finance, healthcare sectors

The It Risk And Compliance Analyst focuses on ensuring organizational adherence to regulations and managing risk frameworks, while the It Security Analyst primarily handles security measures, threat detection, and incident response. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ: one emphasizes compliance and risk management, the other emphasizes security operations.

What is an IT Risk and Compliance Analyst?

IT Risk and Compliance Analysts are professionals who identify, assess, and manage risks related to information technology systems within an organization. They ensure that IT processes and systems comply with internal policies and external regulations, such as GDPR or SOX. Their responsibilities include conducting risk assessments, developing mitigation strategies, monitoring compliance, and reporting on the effectiveness of controls. By doing so, they help protect the organization from cyber threats, data breaches, and regulatory penalties.

What are some common challenges an IT Risk and Compliance Analyst faces when balancing regulatory requirements with business objectives?

One common challenge IT Risk and Compliance Analysts face is ensuring that regulatory requirements are fully met without hindering business operations or innovation. Balancing security protocols and compliance standards—such as GDPR, SOX, or HIPAA—with the need for efficient workflows can be complex. Analysts must collaborate closely with IT, legal, and business units to interpret regulations pragmatically, design effective controls, and communicate the importance of compliance while minimizing disruption. This often requires strong negotiation, communication, and analytical skills to find solutions that satisfy both compliance mandates and business goals.

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance Analyst?

To thrive as an IT Risk and Compliance Analyst, you need a solid understanding of risk management frameworks, regulatory compliance standards (such as SOX, HIPAA, or GDPR), and a bachelor's degree in information technology or a related field. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and relevant certifications like CRISC or CISA is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts interpret regulations and collaborate across departments. These skills ensure organizations proactively manage risks, maintain regulatory compliance, and protect sensitive information.
More about It Risk And Compliance Analyst jobs
What cities are hiring for It Risk And Compliance Analyst jobs? Cities with the most It Risk And Compliance Analyst job openings:
Who are the top companies hiring for It Risk And Compliance Analyst jobs? The top employers for It Risk And Compliance Analyst jobs are:
What states have the most It Risk And Compliance Analyst jobs? States with the most job openings for It Risk And Compliance Analyst jobs include:
Infographic showing various It Risk And Compliance Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $84,210 per year, or $40.5 per hour.

Senior Security Risk & Compliance Analyst

APCO Holdings

Ponte Vedra, FL • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 22 days ago


APCO Holdings rating

8.0

Company rating: 8.0 out of 10

Based on 10 frontline employees who took The Breakroom Quiz

163rd of 306 rated insurance


Job description

APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers.
Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.
We are looking for a Senior Security Risk & Compliance Analyst to support and strengthen APCO's security governance, risk, and compliance (GRC) initiatives. In this role, you will help drive compliance efforts, assess security controls, identify risks, and support the organization's ongoing commitment to maintaining a strong security posture and regulatory compliance.
What You'll Do
Audit & Compliance
  • Support the planning, coordination, and execution of compliance audits, including readiness assessments and external audit engagements
  • Partner with control owners to document, implement, and maintain compliance controls aligned control requirements.
  • Collect, review, and validate audit evidence to ensure completeness and accuracy
  • Track audit findings, exceptions, and remediation efforts through closure
  • Act as a liaison between internal stakeholders and external auditors

Internal Audit
  • Perform internal audits and control assessments to evaluate the effectiveness of security and compliance controls
  • Develop audit plans, testing procedures, and audit reports
  • Identify control gaps and recommend remediation actions
  • Monitor and track remediation efforts to ensure timely resolution

GRC Platform Management
  • Administer and maintain the organization's GRC platform
  • Configure audit workflows and maintain accurate, up-to-date due diligence responses within the GRC platform.
  • Ensure data integrity and accuracy within the system
  • Generate dashboards and reports for compliance status, audit tracking, and risk posture

Risk Registration & Management
  • Maintain the enterprise risk register, including identification, classification, and documentation of risks
  • Facilitate risk assessments with business and IT stakeholders
  • Evaluate risk severity based on likelihood and impact
  • Track risk treatment plans (remediation, acceptance, transfer, avoidance)
  • Provide regular reporting on risk posture to leadership

Governance & Cross-Functional Collaboration
  • Collaborate with IT, Security, Legal, and business units to ensure alignment with compliance requirements
  • Assist in the development and maintenance of security policies, standards, and procedures
  • Support other compliance initiatives as needed (e.g., regulatory, customer security questionnaires)

Qualifications
  • Bachelor's degree in Information Security, Information Systems, or related field (or equivalent experience)
  • At least 5 years of experience in security compliance, audit, or GRC
  • Hands-on experience with SOC 2 audits and Trust Services Criteria and New York 23 NYCRR 500, or other regulatory compliance.
  • Experience with performing internal audits and control testing
  • Familiarity with GRC tools (e.g., ServiceNow GRC, Archer GRC)
  • Strong understanding of risk management principles and frameworks
  • Knowledge of common frameworks (e.g., AICPA SOC 2, ISO 27001, NIST)
  • Experience with leading cybersecurity due diligence activities, including responding to customer and partner security questionnaires accurately and in a timely manner
  • Strong analytical, organizational, and communication skills

Preferred Certifications
  • Certified Information Systems Auditor (CISA) or
  • Certified in Risk and Information Systems Control (CRISC) or
  • Certified Information Systems Security Professional (CISSP)

This Role Might Be a Great Fit If You...
  • Enjoy identifying risks and improving security processes
  • Thrive in cross-functional, collaborative environments
  • Like balancing technical security concepts with governance and compliance
  • Are motivated by protecting systems, data, and organizational integrity

What We Offer
  • Competitive compensation
  • Comprehensive medical, dental, and vision benefits
  • 401(k) with company match
  • Paid time off and company holidays
  • Opportunities for professional growth and certification support
  • A collaborative and security-focused work environment

At APCO, the way we work matters just as much as the results we deliver. Our values guide how we work, how we partner, and how we deliver results.
We C.A.R.E.
Committed - We build strong, high-trust relationships with our partners and each other.
Accountable - We take ownership of outcomes and hold ourselves to the highest standards of performance and integrity.
Results-Driven - We focus on delivering measurable outcomes that create value for our partners and our business.
Excellent - We strive for excellence in everything we do while balancing short-term performance with long-term success.
If you're excited about joining a team that values collaboration, accountability, and continuous improvement, we'd love to hear from you.
By submitting your application, you acknowledge that you have read and understand our Privacy Policy and Terms & Conditions. APCO Holdings may collect personal information (such as name, contact details, and employment history) to evaluate your candidacy. We may share this data with our subsidiaries, affiliates, and service providers. We retain applicant data only as long as necessary for the hiring process or as required by law.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

What APCO Holdings employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom