1

It Risk And Compliance Jobs (NOW HIRING)

The IT Risk and Compliance Analyst position is a highly visible, client facing role which works closely with the Legal and Business Unit stakeholders and reports to the IT Risk and Compliance Manager.

IT Risk and Compliance Analyst

Boston, MA · On-site

$90K - $115K/yr

The IT Risk and Compliance Analyst position is a highly visible, client facing role which works closely with the Legal and Business Unit stakeholders and reports to the IT Risk and Compliance Manager.

IT Risk and Compliance Analyst

New York, NY · On-site

$90K - $115K/yr

The IT Risk and Compliance Analyst position is a highly visible, client facing role which works closely with the Legal and Business Unit stakeholders and reports to the IT Risk and Compliance Manager.

IT Risk and Compliance Analyst

Chicago, IL · On-site

$90K - $115K/yr

The IT Risk and Compliance Analyst position is a highly visible, client facing role which works closely with the Legal and Business Unit stakeholders and reports to the IT Risk and Compliance Manager.

Job Summary The IT Risk Associate will support the organization's technology risk management and cybersecurity compliance programs. Reporting to the Senior Director of IT and Cybersecurity Risk, this ...

Further, the IT Risk Analyst will participate in the design and evaluation of proposed remediation plans for noted issues to support compliance with prescribed requirements. The IT Risk Analyst will ...

Further, the IT Risk Analyst will participate in the design and evaluation of proposed remediation plans for noted issues to support compliance with prescribed requirements. The IT Risk Analyst will ...

Further, the IT Risk Analyst will participate in the design and evaluation of proposed remediation plans for noted issues to support compliance with prescribed requirements. The IT Risk Analyst will ...

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and ... Bachelor's degree in Computer Science, Information Technology, Engineering, Business, or a related ...

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and ... Bachelor's degree in Computer Science, Information Technology, Engineering, Business, or a related ...

next page

Showing results 1-20

It Risk And Compliance information

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance professional, and why are they important?

To thrive as an IT Risk and Compliance professional, you need a solid understanding of IT governance, risk management frameworks, regulatory requirements, and a relevant degree such as in information technology, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISA, CRISC, or CISSP, is typically required. Strong analytical thinking, attention to detail, and effective communication help professionals excel in navigating complex regulations and collaborating with cross-functional teams. These skills and qualifications are crucial for ensuring organizational compliance, mitigating security risks, and maintaining trust with stakeholders.

What is IT Risk and Compliance?

IT Risk and Compliance refers to the process of identifying, assessing, and managing risks associated with an organization's information technology systems, while ensuring that these systems adhere to relevant laws, regulations, and internal policies. Professionals in this field work to protect sensitive data, prevent security breaches, and ensure that the organization's IT practices are compliant with industry standards such as GDPR, HIPAA, or SOX. They often conduct risk assessments, implement controls, monitor compliance, and respond to audits. The goal is to minimize potential threats to IT infrastructure and maintain the trust of customers and stakeholders.

How does an IT Risk and Compliance professional typically collaborate with other departments to ensure regulatory adherence?

IT Risk and Compliance professionals regularly work with teams across the organization—such as IT, legal, audit, and business operations—to identify risks, interpret regulations, and implement compliance controls. They facilitate training, conduct assessments, and coordinate responses to audits or incidents, ensuring that everyone understands their responsibilities. Effective communication and strong relationship-building skills are essential, as much of the role involves translating technical requirements into actionable steps for non-technical staff. This cross-functional collaboration helps maintain a culture of compliance and minimizes organizational risk.

What is risk and compliance in it?

In IT risk and compliance, professionals identify, assess, and manage potential security threats and ensure that an organization adheres to relevant laws, regulations, and policies. This involves implementing controls, conducting audits, and maintaining documentation to protect information assets and support regulatory requirements.

What is the difference between It Risk And Compliance vs Cybersecurity Analyst?

AspectIt Risk And ComplianceCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, risk assessments, compliance auditsMonitoring security threats, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on protecting information, It Risk And Compliance emphasizes establishing policies, ensuring regulatory adherence, and managing overall risk frameworks. Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Understanding these differences helps organizations assign the right responsibilities and professionals for their security needs.

How much does risk and compliance make?

Risk and compliance professionals typically earn a median annual salary ranging from $70,000 to $120,000, depending on experience, industry, and location. Certifications such as Certified Risk and Compliance Management Professional (CRCMP) can enhance earning potential, and roles often require knowledge of regulations, risk assessment tools, and compliance frameworks.

How much does a risk and compliance officer make?

A risk and compliance officer's salary varies by experience, industry, and location, but typically ranges from $70,000 to $130,000 annually. Senior roles or those with certifications like CRC or CCEP can earn higher salaries, especially in regulated industries such as finance or healthcare.

Will compliance be replaced by AI?

IT Risk and Compliance professionals use AI to automate monitoring, detect threats, and ensure regulatory adherence. While AI can handle routine tasks, human oversight remains essential for interpreting complex regulations and making strategic decisions. AI enhances compliance processes but does not fully replace the need for skilled compliance experts.
More about It Risk And Compliance jobs
What cities are hiring for It Risk And Compliance jobs? Cities with the most It Risk And Compliance job openings:
What states have the most It Risk And Compliance jobs? States with the most job openings for It Risk And Compliance jobs include:
What job categories do people searching It Risk And Compliance jobs look for? The top searched job categories for It Risk And Compliance jobs are:
Infographic showing various It Risk And Compliance job openings in the United States as of June 2026, with employment types broken down into 1% Locum Tenens, 1% As Needed, 41% Full Time, 52% Part Time, 4% Contract, and 1% Nights. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution.

IT Risk and Compliance Analyst

Thinkbrg

Washington, DC

$90K - $115K/yr

Full-time

Posted 21 days ago


Job description

We do Consulting Differently

Job Summary:

The IT Risk and Compliance Analyst position is a highly visible, client facing role which works closely with the Legal and Business Unit stakeholders and reports to the IT Risk and Compliance Manager. This role is responsible for providing assistance in evaluating, assessing, and monitoring the firm's risk and compliance with applicable information security standards and frameworks, industry best practices, and applicable laws and regulations. This role will also help coordinate and maintain the firm's Information Security Management Program and assist in implementing security policy objectives in ways that align with business and mission objectives.

Reporting Relationships:

  • IT Risk and Compliance Manager

Key Contacts:

  • Works closely with the Legal and Business Unit stakeholders.
  • This role will work with the clients in response to security assessments and due diligence questionnaires covering a broad range of business disciplines and industries (i.e., Healthcare, Financial Services, Construction, Government Contracts, Insurance, Real Estate, et al).
  • This role will work in conjunction with the IT Security and Infrastructure Team.

Major Responsibilities/ Job Functions:

  • Provide IT security, risk, and compliance advice to business units on an ongoing basis.
  • Analyze and address gaps in operations to ensure integrity of processes, controls, and policies.
  • Assist in maintaining and updating Information Security Program policies and procedures as needed, also completing a yearly review to ensure all documentation is properly updated.
  • Provide governance for participation in the information security incident response process by ensuring that the process is being followed and documented.
  • Respond to escalated security events and drive the security incident response process.
  • Participate in the evaluation, development and implementation of security standards, procedures and guidelines for multiple platforms and diverse systems environments.
  • Works with internal and external auditors to demonstrate and provide evidence for controls that are in place. May conduct additional testing to validate that items found during testing have been remediated.
  • Responsible for completion of client security questionnaires and working with the business units to assist with RFI responses related to IT security.
  • Assists in vendor vetting to ensure our vendors, business partners, or suppliers are using the same or higher security practices.
  • Assists in conducting Risk Assessments and annual reviews for any new or current vendors, business partners, or suppliers.
  • Assists with complex security assessments that require both analytical and technical skills across a broad range of Information Technology topics (e.g., Identity and Access Management,

Security Architecture, Physical and Environmental, etc.).

  • Assists with evaluating, testing, documenting, and maintaining the firmwide DR and BCP policies, processes, and standards.
  • Assists with the Security Awareness Training program initiatives related to phishing campaigns and coordinate with HR to deliver ongoing employee training.

Requirements:

  • Associate Degree or equivalent work experience
  • 3 years of experience in two or more major information technology functions (infrastructure, operations, datacenter, application support, etc.)
  • 3 years IT security, IT compliance, or IT risk management experience desired.
  • 3 years of experience involving ISO27001 annual surveillance audits and full recertification audits.
  • Familiarity with industry frameworks and standards such as SOC2, HIPAA, HITRUST is a plus.
  • Familiarity with GDPR and CCPA.
  • Familiarity using GRC tools.
  • Knowledge of application and network security, information security risk and industry best practice (how to best manage risk).
  • Experience with building, executing, and maintaining DR and BCP program.
  • Ability to effectively prioritize and execute tasks in a high-pressure environment.
  • Excellent written/verbal communication skills and time management skills.
  • Strong troubleshooting, problem-solving and analytical skills.
  • Position may require traveling for short periods. Trips will sometimes extend to 5 working days and could on rare occasions extend beyond 5 business days. All travel expenses will be reimbursed.

Salary Range: $90,000-$115,000

Candidate must be able to submit verification of his/her legal right to work in the U.S., without company sponsorship.

#LI-SJ1

About BRG

BRG combines world-leading academic credentials with world-tested business expertise and purpose-built emerging technologies. Our culture centers on agility and connectivity which sets us apart and gets you ahead.

At BRG, our professionals include specialist consultants, industry experts, renowned academics, and leading-edge data scientists. Together, they bring a diversity of real-world experience, data, and human and artificial intelligence, to economics, disputes, and investigations; corporate finance; and performance improvement services that address the most complex challenges facing organizations across the globe.

Our unique structure nurtures the interdisciplinary relationships that give us the edge, laying the groundwork for more informed insights and more original, incisive thinking. When paired with our global reach and resources, our diverse perspectives and technical capabilities make us uniquely capable to address our clients' challenges. We get results because we know how to apply our thinking to your world.

At BRG, we don't just show you what's possible. We're built to help you make it happen.


BRG is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran status, ancestry, sexual orientation, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law.