1

It Risk And Compliance Jobs (NOW HIRING)

IT Controls & Compliance Analyst

Denver, CO

$96.80K - $97.30K/yr

Manages and optimizes Governance, Risk & Compliance (GRC) processes, workflows, tooling, reporting ... Reviews and maintains IT security policies, standards, and governance documentation to align with ...

next page

Showing results 1-20

It Risk And Compliance information

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance professional, and why are they important?

To thrive as an IT Risk and Compliance professional, you need a solid understanding of IT governance, risk management frameworks, regulatory requirements, and a relevant degree such as in information technology, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISA, CRISC, or CISSP, is typically required. Strong analytical thinking, attention to detail, and effective communication help professionals excel in navigating complex regulations and collaborating with cross-functional teams. These skills and qualifications are crucial for ensuring organizational compliance, mitigating security risks, and maintaining trust with stakeholders.

How does an IT Risk and Compliance professional typically collaborate with other departments to ensure regulatory adherence?

IT Risk and Compliance professionals regularly work with teams across the organization—such as IT, legal, audit, and business operations—to identify risks, interpret regulations, and implement compliance controls. They facilitate training, conduct assessments, and coordinate responses to audits or incidents, ensuring that everyone understands their responsibilities. Effective communication and strong relationship-building skills are essential, as much of the role involves translating technical requirements into actionable steps for non-technical staff. This cross-functional collaboration helps maintain a culture of compliance and minimizes organizational risk.

What is IT Risk and Compliance?

IT Risk and Compliance refers to the process of identifying, assessing, and managing risks associated with an organization's information technology systems, while ensuring that these systems adhere to relevant laws, regulations, and internal policies. Professionals in this field work to protect sensitive data, prevent security breaches, and ensure that the organization's IT practices are compliant with industry standards such as GDPR, HIPAA, or SOX. They often conduct risk assessments, implement controls, monitor compliance, and respond to audits. The goal is to minimize potential threats to IT infrastructure and maintain the trust of customers and stakeholders.

What is the difference between It Risk And Compliance vs Cybersecurity Analyst?

AspectIt Risk And ComplianceCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, risk assessments, compliance auditsMonitoring security threats, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on protecting information, It Risk And Compliance emphasizes establishing policies, ensuring regulatory adherence, and managing overall risk frameworks. Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Understanding these differences helps organizations assign the right responsibilities and professionals for their security needs.

More about It Risk And Compliance jobs
What cities are hiring for It Risk And Compliance jobs? Cities with the most It Risk And Compliance job openings:
What states have the most It Risk And Compliance jobs? States with the most job openings for It Risk And Compliance jobs include:
What job categories do people searching It Risk And Compliance jobs look for? The top searched job categories for It Risk And Compliance jobs are:
AVP, IT & AI Governance

$171.80K - $215K/yr

Full-time

Posted 25 days ago


Job description

Overview
ABOUT US

Founded in 1993, Bayview Asset Management is an investment management firm focused on investments in mortgage and consumer credit, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets.

POSITION SUMMARY

Bayview Asset Management is seeking a highly experienced Assistant Vice President (AVP), IT & AI Governance to lead the firm’s enterprise technology governance function. This role is responsible for establishing and overseeing a robust IT and Artificial Intelligence (AI) governance framework that ensures alignment with business strategy, regulatory requirements, risk management standards, and operational excellence.

The AVP will oversee IT governance, AI governance, model risk alignment, technology risk management, and regulatory compliance across the organization. This role serves as a key control function, partnering with IT, Risk, Compliance, Legal, Information Security, and business leadership to ensure safe, responsible, and compliant use of technology — including emerging AI and Generative AI capabilities.

RESPONSIBILITIES:

IT & AI Governance Leadership

  • Lead enterprise IT and AI governance frameworks aligned with NIST, SCF, NYDFS, and regulatory best practices
  • Embed AI governance into IT, data, and enterprise risk programs
  • Ensure governance is scalable, repeatable, and audit-ready

AI Risk & Model Governance

  • Partner with Model Risk Management to align with SR 117 and OCC/Fed guidance
  • Set standards for AI/model documentation and lifecycle oversight
  • Govern internal, thirdparty, and Generative AI solutions
  • Maintain AI risk taxonomy, reporting, and escalation

IT & AI Risk Management

 

  • Identify, assess, and monitor IT and AI risks
  • Own mitigation strategies, control frameworks, and centralized risk register
  • Lead risk assessments, governance reviews, and control testing

Regulatory, Audit & Compliance

  • Ensure compliance with IT and AI regulatory requirements
  • Establish AI compliance monitoring
  • Serve as primary liaison for audits and regulatory exams
  • Maintain documentation, evidence retention, and audit trails

Policy & Control Frameworks

  • Develop and maintain IT and AI policies, standards, and procedures
  • Lead periodic reviews and operational adoption

Strategy & Emerging Technology

  • Align governance with IT and digital transformation strategy
  • Provide governance review for new technology initiatives
  • Assess emerging AI technologies prior to adoption

ThirdParty & Vendor AI Governance

  • Define AI governance standards for vendors
  • Partner with Vendor Risk to assess controls, transparency, validation, and data protections
  • Ensure AIspecific contractual safeguards

Metrics & Reporting

  • Define KPIs and KRIs for IT and AI governance
  • Report risk posture, compliance status, and remediation to leadership
  • Drive continuous improvement

Stakeholder Engagement & Culture

  • Advise leaders on responsible AI adoption
  • Promote ethical technology use and risk awareness
  • Lead governance training and crossfunctional forums

Leadership

  • Lead and develop the IT Governance team
  • Build enterprise AI governance capabilities
  • Establish clear accountability across IT, Risk, Compliance, and business teams
SKILLS & REQUIRMENTS:
  • Strong knowledge of IT governance frameworks and standards (COBIT, ITIL, NIST, ISO 27001)
  • Proficiency with IT governance, risk, and compliance tools
  • Solid understanding of IT infrastructure, applications, and cybersecurity principles
  • Excellent written and verbal communication skills; able to convey complex concepts to nontechnical audiences
  • Strong analytical and critical thinking skills with sound judgment in complex situations
  • Proven leadership and people management capabilities
  • Experience leading projects and initiatives from inception through execution
  • Ability to manage multiple priorities in a fastpaced environment
  • Demonstrated ability to develop and implement IT policies, procedures, and controls
  • Strong interpersonal skills with the ability to influence stakeholders at all levels
QUALIFICATIONS:
  • Bachelor’s degree in Information Technology, Computer Science, Business Administration, or a related field. Master’s degree preferred
  • A minimum of 8-10 years of experience in IT governance, risk management, or a related field, with at least 3 years in a leadership role
  • Experience with regulatory compliance and risk management in the IT domain
Certifications, Licenses, and/or Registration 
  • Certifications such as CISA, CISM, CRISC, or CGEIT are highly desirable.
EEOC

Bayview is an Equal Employment Opportunity employer.  All aspects of consideration for employment and employment with the Company are governed on the basis of merit, competence and qualifications without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, or any other category protected by federal, state, or local law.

Qualifications:UNAVAILABLEEducation:UNAVAILABLEEmployment Type: FULL_TIME