We are looking for an experienced IT Risk and Compliance Specialist to help strengthen and scale a growing governance, risk, and compliance program in Milwaukee, Wisconsin. This contract opportunity with potential for a permanent role is ideal for someone who can turn regulatory and security expectations into practical, sustainable processes across technical and business teams. The person in this role will guide audit and certification readiness, improve control maturity, and partner with stakeholders to build a stronger culture of accountability and security.
Responsibilities:
โข Direct cross-functional risk and compliance efforts across IT and business teams to advance enterprise governance objectives.
โข Act as the central point of contact for auditors, internal stakeholders, compliance partners, and technology leaders during assessments and review cycles.
โข Prepare the organization for ISO 27001 certification activities and support ongoing alignment with established compliance obligations.
โข Evaluate control environments through risk assessments and recommend improvements that strengthen security oversight and operational resilience.
โข Manage third-party risk reviews by assessing vendor security practices and identifying areas that require mitigation or follow-up.
โข Oversee segregation of duties governance and monitor the effectiveness of related controls across relevant systems and processes.
โข Work with stakeholders to identify audit findings, define corrective action plans, and monitor remediation progress through resolution.
โข Develop and maintain policies, standards, procedures, and supporting documentation that reinforce security and compliance expectations.
โข Coordinate disaster recovery and business continuity planning efforts, including testing activities and program enhancement initiatives.
โข Contribute to data protection, security awareness, and emerging governance initiatives related to areas such as AI risk and control management.โข At least 5 years of experience leading or supporting IT governance, risk, and compliance programs in complex enterprise environments.
โข Strong knowledge of security and compliance frameworks such as ISO 27001, NIST, SOX, IT general controls, or comparable standards.
โข Demonstrated success managing audits, validating controls, coordinating stakeholders, and driving remediation activities.
โข Experience performing risk assessments and converting regulatory or framework requirements into workable business and technical controls.
โข Ability to create clear security policies, standards, procedures, and governance documentation.
โข Strong communication and organizational skills with the ability to influence both technical and non-technical audiences.
โข Familiarity with business continuity, disaster recovery, and vendor risk management practices.
โข Preferred qualifications include certifications such as CISSP or ISO 27001 Lead Auditor, along with exposure to cloud environments across SaaS, PaaS, and IaaS.