Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
ECMC Group

Information Technology Risk & Compliance Analyst

ECMC Group

. Plan, execute, and report on complex IT compliance activities .

Posted 9/25/2026full-timeMinneapolis • Minnesota • United StatesMid-LevelSenior💰 $90,000 - $100,000 per yearWebsite

Tech Stack

Tools & technologies
AWSCloud

About the role

Key responsibilities & impact
  • Plan, execute, and report on complex IT compliance activities
  • Lead vendor security risk assessments and review security and compliance provisions within vendor contracts with procurement and legal teams
  • Engage management to assess processes, identify control weaknesses, and discuss compliance observations and risks
  • Secure management ownership of findings and remediation plans and monitor remediation through completion
  • Prepare documentation and draft reports communicating results, risks, and recommendations to improve information system controls and practices
  • Plan and execute IT compliance reviews
  • Support internal and external audits through evidence preparation and auditor coordination
  • Contribute to enterprise risk assessments by identifying emerging risks, control gaps, and improvement opportunities
  • Provide guidance and informal coaching to staff on low- to medium-complexity compliance activities
  • Manage stakeholder expectations and ensure timely, consistent delivery of compliance services
  • Communicate complex compliance concepts to peers, leaders, and business partners
  • Perform other assigned duties and responsibilities

Requirements

What you’ll need
  • Bachelor’s degree in computer information systems, information technology, legal studies, or related field, or an additional 2 years of relevant experience in lieu of degree
  • 3+ years of experience in IT risk and compliance, IT governance, IT auditing, or an IT-related field
  • Understanding of identity and access management, threat and vulnerability management, data loss prevention, change management, data analytics, and software development lifecycle
  • Experience assessing vendor risk, performing security assessments, and reviewing contracts
  • Experience working with procurement and legal teams
  • Experience assessing security controls for AWS or cloud environments
  • Experience developing and maintaining policies and/or information management frameworks
  • Experience creating and assembling evidence for internal or external auditors
  • Advanced knowledge of Microsoft Office suite, including Excel data analysis and SharePoint site design or management
  • General knowledge of security control concepts, principles, risk analysis, FISMA, PCI Compliance, HIPAA, Privacy, process improvement, NIST, ISO2700, COSO, and COBIT
  • CISA and CIA certifications preferred

Benefits

Comp & perks
  • Medical, dental, and vision insurance plan options, with a generous employer subsidy
  • Company paid life and disability insurance
  • Pre-tax flexible spending accounts
  • Robust wellness programs
  • Generous 401(k) plan with a company match up to 6%
  • Additional discretionary contribution potential
  • Holiday time off
  • Paid time off accrual starting at 20 days/year
  • Commuter subsidy
  • Tuition reimbursement up to $10,500/year for approved programs
  • Student loan payment reimbursement up to $4,800/year
  • Up to $5,250 of qualifying education benefits reimbursed pre-tax
  • Hybrid work schedule Monday–Wednesday in Minneapolis, MN