FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Information Technology Risk & Compliance Analyst
ECMC Group. Plan, execute, and report on complex IT compliance activities .
Posted 9/25/2026full-timeMinneapolis • Minnesota • United StatesMid-LevelSenior💰 $90,000 - $100,000 per yearWebsite
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Plan, execute, and report on complex IT compliance activities
- Lead vendor security risk assessments and review security and compliance provisions within vendor contracts with procurement and legal teams
- Engage management to assess processes, identify control weaknesses, and discuss compliance observations and risks
- Secure management ownership of findings and remediation plans and monitor remediation through completion
- Prepare documentation and draft reports communicating results, risks, and recommendations to improve information system controls and practices
- Plan and execute IT compliance reviews
- Support internal and external audits through evidence preparation and auditor coordination
- Contribute to enterprise risk assessments by identifying emerging risks, control gaps, and improvement opportunities
- Provide guidance and informal coaching to staff on low- to medium-complexity compliance activities
- Manage stakeholder expectations and ensure timely, consistent delivery of compliance services
- Communicate complex compliance concepts to peers, leaders, and business partners
- Perform other assigned duties and responsibilities
Requirements
What you’ll need- Bachelor’s degree in computer information systems, information technology, legal studies, or related field, or an additional 2 years of relevant experience in lieu of degree
- 3+ years of experience in IT risk and compliance, IT governance, IT auditing, or an IT-related field
- Understanding of identity and access management, threat and vulnerability management, data loss prevention, change management, data analytics, and software development lifecycle
- Experience assessing vendor risk, performing security assessments, and reviewing contracts
- Experience working with procurement and legal teams
- Experience assessing security controls for AWS or cloud environments
- Experience developing and maintaining policies and/or information management frameworks
- Experience creating and assembling evidence for internal or external auditors
- Advanced knowledge of Microsoft Office suite, including Excel data analysis and SharePoint site design or management
- General knowledge of security control concepts, principles, risk analysis, FISMA, PCI Compliance, HIPAA, Privacy, process improvement, NIST, ISO2700, COSO, and COBIT
- CISA and CIA certifications preferred
Benefits
Comp & perks- Medical, dental, and vision insurance plan options, with a generous employer subsidy
- Company paid life and disability insurance
- Pre-tax flexible spending accounts
- Robust wellness programs
- Generous 401(k) plan with a company match up to 6%
- Additional discretionary contribution potential
- Holiday time off
- Paid time off accrual starting at 20 days/year
- Commuter subsidy
- Tuition reimbursement up to $10,500/year for approved programs
- Student loan payment reimbursement up to $4,800/year
- Up to $5,250 of qualifying education benefits reimbursed pre-tax
- Hybrid work schedule Monday–Wednesday in Minneapolis, MN