FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

IT Risk & Compliance Analyst
Intact Insurance Specialty Solutions. Maintain records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in IT risk management, cybersecurity metrics analysis, and compliance reporting, with a strong ability to coordinate audit activities and develop actionable insights for stakeholders. Proficient in applying NIST-based frameworks and managing application security testing across various platforms.
Highest-signal resume keywords
IT Risk ManagementNIST-Based Cybersecurity FrameworksAudit CoordinationCybersecurity Metrics AnalysisApplication Security Testing
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
IT RiskGRCInformation SecurityIT AuditTechnology ControlsSecurity OperationsVulnerability ManagementIncident ResponseData AnalysisControl Assessments
Soft Skills
Stakeholder CoordinationCommunicationOrganizational SkillsAnalytical ThinkingProblem Solving
Tools & Technologies
ExcelPowerPointSharePointTicketing SystemsReporting Platforms
Certifications & Qualifications
Security+CISACRISCCISMCISSPCGRCITIL Foundation
Industry Keywords
Financial ServicesHealthcareUtilitiesRegulated IndustryCompliance
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Maintain records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status
- Collect and validate information for risk reviews, control assessments, compliance activities, cybersecurity metrics, and management reporting
- Coordinate audit response activities across internal and external auditors and IT, security, infrastructure, compliance, and business stakeholders
- Track audit requests, evidence, findings, remediation actions, retesting, risk acceptances, compensating controls, deadlines, and closure
- Develop clear responses to audit findings and maintain organized, repeatable, auditable evidence
- Collect, organize, and analyze cybersecurity and IT risk metrics
- Develop reports, dashboards, and management-ready summaries using reporting tools
- Analyze trends, gaps, aging items, control exceptions, and remediation progress for leadership, risk committees, auditors, and non-technical audiences
- Define and maintain metric definitions, data owners, source systems, refresh schedules, assumptions, and limitations
- Create and maintain trackers, checklists, evidence logs, reporting calendars, process maps, and follow-up routines
- Coordinate application security and penetration testing, including scoping, scheduling, execution support, findings tracking, remediation validation, and retesting through closure
- Maintain application inventories, promote secure software development practices, prepare management reporting, and align testing with organizational and regulatory requirements
- Apply recognized cybersecurity and control frameworks, including NIST-based terminology
- Clarify ownership, next steps, and response dates; follow up with stakeholders
- Escalate material risks, delays, unresolved ownership, and data quality concerns
Requirements
What you’ll need- Management, Audit, Accounting, or a related field, or equivalent relevant experience
- Three (3) to five (5) years of experience in IT risk, GRC, information security, IT audit, technology controls, security operations, or a related function
- Experience in insurance, financial services, healthcare, utilities, or another regulated or compliance-intensive industry is preferred
- Relevant professional certifications such as Security+, CISA, CRISC, CISM, CISSP, CGRC, or ITIL Foundation are preferred but not required
- Experience with NIST-based cybersecurity and control frameworks
- Experience with Excel, PowerPoint, SharePoint, ticketing systems, and reporting platforms
- Knowledge of vulnerability management, identity and access management, endpoint protection, incident response, infrastructure operations, logging, and monitoring
- Experience coordinating application security and penetration testing across internally developed, SaaS, web, mobile, API, cloud, and vendor-hosted applications
- Ability to collect, validate, organize, analyze, and report cybersecurity risk and control information
- Ability to coordinate with internal and external auditors and multiple technical and business stakeholders
Benefits
Comp & perks- Bonus potential
- Comprehensive medical, dental and vision insurance with no waiting period
- Competitive paid time off programs
- 401(k) savings and annual contributions of up to 12% of annual salary
- Mental health support programs
- Life and disability insurance
- Paid parental leave
- Additional voluntary benefits
- Flexible Work Arrangement options
- Performance-led financial rewards
- Opportunities for professional growth, learning, and development