Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Intact Insurance Specialty Solutions

IT Risk & Compliance Analyst

Intact Insurance Specialty Solutions

. Maintain records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status .

Posted 10/8/2026full-timeUnited StatesMid-LevelSenior💰 $75,000 - $107,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in IT risk management, cybersecurity metrics analysis, and compliance reporting, with a strong ability to coordinate audit activities and develop actionable insights for stakeholders. Proficient in applying NIST-based frameworks and managing application security testing across various platforms.

Highest-signal resume keywords
IT Risk ManagementNIST-Based Cybersecurity FrameworksAudit CoordinationCybersecurity Metrics AnalysisApplication Security Testing

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
IT RiskGRCInformation SecurityIT AuditTechnology ControlsSecurity OperationsVulnerability ManagementIncident ResponseData AnalysisControl Assessments
Soft Skills
Stakeholder CoordinationCommunicationOrganizational SkillsAnalytical ThinkingProblem Solving
Tools & Technologies
ExcelPowerPointSharePointTicketing SystemsReporting Platforms
Certifications & Qualifications
Security+CISACRISCCISMCISSPCGRCITIL Foundation
Industry Keywords
Financial ServicesHealthcareUtilitiesRegulated IndustryCompliance

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Maintain records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status
  • Collect and validate information for risk reviews, control assessments, compliance activities, cybersecurity metrics, and management reporting
  • Coordinate audit response activities across internal and external auditors and IT, security, infrastructure, compliance, and business stakeholders
  • Track audit requests, evidence, findings, remediation actions, retesting, risk acceptances, compensating controls, deadlines, and closure
  • Develop clear responses to audit findings and maintain organized, repeatable, auditable evidence
  • Collect, organize, and analyze cybersecurity and IT risk metrics
  • Develop reports, dashboards, and management-ready summaries using reporting tools
  • Analyze trends, gaps, aging items, control exceptions, and remediation progress for leadership, risk committees, auditors, and non-technical audiences
  • Define and maintain metric definitions, data owners, source systems, refresh schedules, assumptions, and limitations
  • Create and maintain trackers, checklists, evidence logs, reporting calendars, process maps, and follow-up routines
  • Coordinate application security and penetration testing, including scoping, scheduling, execution support, findings tracking, remediation validation, and retesting through closure
  • Maintain application inventories, promote secure software development practices, prepare management reporting, and align testing with organizational and regulatory requirements
  • Apply recognized cybersecurity and control frameworks, including NIST-based terminology
  • Clarify ownership, next steps, and response dates; follow up with stakeholders
  • Escalate material risks, delays, unresolved ownership, and data quality concerns

Requirements

What you’ll need
  • Management, Audit, Accounting, or a related field, or equivalent relevant experience
  • Three (3) to five (5) years of experience in IT risk, GRC, information security, IT audit, technology controls, security operations, or a related function
  • Experience in insurance, financial services, healthcare, utilities, or another regulated or compliance-intensive industry is preferred
  • Relevant professional certifications such as Security+, CISA, CRISC, CISM, CISSP, CGRC, or ITIL Foundation are preferred but not required
  • Experience with NIST-based cybersecurity and control frameworks
  • Experience with Excel, PowerPoint, SharePoint, ticketing systems, and reporting platforms
  • Knowledge of vulnerability management, identity and access management, endpoint protection, incident response, infrastructure operations, logging, and monitoring
  • Experience coordinating application security and penetration testing across internally developed, SaaS, web, mobile, API, cloud, and vendor-hosted applications
  • Ability to collect, validate, organize, analyze, and report cybersecurity risk and control information
  • Ability to coordinate with internal and external auditors and multiple technical and business stakeholders

Benefits

Comp & perks
  • Bonus potential
  • Comprehensive medical, dental and vision insurance with no waiting period
  • Competitive paid time off programs
  • 401(k) savings and annual contributions of up to 12% of annual salary
  • Mental health support programs
  • Life and disability insurance
  • Paid parental leave
  • Additional voluntary benefits
  • Flexible Work Arrangement options
  • Performance-led financial rewards
  • Opportunities for professional growth, learning, and development