The Risk & Compliance Analyst supports the organization's information security, risk, and compliance programs by monitoring, evaluating, and maintaining IT security frameworks, policies, standards, controls, and best practices. This role performs compliance and audit activities, evaluates technical evidence from cloud and hosting environments, and works with stakeholders to identify and remediate control gaps.
The Risk & Compliance Analyst independently manages assigned projects and compliance activities from initiation through completion and contributes to continuous improvement through the use of automation, scripting, data analysis, and AI-enabled technologies. The role requires strong technical curiosity, ownership, analytical thinking, and the ability to rapidly learn new technologies, processes, tools, and applications.
What you'll be doing
- Execute and monitor compliance activities related to IT security frameworks, policies, standards, controls, and industry best practices; analyze findings, identify root causes and control gaps; and communicate results and recommendations to stakeholders and leadership.
- Coordinate and support internal and external IT security audits, including gathering, reviewing, validating, organizing, and presenting audit evidence and working with control owners to address evidence gaps and remediation activities.
- Review and evaluate technical audit evidence from cloud, SaaS, hosting, infrastructure, identity, network, security, and other technology environments to determine whether controls are appropriately designed, implemented, and operating effectively.
- Translate industry standards, regulatory requirements, contractual obligations, and audit criteria into actionable security controls, policies, procedures, testing requirements, and compliance activities.
- Independently manage assigned compliance projects and workstreams from planning through completion, including defining activities, coordinating stakeholders, tracking milestones and dependencies, resolving issues, and delivering required outcomes with limited supervision.
- Identify opportunities to automate repetitive compliance, audit, evidence collection, testing, reporting, and data analysis activities; develop or support scripts, integrations, workflows, and AI-enabled solutions to improve efficiency and scalability.
- Build and maintain productive relationships with internal stakeholders, control owners, technology teams, auditors, and other compliance partners while asking probing questions and challenging assumptions when additional information or evidence is required.
- Manage multiple concurrent audits, compliance activities, projects, and deadlines; maintain accurate documentation and proactively communicate risks, issues, dependencies, and status.
- Assist the sales team by responding to security questionnaires and questions submitted by customers and prospects.
What you'll likely bring
- Strong working knowledge of information security, IT risk, compliance, audit principles, and control frameworks, with sufficient technical understanding of cloud and hosted environments to analyze system configurations, access controls, logs, infrastructure evidence, security controls, and other technical audit artifacts.
- Fluency with modern AI technologies, including generative AI, large language models, AI agents, and AI-enabled automation, with the ability to understand their capabilities, limitations, security and compliance considerations, and appropriate application to compliance processes.
- Working knowledge of scripting and development concepts, with an interest and ability to develop automation that reduces manual compliance activities.
- Strong project management, analytical, problem-solving, and organizational skills, including the ability to independently take ownership of work, manage multiple competing priorities and projects, meet deadlines, and drive activities through completion.
- Demonstrated curiosity and learning agility, including the ability to ask effective questions, investigate unfamiliar technical concepts, challenge incomplete information, and rapidly learn new technologies, processes, tools, applications, and compliance requirements.
What can set you apart
- 3+ years of applicable experience in IT compliance, governance, risk and compliance (GRC), IT audit, information security, technology risk, or a related field preferred.
- Bachelor's degree or equivalent combination of education and relevant experience.
- Experience reviewing or supporting audits of cloud, hosted, SaaS, or other technology environments preferred.
- Experience with scripting, automation, APIs, data analysis, AI technologies, or development concepts preferred.
- Proficiency with data analysis tools and experience working with compliance, audit, risk management, data analysis, or workflow tools preferred.
#LI-CM1
#HYBRID
About Epicor
At Epicor, we’re truly a team. Join 5,000 talented professionals in creating a world of better business through data, AI, and cognitive ERP. We help businesses stay future-ready by connecting people, processes, and technology. From software engineers who command the latest AI technology to business development reps who help us seize new opportunities, the work we do matters. Together, Epicor employees are creating a more resilient global supply chain.
We’re Proactive, Proud, Partners.
Whatever your career journey, we’ll help you find the right path. Through our training courses, mentorship, and continuous support, you’ll get everything you need to thrive. At Epicor, your success is our success. And that success really matters, because we’re the essential partners for the world’s most essential businesses—the hardworking companies who make, move, and sell the things the world needs.
Competitive Pay & Benefits
Health and Wellness: Comprehensive health and wellness benefits designed to support your overall well-being.
Internal Mobility: Opportunities for mentorship, continuing education, and focused career goal setting, with 25% of positions filled internally.
Career Development: Free LinkedIn Learning licenses for everyone, along with our Mentoring Program to boost your personal development.
Education Support: Geographically specific programs to balance the cost of education with the benefits of continued learning and personal development.
Inclusive Workplace: Collaborate with a diverse team in an inclusive, global workplace that fosters innovation and celebrates partnership.
Work-Life Balance: Policies built on mutual trust and support, encouraging time off to rest, recharge, and reconnect.
Global Mobility: Comprehensive support for international relocations and permanent residency processes.
Equal Opportunities and Accommodations Statement
Epicor is committed to creating a workplace and global community where inclusion is valued; where you bring the whole and real you—that’s who we’re interested in. If you have interest in this or any role- but your experience doesn’t match every qualification of the job description, that’s okay- consider applying regardless.
We are an equal-opportunity employer.
Recruiter:
Christi McCallSkills Required
- Strong working knowledge of information security, IT risk, compliance, audit principles, and control frameworks
- Technical understanding of cloud and hosted environments, including system configurations, access controls, logs, infrastructure evidence, and security controls
- Fluency with modern AI technologies, including generative AI, large language models, AI agents, and AI-enabled automation
- Working knowledge of scripting and development concepts
- Strong project management, analytical, problem-solving, and organizational skills
- Ability to independently manage competing priorities, meet deadlines, and drive activities through completion
- Curiosity, learning agility, and ability to investigate unfamiliar technical concepts and compliance requirements
- 3+ years of applicable experience in IT compliance, GRC, IT audit, information security, or technology risk
- Bachelor's degree or equivalent combination of education and relevant experience
- Experience reviewing or supporting audits of cloud, hosted, SaaS, or other technology environments
- Experience with scripting, automation, APIs, data analysis, AI technologies, or development concepts
- Proficiency with data analysis tools and compliance, audit, risk management, data analysis, or workflow tools
Epicor Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Epicor and has not been reviewed or approved by Epicor.
-
Healthcare Strength — Health coverage (medical, dental, vision) is characterized as decent to solid, complemented by wellness resources. Company materials highlight health and wellness programming alongside core plans.
-
Leave & Time Off Breadth — Flexible or unlimited PTO exists in U.S. roles, and the organization emphasizes taking time to recharge. When team norms support it, the flexibility is considered a meaningful perk.
-
Retirement Support — A 401(k) with company match is available as part of the standard offering. The match level is generally viewed as modest but serviceable.
Epicor Insights
Similar Jobs
What We Do
We’re the Digital Brains of Our Customers’ Operations We help businesses stay future-ready with cognitive ERP that connects people, processes, and technology. From software engineers who command the latest AI technology to business development reps who help us seize new opportunities, the work we do matters. Together, Epicor employees are creating a more resilient global supply chain.
Why Work With Us
Our policies are built on mutual trust, support, and a commitment to maintaining a healthy work-life balance. That's why we encourage you to take the time off you need to rest, recharge, and reconnect.
Gallery







