Senior Risk & Compliance Analyst

Posted 5 Days Ago
Be an Early Applicant
Minneapolis, MN, USA
In-Office
115K-125K Annually
Senior level
Edtech • Other
The Role
Leads IT risk and compliance reviews, control testing, risk assessments, audits, FISMA and SOC readiness, penetration testing, vendor security assessments, and security awareness initiatives. Evaluates controls across cloud, identity, vulnerability management, data protection, change management, and SDLC domains. Documents findings, recommends corrective actions, monitors remediation, improves governance practices, advises stakeholders, and mentors junior team members.
Summary Generated by Built In

ECMC Group is a nonprofit corporation focused on helping students succeed. Headquartered in Minneapolis, ECMC Group and its family of companies provide financial tools and services, as well as funding for innovative programs to help students achieve their academic and professional goals.

    Job Summary:

    Serves as a senior member of the IT Risk and Compliance function, providing expertise and independent judgment to support the organization's risk management, regulatory compliance, and information security objectives. Partners with stakeholders across the enterprise to evaluate risk, strengthen controls, and promote compliance with applicable standards and requirements. Acts as a trusted advisor within the organization, contributing to the effectiveness and continuous improvement of risk and compliance practices while serving as a resource to less experienced team members.

    Essential Duties and Responsibilities:

    • Leads and performs medium to high complexity IT risk and compliance reviews, including planning, risk analysis, evidence gathering, control testing, and reporting.

    • Coordinates and supports FISMA readiness assessments, SOC reporting, external penetration testing, and internal and external audit activities.

    • Plans and coordinates security awareness initiatives, including annual training, phishing simulations, security communications, and custom learning content.

    • Leads vendor security risk assessments and evaluates security and compliance requirements within vendor relationships.

    • Independently engages stakeholders to identify control weaknesses, assess compliance risks, and recommend corrective actions.

    • Prepares clear documentation, reports, and recommendations that improve information system controls and risk management practices.

    • Secures stakeholder ownership of findings and remediation plans and monitors progress through resolution.

    • Completes enterprise risk assessments and supports the design and implementation of effective controls to address emerging risks and compliance requirements.

    • Contributes to the development and continuous improvement of risk and compliance standards, policies, procedures, monitoring activities, and governance practices.

    • Mentors less experienced team members, manages stakeholder expectations, and communicates complex compliance concepts to business and technology leaders.

    • Performs other duties or responsibilities as assigned.

    Required Qualifications:

    • Bachelor's degree in Computer Information Systems, Information Technology, Legal Studies, or a related field; or an additional two years of relevant IT experience in lieu of a degree.

    • 5+ years of experience in IT risk and compliance, IT governance, IT auditing, information security, or a related field.

    • Experience supporting SOC reporting, third-party assessments, FISMA readiness activities, and internal or external audits.

    • Experience applying security control frameworks, risk assessment methodologies, and compliance standards, including NIST, ISO 27001, COSO, COBIT, PCI DSS, HIPAA, or similar frameworks.

    • Experience evaluating or supporting controls related to identity and access management, vulnerability management, data protection, change management, software development lifecycle, or other IT control domains.

    • Experience assessing security controls within AWS or other cloud environments.

    • Advanced proficiency with Microsoft Office applications, including Excel data analysis and SharePoint content and site administration.

    • Experience developing and delivering training, awareness content, or learning programs using Articulate Rise or similar learning platforms.

    Preferred Qualifications:

    • Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications

    • Big 4 accounting firm experience
       

    The pay range for this position is $115,000-$125,000. Actual compensation may vary based on factors such as relevant experience, peer and market benchmarks, and geographic location.

    This position is classified as hybrid Monday - Wednesday and requires attendance in Minneapolis, MN.

    To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

    ECMC Group also provides a comprehensive benefits package:  

    • Health & wellness benefits: Medical, dental, and vision insurance plan options, with a generous employer subsidy. Company paid life & disability insurance, pre-tax flexible spending accounts and robust wellness programs.
    • Financial benefits: Generous 401(k) plan with a company match up to 6% and additional discretionary contribution potential, holiday time off, paid time off accrual starting at 20 days/year and commuter subsidy.
    • Education benefits: Tuition reimbursement up to $10,500/year for approved programs and student loan payment reimbursement up to $4,800/year. Up to $5,250 of qualifying education benefits can be reimbursed pre-tax.

    Skills Required

    • Bachelor's degree in Computer Information Systems, Information Technology, Legal Studies, or a related field, or two additional years of relevant IT experience in lieu of a degree
    • 5+ years of experience in IT risk and compliance, IT governance, IT auditing, information security, or a related field
    • Experience supporting SOC reporting, third-party assessments, FISMA readiness activities, and internal or external audits
    • Experience applying security control frameworks, risk assessment methodologies, and compliance standards including NIST, ISO 27001, COSO, COBIT, PCI DSS, HIPAA, or similar frameworks
    • Experience evaluating or supporting controls related to identity and access management, vulnerability management, data protection, change management, software development lifecycle, or other IT control domains
    • Experience assessing security controls within AWS or other cloud environments
    • Advanced proficiency with Microsoft Office applications, including Excel data analysis and SharePoint content and site administration
    • Experience developing and delivering training, awareness content, or learning programs using Articulate Rise or similar learning platforms
    • Certified Information Systems Auditor (CISA) certification
    • Certified Internal Auditor (CIA) certification
    • Big Four accounting firm experience
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    HQ: Minneapolis, MN
    1,153 Employees

    What We Do

    ECMC Group is a nonprofit corporation with a mission to help students succeed. All companies in the ECMC Group family work together to fulfill this mission through product and service support and by funding its philanthropic activities through ECMC Foundation.

    Similar Jobs

    Applied Systems Logo Applied Systems

    Manager, HRIS

    Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
    Remote or Hybrid
    United States
    3116 Employees
    100K-160K Annually

    PwC Logo PwC

    Finance Data, Analytics & AI - Associate

    Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
    Hybrid
    39 Locations
    370000 Employees
    61K-100K Annually

    PwC Logo PwC

    Consultant

    Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
    Hybrid
    21 Locations
    370000 Employees
    77K-202K Annually

    PwC Logo PwC

    Managed Services - Revenue Cycle Coding - Senior Manager

    Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
    Hybrid
    42 Locations
    370000 Employees
    124K-280K Annually

    Similar Companies Hiring

    CodePath.org Thumbnail
    Edtech • Social Impact
    San Francisco, CA
    55 Employees
    Rosendin Thumbnail
    Other • Manufacturing
    San Jose, CA
    6219 Employees
    OmniCable Thumbnail
    Other
    Houston, Texas
    815 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account