Information Technology Risk & Compliance Analyst

ECMC Foundation•Minneapolis, MN
•Hybrid

About The Position

Responsible for planning, executing and reporting on complex IT compliance activities and related initiatives across information systems. Performs assigned portions of IT compliance programs, determining compliance with policies and procedures, monitoring, recommending corrective action, preparing findings, and assisting with remediation plans. Reviews and services should be performed in accordance with professional and department standards.

Requirements

  • Bachelor’s degree in computer information systems, information technology, legal studies, or related field or an additional 2 years of relevant experience in lieu of degree.
  • Understanding of IT concepts such as identity and access management, threat and vulnerability management, data loss prevention, change management, data analytics, and software development lifecycle
  • 3+ years of experience in IT risk and compliance, IT governance, IT auditing or an IT related field
  • Experience assessing vendor risk, performing security assessments, and reviewing contracts
  • Experience working with procurement and legal teams
  • Experience assessing security controls for AWS or cloud environments
  • Experience developing and maintaining policies and/or information management frameworks
  • Experience creating and assembling evidence for internal or external auditors
  • Advanced knowledge of Microsoft Office suite, including experience analyzing data using Excel and designing or managing SharePoint sites
  • General knowledge of security control concepts, principles, risk analysis, FISMA, PCI Compliance, HIPAA, Privacy, process improvement and techniques, including frameworks such as NIST, ISO2700, COSO and COBIT

Nice To Haves

  • Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications preferred

Responsibilities

  • Leads and performs complex IT compliance activities including planning, risk analysis, testing and reporting in accordance with professional and department standards.
  • Leads vendor security risk assessments and reviews security and compliance provisions within vendor contracts in partnership with procurement and legal teams.
  • Independently engages management to assess processes, identify control weaknesses and discuss compliance observations and risks.
  • Secures management ownership of findings and remediation plans and monitors remediation progress through completion.
  • Prepares clear documentation and draft reports communicating results, risks and recommendations to improve information system controls and practices.
  • Plans and executes IT compliance reviews and supports internal and external audits through evidence preparation and auditor coordination.
  • Contributes to enterprise risk assessments by identifying emerging risks, control gaps and improvement opportunities.
  • Provides guidance and informal coaching to staff on compliance activities of low to medium complexity as assigned.
  • Anticipates and manages stakeholder expectations while ensuring timely, consistent delivery of compliance services.
  • Communicates complex compliance concepts clearly to peers, leaders and business partners.
  • Performs other duties or responsibilities as assigned.

Benefits

  • Medical, dental, and vision insurance plan options, with a generous employer subsidy.
  • Company paid life & disability insurance
  • Pre-tax flexible spending accounts
  • Robust wellness programs
  • Generous 401(k) plan with a company match up to 6% and additional discretionary contribution potential
  • Holiday time off
  • Paid time off accrual starting at 20 days/year
  • Commuter subsidy
  • Tuition reimbursement up to $10,500/year for approved programs
  • Student loan payment reimbursement up to $4,800/year
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service