IT Risk & Compliance Analyst (Hybrid)

Intact Insurance Specialty Solutions•Farmington, CT
•$75,000 - $110,000•Hybrid

About The Position

The IT Risk & Compliance Analyst supports the organization’s IT Risk / GRC function by collecting, organizing, analyzing, and reporting information related to cybersecurity risk, control performance, audit response, remediation tracking, and security metrics. This is a hands-on individual contributor role where one person may support multiple related activities across governance, risk, compliance, cybersecurity metrics, and audit coordination all aligned with the NIST framework. The analyst works with and contributes to IT, cybersecurity, infrastructure, identity and access management, vulnerability management, and audit stakeholders to help organize evidence, track action items, maintain accurate status reporting, and translate technical information into clear management-ready reporting. The ideal candidate is highly organized, analytical, comfortable learning new cybersecurity domains, and able to follow up consistently across multiple teams and deadlines.

Requirements

  • Management, Audit, Accounting, or a related field, or equivalent relevant experience.
  • Three (3) to five (5) years of experience in IT risk, GRC, information security, IT audit, technology controls, security operations, or a related function.
  • Experience in insurance, financial services, healthcare, utilities, or another regulated or compliance-intensive industry is preferred.

Nice To Haves

  • Relevant professional certifications, such as Security+, CISA, CRISC, CISM, CISSP, CGRC, or ITIL Foundation, are preferred but not required.

Responsibilities

  • Maintain organized records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status.
  • Collect and validate information from control owners and technical teams to support risk reviews, control assessments, compliance activities, cybersecurity metrics, and management reporting.
  • Coordinate audit response activities across internal and external auditors in multiple geographic regions and IT, security, infrastructure, compliance, and business stakeholders.
  • Track audit requests, evidence, responses, findings, remediation actions, retesting, risk acceptances, compensating controls, owners, deadlines, and closure; identify blockers and escalate overdue or unclear items as appropriate.
  • Help IT and security teams develop clear, well-supported responses to audit findings and maintain evidence in an organized, repeatable, and auditable manner.
  • Collect, organize, and analyze cybersecurity and IT risk metrics across vulnerability management, identity and access management, endpoint protection, incident response, infrastructure operations, logging, and monitoring.
  • Develop accurate reports, dashboards, and management-ready summaries using tools such as Excel, PowerPoint, SharePoint, ticketing systems, and other available reporting platforms.
  • Analyze trends, gaps, aging items, control exceptions, and remediation progress, and translate technical security information into business-relevant insights for leadership, risk committees, auditors, and non-technical audiences.
  • Define and maintain consistent metric definitions, data owners, source systems, refresh schedules, assumptions, and limitations.
  • Create and maintain trackers, checklists, evidence logs, reporting calendars, process maps, and follow-up routines that improve consistency, accuracy, timeliness, and repeatability of risk, audit, and security reporting.
  • Coordinate application security and penetration testing for internally developed, SaaS, web, mobile, API, cloud, and vendor-hosted applications, including scoping, scheduling, execution support, findings tracking, remediation validation, and retesting through closure.
  • Support application security governance by maintaining application inventories, promoting secure software development practices, preparing management reporting, and aligning testing with organizational and regulatory requirements.
  • Apply recognized cybersecurity and control frameworks, including NIST-based terminology, under leadership guidance.
  • Clarify ownership, next steps, and response dates; follow up consistently and communicate professionally with stakeholders while maintaining a collaborative, service-oriented approach.
  • Escalate material risks, delays, unresolved ownership, and data quality concerns, and promote accountability and continuous improvement across IT risk and security operations.

Benefits

  • Comprehensive medical, dental and vision insurance with no waiting period
  • Competitive paid time off programs
  • 401(k) savings and annual contributions of up to 12% of annual salary
  • Mental health support programs, life and disability insurance, paid parental leave and a variety of additional voluntary benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service