IT Risk and Compliance Analyst @HugeInc
Compliance
Salary $80,000 - $90,0..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted YDay

[Hiring] IT Risk and Compliance Analyst @HugeInc

YDay - HugeInc is hiring a remote IT Risk and Compliance Analyst. πŸ’Έ Salary: $80,000 - $90,000 usd πŸ“Location: USA

Role Description

We are looking for a Compliance Officer to join the IT Risk and Compliance team and carry the day-to-day execution of the program. This is a generalist role spanning:

  • Client contracts and security questionnaires
  • Control evidence and gap remediation
  • Vendor risk
  • Data retention and privacy
  • Policies that tie it all together

The program is being rebuilt from the ground up, so you will help shape how the work gets done. The ideal candidate is organized, comfortable with legal and technical language, and able to keep many threads moving at once.

What you’ll be doing

  • Review client MSAs, SOWs, DPAs, and security addenda using our contract analysis tooling; identify clauses that need Legal, IT, or Delivery attention and coordinate redlines through to signature.
  • Translate signed contractual obligations (security, privacy, data handling, audit rights, breach notification, sub-processor terms) into tracked commitments and confirm they are being met operationally.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries; maintain the reusable answer library so responses get faster and more consistent over time.
  • Collect, organize, and maintain control evidence in the GRC platform; track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks as they are adopted.
  • Support vendor risk assessments for SaaS and AI providers: review vendor security documentation, DPAs, and sub-processor lists, and record and monitor findings in the vendor register.
  • Operationalize the data retention and disposal policy: track department retention schedules, document exceptions and legal holds, and verify retention settings across platforms with IT.
  • Support the privacy program including data mapping, data subject request handling, and GDPR and CCPA obligation tracking.
  • Draft and maintain compliance policies, SOPs, and process documentation; keep them current, published (for internal use where applicable) and actually followed.
  • Prepare risk and compliance status reporting for leadership.
  • Participate in business continuity and disaster recovery planning and tabletop exercises.
  • Participate in security incident response management.
  • Maintain and monitor risk register and prepare for annual risk assessment.
  • Administer security awareness training and track compliance.
  • Support internal audits, access reviews, and periodic control testing.

Qualifications

  • Bachelor’s degree required or equivalent practical experience.
  • 3–5 years of experience in compliance, GRC, contract management, privacy, or a related field.
  • Hands-on experience reading and reviewing commercial contracts, ideally MSAs, DPAs, or security addenda, and working with legal counsel on redlines.
  • Experience responding to client security questionnaires or vendor due diligence requests.
  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, NIST CSF) and what evidence looks like in practice.
  • Foundational understanding of data privacy regulations (GDPR, CCPA) and how they show up in contracts.
  • Exceptional organization and follow-through; you can run many parallel threads and nothing slips.
  • Clear, concise written communication; you can summarize a 40-page contract into the three things that matter.
  • Comfortable working with SaaS tools and learning new platforms quickly; you like using software to make process better.
  • Self-directed and effective in a small team where you own outcomes end to end.

Requirements

  • This role is currently not available for hire or work in New Mexico, Montana, Alaska and Hawaii, USA.

Benefits

  • The salary range for this position is $80,000 β€” $90,000 USD.
  • Exactly where a prospective employee will be paid within this range will depend on various factors including experience, qualifications, and market conditions.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
IT Risk and Compliance Analyst @HugeInc
Compliance
Salary $80,000 - $90,0..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,280+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later