Information Technology Risk Compliance Analyst positions focus on delivering results in their domain. This page aggregates open Information Technology Risk Compliance Analyst roles and what employers typically expect.
**Position Summary:** The IT Risk & Compliance Analyst plays a critical role in safeguarding Trinity’s technology environment by managing cybersecurity risk, regulatory compliance, and business continuity programs. In addition to ensuring compliance with standards such as PCI DSS and overseeing disaster recovery planning, this role monitors Trinity’s IT environment for emerging cyber threats and coordinates incident response efforts. As a hybrid security and compliance role, the Analyst supports the development and enforcement of security policies, manages security assessments and remediation, and maintains documentation for internal governance and external audits. The role also provides hands-on technical oversight of log reviews, vulnerability scans, and threat monitoring activities. By promoting a security-aware culture and enabling continuous improvement, the IT Risk & Compliance Analyst strengthens the organization’s resilience and readiness in the face of evolving threats. The annual salary range for this position is $126,100 to $157,900. **Essential Duties and Responsibilities:** Governance - Develop and coordinates vendor risk management frameworks, policies and processes within a broader enterprise, operational and IT risk management model. - Compile metrics for reporting threats, risks, and success of operating controls to leadership. - Coordinate creation, approval, maintenance and updating of security policies. - Coordinate periodic access reviews. Risk Management - Develop and maintain a methodology to identify and prioritize internal and external threats, quantify the risk to the organization, and recommend methods to mitigate or remediate risk. Work with risk owners to develop appropriate risk response plans; monitor plans to closure. - Develop and maintain a risk register. Coordinate periodic management reviews and manage exception requests. - Research emerging threats and vulnerabilities to aid in the identification of network incidents. Third-Party Risk Management - Coordinate management of vendor, supplier and other third-party risk. - Facilitate assessments of new and existing third-parties. Evaluate statements of work from partners to ensure that adequate security protections are in place. Assess provider documentation (e.g., security assessment questionnaire responses, SOC 1 or SOC 2 audit reports, or other sources). - As risks are identified, report risks to management and vendor management teams; work with third-parties to develop appropriate risk response plans; and monitor plans to closure. Security Awareness and Training - Coordinate, maintain and continuously improve security awareness and role-based security training programs, to mitigate human risks. - Educate stakeholders on cybersecurity-related matters to increase awareness and improve culture. - Create and coordinate plans for role-based security training. Audit and Compliance - Work with Legal to maintain an understanding of internal and external regulatory compliance requirements. - Assist in responding to findings from external audits, penetration tests and vulnerability assessments. - Conduct security control gap assessments of internal systems, third-party and internally-developed applications, and IT infrastructure. Work with technical teams as they develop remediation plans and track approved plans to completion. Security Monitoring and Incident Response - Serve as the designated backup Incident Manager when the primary manager is unavailable. Lead the end to end response to security incidents, coordinating with external partners as needed (such as cyber insurance carriers, digital forensics teams, and root cause analysis specialists). When activated, initiate and direct the security incident response process and exercise decision making authority within the scope of the role to ensure timely and effective resolution. **Required Knowledge, Skills, and Activities:** - Strong understanding of IT risk frameworks, compliance requirements,…