Job Summary
The IT Compliance Analyst plays a critical role in ensuring the quality, security, and compliance of enterprise information systems throughout their lifecycle. This role focuses on the design, execution, and continuous improvement of IT General Controls (ITGCs) spanning system development, cybersecurity, and data privacy. The analyst partners closely with system owners, control owners, cybersecurity, and audit teams to support regulatory compliance, risk management, and audit readiness while promoting a strong culture of IT quality and accountability.
Key Responsibilities
- Ensure IT General Controls (ITGCs) are properly designed, documented, and operating effectively across system lifecycles.
- Evaluate controls related to system development, change management, access management, cybersecurity, and data protection.
- Partner with system owners and control owners to document processes, perform control testing, and remediate deficiencies.
- Support internal and external audits by coordinating evidence collection, responding to audit inquiries, and tracking remediation efforts.
- Identify, assess, and document IT risks with a focus on cybersecurity threats, data privacy concerns, and control gaps.
- Contribute to the continuous improvement of IT quality practices, standards, and control frameworks.
- Develop, update, and deliver training and awareness materials for IT policies, standards, and operating procedures.
- Support compliance with applicable regulatory and contractual requirements, including HIPAA, SOX, and data privacy obligations.
Qualifications
- Bachelor’s degree in Information Systems, Computer Science, Information Technology, or a related field.
- 2–3 years of experience in IT compliance, IT audit, risk management, or IT quality assurance.
- Strong understanding of IT control frameworks and IT General Controls (e.g., access controls, SDLC, change management, incident response).
- Experience with system lifecycles, including development, implementation, maintenance, and retirement.
- Working knowledge of cybersecurity concepts and data protection controls.
- Familiarity with HIPAA regulations and SOX compliance requirements.
- Strong background in data privacy principles and control requirements.
- Excellent written, verbal, and cross-functional collaboration skills.
- Must be available for night shifts.
Preferred Qualifications
- Background in healthcare information privacy and protection of sensitive health data.
- Experience working in regulated healthcare or life sciences environments.
- Exposure to frameworks such as COBIT, NIST, ISO 27001, or similar.
- Audit support experience in HIPAA-regulated systems or environments.