Hiring.Camp

IT Risk and Compliance Analyst

Hugeinc

·

Today

Location
United States
Department
IT
Experience
3+ years
Source
Greenhouse

Description

Location: This position is remote within the United States.

The role. 

We are looking for a Compliance Officer to join the IT Risk and Compliance team and carry the day-to-day execution of the program. This is a generalist role spanning client contracts and security questionnaires, control evidence and gap remediation, vendor risk, data retention and privacy, and the policies that tie it all together.

The program is being rebuilt from the ground up, so you will help shape how the work gets done. The ideal candidate is organized, comfortable with legal and technical language, and able to keep many threads moving at once.

What you’ll be doing. 

  • Review client MSAs, SOWs, DPAs, and security addenda using our contract analysis tooling; identify clauses that need Legal, IT, or Delivery attention and coordinate redlines through to signature.
  • Translate signed contractual obligations (security, privacy, data handling, audit rights, breach notification, sub-processor terms) into tracked commitments and confirm they are being met operationally.
  • Respond to client security questionnaires, due diligence requests, and audit inquiries; maintain the reusable answer library so responses get faster and more consistent over time.
  • Collect, organize, and maintain control evidence in the GRC platform; track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks as they are adopted.
  • Support vendor risk assessments for SaaS and AI providers: review vendor security documentation, DPAs, and sub-processor lists, and record and monitor findings in the vendor register.
  • Operationalize the data retention and disposal policy: track department retention schedules, document exceptions and legal holds, and verify retention settings across platforms with IT.
  • Support the privacy program including data mapping, data subject request handling, and GDPR and CCPA obligation tracking.
  • Draft and maintain compliance policies, SOPs, and process documentation; keep them current, published (for internal use where applicable) and actually followed.
  • Prepare risk and compliance status reporting for leadership.
  • Participate in business continuity and disaster recovery planning and tabletop exercises.
  • Participate in security incident response management.
  • Maintain and monitor risk register and prepare for annual risk assessment.
  • Administer security awareness training and track compliance.
  • Support internal audits, access reviews, and periodic control testing.

What we’d like to see.

  • Bachelor’s degree required or equivalent practical experience.
  • 3–5 years of experience in compliance, GRC, contract management, privacy, or a related field.
  • Hands-on experience reading and reviewing commercial contracts, ideally MSAs, DPAs, or security addenda, and working with legal counsel on redlines.
  • Experience responding to client security questionnaires or vendor due diligence requests.
  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, NIST CSF) and what evidence looks like in practice.
  • Foundational understanding of data privacy regulations (GDPR, CCPA) and how they show up in contracts.
  • Exceptional organization and follow-through; you can run many parallel threads and nothing slips.
  • Clear, concise written communication; you can summarize a 40-page contract into the three things that matter.
  • Comfortable working with SaaS tools and learning new platforms quickly; you like using software to make process better.
  • Self-directed and effective in a small team where you own outcomes end to end.

This role is currently not available for hire or work in New Mexico, Montana, Alaska and Hawaii, USA.

About Huge.

Huge is an independent, human-first AI-native design and technology company. We make things that matter by bringing AI, people, design and technology together as one system. With more than 1,000 design and technology experts working in hub cities around the world, including Bogotá, Chicago, Ho Chi Minh City, London, Los Angeles, Medellín, New York, San Francisco, and Washington, DC, we partner with some of the world’s most ambitious brands, including Google, NBCU, PepsiCo, Vail Resorts, Atlantic Health, and Candescent. Learn more at hugeinc.com.

Huge is committed to creating an inclusive employee experience for all. Regardless of race, gender, religion, sexual orientation, age, disability, or if you’re parenting the next generation of innovators, we firmly believe that our work is at its best when everyone feels free to be their most authentic self.

Huge is an equal opportunity employer (EOE). We strongly support diversity in the workforce. We are committed to an inclusive, barrier-free recruitment and selection process and work environment. If you are contacted for a job opportunity, please advise us of any accommodation needed to ensure you have access to a fair and equitable process. Any information received relating to accommodation will be addressed confidentially.

Workers shall not be required to pay employers’ or agents’ recruitment fees or other related fees for their employment. If any such fees are found to have been paid by workers, such fees shall be repaid to the worker.


#LI-POST #LI-Remote

The salary range for this position is as listed below. Exactly where a prospective employee will be paid within this range will depend on, among other factors, the actual salary ranges for current and former employees who are either currently filling a similar role or did in the past; the candidate’s depth of experience and qualifications; the level of specialization the role requires; budgetary considerations; the market demand for that role and the local market conditions that exist where the employee will be based. For current Huge employees, tenure will also be a consideration.
Wage Disclosure
$80,000—$90,000 USD

Skills

SOCContract ManagementComplianceSOC 2GDPRISO 27001

Similar Jobs

27

Senior IT Risk and Compliance Analyst

Copeland·Pune, India·Hybrid

1d ago

IT Risk and Compliance Specialist Principal

GDIT·USA LA Bossier City - 6310 E Texas St, US

4d ago

IT Risk and Compliance Analyst

Greenberg Traurig·Miramar, US·Hybrid

3mo ago

Vice President, IT Security Risk and Control

Mufgub·London Ropemaker place, UK

2d ago

Head of IT Governance, Risk, and Compliance (GRC)

"LabConnect, LLC"·Remote - US, 2304 Silverdale Drive·Remote

1w ago

Staff IT Analyst II - IT Governance, Risk, and Controls

Western Alliance Bancorporation·Block 23, US +2

2w ago

Intern - CFO - IT (Security, Risk, and Compliance)

Gilead Sciences·US - CA - Foster City, US·Hybrid

3w ago

Analyst, IT Governance, Risk, and Compliance

Telesat·Ottawa, Ontario·Hybrid

4w ago

Sr Manager - IT Governance, Risk, and Compliance

Plexus·Oradea, BH

1mo ago

Sr Manager - IT Governance, Risk, and Compliance

Plexus·Livingston, GB

1mo ago

IT Compliance and Risk Specialist

HiNext·Office_KRK Pawia, Poland +1·Hybrid

1mo ago

Sr. Research IT Security Risk and Compliance Analyst - Computing Services

Careers @ Carnegie Mellon·Pittsburgh, US

1mo ago

Manager, IT Governance, Risk and Compliance

Wwecorp·New York, NY +6·Remote

1mo ago

IT Governance, Risk and Compliance Specialist

Abaxx Technologies·Singapore

2mo ago

IT Governance, Risk and Control Specialist

Encore·West Malling - 1 Kings Hill, UK +1·Remote

2mo ago

IT and Cybersecurity Risk Manager

Hrhub·Porto, Portugal·Onsite

2mo ago

Head of IT Governance, Risk, and Compliance (GRC)

"LabConnect, LLC"·Remote - US, 2304 Silverdale Drive·Remote

3mo ago

IT Governance and Risk Assessment Officer

Global Water Solutions·Boksburg Gauteng, South Africa

4mo ago

IT and Cybersecurity Risk Manager

Hrhub·Paris, France

4mo ago

Manager - IT Governance, Risk and Compliance

Plexus·Neenah, WI

4mo ago

Head IT Governance and Risk Asia

Juliusbaer·Singapore

6mo ago

IT Governance, Risk and Compliance Consultant (Contract Contingent)

ProSidian Consulting·Arlington, VA

1y+ ago

R1054609 Senior Analyst, IT Compliance & Risk - Identity and Access Management (IAM)

CVS Health·Woonsocket-1 CVS Drive, US +1·Remote

1d ago

Governance, Risk, and Compliance Associate - IT

Weaver·New York, NY +2

2mo ago

IT Sr Director, Compliance and Risk Governance

Intuitive Surgical·Sunnyvale, CA

1mo ago

Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance

Weaver·New York, NY

1mo ago

Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver·DALLAS, TX +3

1w ago