NORC at the University of Chicago

IT Risk & Compliance Analyst

Washington, Washington, D.C

No sponsorship$53k-$800kDetected 1 day ago
SpringCloud PlatformsCybersecurityComplianceHIPAAResearchLeadershipCommunicationCollaborationOrganizational SkillsCISSP

About the role

  • NORC at the University of Chicago is seeking an IT Risk & Compliance Analyst to join our DSS Security & Compliance team.

Responsibilities

  • Partner with engineering, cloud, infrastructure, and operations teams to validate security controls, resolve compliance findings, and improve overall security posture.
  • Develop, review, validate, and maintain security documentation, including policies, standards, procedures, System Security Plans (SSPs), control implementation statements, and supporting compliance evidence.
  • Support internal and external audits by coordinating evidence requests, responding to assessor questions, and managing remediation activities.
  • Assist in developing compliance dashboards, metrics, and executive reporting that measure security posture, control effectiveness, and continuous monitoring performance.
  • Support governance and compliance initiatives across NIST SP 800-53 Rev.
  • The Security & Compliance team partners across the organization to strengthen cybersecurity, reduce organizational risk, and maintain compliance with government, client, and industry security requirements.
  • WHAT WE DO: NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions.
  • Today, government, corporate, and nonprofit clients around the world partner with us to transform increasingly complex information into useful knowledge.

Requirements

  • FedRAMP Continuous Monitoring & Compliance (Primary Focus) Minimum of two years of experience supporting cybersecurity, governance, risk, or compliance programs.
  • Experience coordinating evidence collection, security control assessments, vulnerability management, remediation tracking, POA&M management, and compliance reporting.
  • Familiarity with vulnerability management platforms, cloud security technologies, configuration compliance tools, endpoint security, and security monitoring solutions.
  • Security Governance & Compliance Strong understanding of cybersecurity governance principles and security compliance frameworks including NIST SP 800-53 Rev.
  • Serve as a primary contributor to NORC's FedRAMP Continuous Monitoring Program, coordinating recurring activities required to maintain FedRAMP authorization.

Skills

  • CAP, CGRC, CISSP, CISM, CISA or other cybersecurity certification preferred.
  • Experience supporting or maintaining a FedRAMP Authorized or FedRAMP Ready cloud environment is strongly preferred.
  • Knowledge of FedRAMP Continuous Monitoring requirements, including monthly, quarterly, annual, and significant change activities.
  • Experience monitoring security control effectiveness and partnering with technical teams to resolve compliance findings.
  • Experience supporting internal or external assessments and audit activities.
  • Familiarity with FedRAMP templates, documentation, assessment processes, and security reporting.
  • 5, CMMC, ISO 27001, SOC 2, HIPAA, and related industry standards.
  • Experience supporting governance processes that improve compliance consistency, audit readiness, and operational maturity.
  • Experience using Governance, Risk, and Compliance (GRC) platforms such as CSAM, ServiceNow GRC, Archer, or similar solutions.
  • Risk Management Experience conducting or supporting security risk assessments, security impact analyses, and control gap assessments.
  • Ability to identify security risks, assess business impact, and recommend practical remediation strategies.
  • Experience reviewing vulnerability findings and supporting remediation activities.

Compensation

  • per year - estimated
  • $91,000 - $125,000 per year
  • The pay range for this position is $77,000 - $95,000.

Benefits

  • Regular staff are eligible for NORC's comprehensive benefits program.
  • NORC is committed to equity and transparency in its pay practices.
  • We publish salary ranges and benefit information for every job.
  • A candidate's placement within the range depends on factors such as competencies, education, qualifications, experience, skills, performance, and organizational needs.

Company info

  • For over 80 years, NORC has evolved in many ways, moving the needle with research methods, technical applications and groundbreaking research findings.
  • But our tradition of excellence, passion for innovation, and commitment to collegiality have remained constant components of who we are as a brand, and who each of us is as a member of the NORC team.
  • With world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we're known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale.
  • EEO STATEMENT: NORC is an equal opportunity employer.
  • NORC evaluates qualified applicants without regard to race, color, religion, sex, gender, national origin, disability, status as a protected veteran, sexual orientation, and other legally protected characteristics.
  • Stats for this job
  • Salary comparison:
  • Washington, D.C.
  • The number of jobs in each salary range for all:
  • IT Security Risk and Compliance Analyst II
  • $91,000 - $125,000 per year
  • United Therapeutics
  • Silver Spring, Maryland
  • Silver Spring, Maryland, 20915
  • Compliance and Risk Analyst
  • Integral Federal
  • Tysons Corner, Virginia, 22102
  • Risk and Compliance Systems Analyst
  • Vienna, Virginia, 22184
  • Risk & Compliance Systems Analyst
  • Popular searches
  • Risk and compliance
  • Back to last search
  • No thanks, take me to the job
  • Country selection
  • South Africa
  • United Kingdom
  • NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions.
  • Since 1941, our teams have conducted groundbreaking studies, created and applied innovative methods and tools, and advanced principles of scientific integrity and collaboration.

Visa & Work Authorization

  • Citizenship: U

This listing is sourced directly from NORC at the University of Chicago's careers page and normalized into a canonical job model.