Information Technology Risk & Compliance Analyst

basecamp· ECMC Shared Services Company, LLC
Apply Now ↗
📍 Minneapolis, MN - HybridFull time💰 USD 90K–100K

About this role

ECMC Group is a nonprofit corporation focused on helping students succeed. Headquartered in Minneapolis, ECMC Group and its family of companies provide financial tools and services, as well as funding for innovative programs to help students achieve their academic and professional goals.

    Job Summary


    Responsible for planning, executing and reporting on complex IT compliance activities and related initiatives across information systems.  Performs assigned portions of IT compliance programs, determining compliance with policies and procedures, monitoring, recommending corrective action, preparing findings, and assisting with remediation plans.  Reviews and services should be performed in accordance with professional and department standards.


    Essential Duties and Responsibilities:

    • Leads and performs complex IT compliance activities including planning, risk analysis, testing and reporting in accordance with professional and department standards.
    • Leads vendor security risk assessments and reviews security and compliance provisions within vendor contracts in partnership with procurement and legal teams.
    • Independently engages management to assess processes, identify control weaknesses and discuss compliance observations and risks.
    • Secures management ownership of findings and remediation plans and monitors remediation progress through completion.
    • Prepares clear documentation and draft reports communicating results, risks and recommendations to improve information system controls and practices.
    • Plans and executes IT compliance reviews and supports internal and external audits through evidence preparation and auditor coordination.
    • Contributes to enterprise risk assessments by identifying emerging risks, control gaps and improvement opportunities.
    • Provides guidance and informal coaching to staff on compliance activities of low to medium complexity as assigned.
    • Anticipates and manages stakeholder expectations while ensuring timely, consistent delivery of compliance services.
    • Communicates complex compliance concepts clearly to peers, leaders and business partners.
    • Performs other duties or responsibilities as assigned.

    Required Qualifications:

    • Bachelor’s degree in computer information systems, information technology, legal studies, or related field or an additional 2 years of relevant experience in lieu of degree.
    • Understanding of IT concepts such as identity and access management, threat and vulnerability management, data loss prevention, change management, data analytics, and software development lifecycle
    • 3+ years of experience in IT risk and compliance, IT governance, IT auditing or an IT related field
    • Experience assessing vendor risk, performing security assessments, and reviewing contracts
    • Experience working with procurement and legal teams
    • Experience assessing security controls for AWS or cloud environments
    • Experience developing and maintaining policies and/or information management frameworks
    • Experience creating and assembling evidence for internal or external auditors
    • Advanced knowledge of Microsoft Office suite, including experience analyzing data using Excel and designing or managing SharePoint sites
    • General knowledge of security control concepts, principles, risk analysis, FISMA, PCI Compliance, HIPAA, Privacy, process improvement and techniques, including frameworks such as NIST, ISO2700, COSO and COBIT

    Preferred Qualifications:

    • Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA) certifications preferred

    The pay range for this position is $90,000-$100,000. Actual compensation may vary based on factors such as relevant experience, peer and market benchmarks, and geographic location.


    This position is classified as hybrid Monday - Wednesday and requires attendance in Minneapolis, MN.


    To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed above are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

    ECMC Group also provides a comprehensive benefits package:  

    • Health & wellness benefits: Medical, dental, and vision insurance plan options, with a generous employer subsidy. Company paid life & disability insurance, pre-tax flexible spending accounts and robust wellness programs.
    • Financial benefits: Generous 401(k) plan with a company match up to 6% and additional discretionary contribution potential, holiday time off, paid time off accrual starting at 20 days/year and commuter subsidy.
    • Education benefits: Tuition reimbursement up to $10,500/year for approved programs and student loan payment reimbursement up to $4,800/year. Up to $5,250 of qualifying education benefits can be reimbursed pre-tax.

    Frequently Asked Questions

    What is the salary for the Information Technology Risk & Compliance Analyst role at basecamp?
    The listed salary for this Information Technology Risk & Compliance Analyst position at basecamp is USD 90K–100K. This is an Full time role.
    Where is the Information Technology Risk & Compliance Analyst position at basecamp located?
    This Information Technology Risk & Compliance Analyst role at basecamp is based in Minneapolis, MN - Hybrid. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
    Is the Information Technology Risk & Compliance Analyst role at basecamp full-time or part-time?
    This is listed as a Full time position. It is posted as a Information Technology Risk & Compliance Analyst role in the ECMC Shared Services Company, LLC department at basecamp.
    Which team or department does the Information Technology Risk & Compliance Analyst at basecamp belong to?
    This Information Technology Risk & Compliance Analyst position is part of the ECMC Shared Services Company, LLC department at basecamp. See the full job description for more information about the team structure and responsibilities.
    How do I apply for the Information Technology Risk & Compliance Analyst position at basecamp?
    Click the "Apply Now" button on this page. You will be redirected to basecamp's official application portal hosted on workday where you can submit your application directly.
    When was the Information Technology Risk & Compliance Analyst job at basecamp posted?
    This Information Technology Risk & Compliance Analyst position at basecamp was posted on Sep 25, 2026. Apply as soon as possible — early applications are often reviewed first.
    Information Technology Risk & Compliance Analyst
    basecamp · 💰 USD 90K–100K
    Apply for this role ↗

    You'll be redirected to basecamp's official application page on Workday.