IT Risk & Compliance Analyst; Hybrid
Listed on 2026-10-10
-
IT/Tech
Cybersecurity
Our employees are at the heart of what we do: helping people, businesses and society prosper in good times and be resilient in bad times. When you join our team, you are bringing this purpose to life alongside a passionate community.
Feel empowered to learn and grow while being valued for who you are. At Intact, we commit to supporting you in reaching your goals with tools, opportunities, and flexibility. It’s our promise to you.
Who we areAt Intact Insurance Specialty Solutions, we are experts at what we do in protecting what makes businesses unique. Our deep understanding of the specialty insurance market is the foundation for our customized solutions, backed by targeted risk control and claims services. Our employees are passionate about providing insurance coverage that’s aligned to our targeted customer groups.
Intact’s Global Specialty Lines business spans across more than 20 verticals in four distinct markets: U.S., Canada, UK and Europe. The following opportunity is for our U.S. team.
The opportunityWe currently have an opportunity for an IT Risk & Compliance Analyst to join our Corporate IT team based in our Canton, MA;
Boston, MA;
Farmington, CT or Raleigh, NC offices on a hybrid schedule. The IT Risk & Compliance Analyst supports the organization’s IT Risk / GRC function by collecting, organizing, analyzing, and reporting information related to cybersecurity risk, control performance, audit response, remediation tracking, and security metrics. This is a hands-on individual contributor role where one person may support multiple related activities across governance, risk, compliance, cybersecurity metrics, and audit coordination all aligned with the NIST framework.
The analyst works with and contributes to IT, cybersecurity, infrastructure, identity and access management, vulnerability management, and audit stakeholders to help organize evidence, track action items, maintain accurate status reporting, and translate technical information into clear management-ready reporting. The ideal candidate is highly organized, analytical, comfortable learning new cybersecurity domains, and able to follow up consistently across multiple teams and deadlines.
Some of the IT Risk & Compliance Analyst responsibilities include but are not limited to:
- Maintain organized records of IT and cybersecurity risks, controls, owners, evidence requests, action items, dependencies, due dates, exceptions, and remediation status.
- Collect and validate information from control owners and technical teams to support risk reviews, control assessments, compliance activities, cybersecurity metrics, and management reporting.
- Coordinate audit response activities across internal and external auditors in multiple geographic regions and IT, security infrastructure, compliance, and business stakeholders.
- Track audit requests, evidence, responses, findings, remediation actions, retesting, risk acceptances, compensating controls, owners, deadlines, and closure; identify blockers and elevate overdue or unclear items as appropriate.
- Help IT and security teams develop clear, well-supported responses to audit findings and maintain evidence in an organized, repeatable, and auditable manner.
- Collect, organize, and analyze cybersecurity and IT risk metrics across vulnerability management, identity and access management, endpoint protection, incident response, infrastructure operations, logging, and monitoring.
- Develop accurate reports, dashboards, and management-ready summaries using tools such as Excel, PowerPoint, SharePoint, ticketing systems, and other available reporting platforms.
- Analyze trends, gaps, aging items, control exceptions, and remediation progress, and translate technical security information into business-relevant…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).