H
Huge
Posted 2 days agoVerified live 1d ago

IT Risk and Compliance Analyst

Brief overview

Remote
UndergradOr in progress
$80k–$90k/yrStated range
3+ yrsMinimum
Commercial Contract ReviewSecurity QuestionnairesVendor Due DiligenceGRCSOC 2ISO 27001NIST CSFGDPRCCPAData Privacy Compliance

Job description

Summary

Huge is an independent, human-first AI-native design and technology company. The Compliance Officer will execute and help rebuild the IT risk and compliance program, covering contracts, security questionnaires, control evidence, vendor risk, privacy, data retention, policies, incident response, and reporting.

Responsibilities

  • Review client MSAs, SOWs, DPAs, and security addenda using our contract analysis tooling; identify clauses that need Legal, IT, or Delivery attention and coordinate redlines through to signature
  • Translate signed contractual obligations (security, privacy, data handling, audit rights, breach notification, sub-processor terms) into tracked commitments and confirm they are being met operationally
  • Respond to client security questionnaires, due diligence requests, and audit inquiries; maintain the reusable answer library so responses get faster and more consistent over time
  • Collect, organize, and maintain control evidence in the GRC platform; track gap remediation against SOC 2, ISO 27001, NIST CSF, and other frameworks as they are adopted
  • Support vendor risk assessments for SaaS and AI providers: review vendor security documentation, DPAs, and sub-processor lists, and record and monitor findings in the vendor register
  • Operationalize the data retention and disposal policy: track department retention schedules, document exceptions and legal holds, and verify retention settings across platforms with IT
  • Support the privacy program including data mapping, data subject request handling, and GDPR and CCPA obligation tracking
  • Draft and maintain compliance policies, SOPs, and process documentation; keep them current, published (for internal use where applicable) and actually followed
  • Prepare risk and compliance status reporting for leadership
  • Participate in business continuity and disaster recovery planning and tabletop exercises
  • Participate in security incident response management
  • Maintain and monitor risk register and prepare for annual risk assessment
  • Administer security awareness training and track compliance
  • Support internal audits, access reviews, and periodic control testing

Skills

  • Bachelor's degree required or equivalent practical experience
  • 3–5 years of experience in compliance, GRC, contract management, privacy, or a related field
  • Hands-on experience reading and reviewing commercial contracts, ideally MSAs, DPAs, or security addenda, and working with legal counsel on redlines
  • Experience responding to client security questionnaires or vendor due diligence requests
  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, NIST CSF) and what evidence looks like in practice
  • Foundational understanding of data privacy regulations (GDPR, CCPA) and how they show up in contracts
  • Exceptional organization and follow-through; you can run many parallel threads and nothing slips
  • Clear, concise written communication; you can summarize a 40-page contract into the three things that matter
  • Comfortable working with SaaS tools and learning new platforms quickly; you like using software to make process better
  • Self-directed and effective in a small team where you own outcomes end to end

Qualifications

Must Haves

  • Bachelor's degree required or equivalent practical experience
  • 3–5 years of experience in compliance, GRC, contract management, privacy, or a related field
  • Hands-on experience reading and reviewing commercial contracts, ideally MSAs, DPAs, or security addenda, and working with legal counsel on redlines
  • Experience responding to client security questionnaires or vendor due diligence requests
  • Working knowledge of at least one major compliance framework (SOC 2, ISO 27001, NIST CSF) and what evidence looks like in practice
  • Foundational understanding of data privacy regulations (GDPR, CCPA) and how they show up in contracts
  • Exceptional organization and follow-through; you can run many parallel threads and nothing slips
  • Clear, concise written communication; you can summarize a 40-page contract into the three things that matter
  • Comfortable working with SaaS tools and learning new platforms quickly; you like using software to make process better
  • Self-directed and effective in a small team where you own outcomes end to end

Benefits

  • This position is remote within the United States.

More jobs like this