IT Governance Analyst

2 weeks ago


Chicago, United States NORC at the University of Chicago Full time

**JOB DESCRIPTION**:
**DEPARTMENT: Information Technology**

NORC's Information Technology program provides technology services to our staff and clients. Given the critical role technology plays in our day-to-day lives, we are committed to providing professional, high-quality solutions in order to further our collective goal of advancing social science research.

**RESPONSIBILITIES**:

- **Policy Development**: Develop and maintain comprehensive IT security policies, standard operating procedures (SOPs), and guidelines in alignment with industry best practices, regulatory requirements, and organizational objectives. Ensure documentation is clear, concise, and easily understandable.
- **SOP Creation**: Write and update detailed standard operating procedures (SOPs) for IT security processes, ensuring clarity, effectiveness, and adherence to compliance standards. Translate technical information into user-friendly documentation.
- **Procedure Documentation**: Document IT security procedures, workflows, and protocols to streamline operations and facilitate consistent execution across the organization. Ensure documentation is accessible and well-organized.
- **Framework Review**: Evaluate existing IT security frameworks such as the NIST Cybersecurity Framework, ISO 27001, HIPAA and HITRUST, to assess their effectiveness, relevance, and suitability for the organization's needs. Provide technical writing support for framework documentation and customization.
- **Framework Customization**: Customize and tailor IT security frameworks to fit the specific requirements and risk profile of the organization, ensuring maximum effectiveness and efficiency. Document customization processes and rationale.
- **Metric Development**: Design, develop, and implement key performance indicators (KPIs) and metrics to measure the effectiveness of IT security controls, processes, and policies. Create documentation explaining metric definitions and calculation methodologies.
- **Metric Tracking**: Regularly monitor and track IT security metrics and performance indicators, analyzing trends, identifying areas for improvement, and providing actionable management insights. Produce reports summarizing metric trends and analysis.
- **Report Generation**: Prepare monthly, quarterly, and annual reports on IT security metrics, incidents, compliance status, and risk posture for presentation to senior management, stakeholders, and regulatory bodies. Ensure reports are well-written and visually appealing.
- **Training and Awareness**: Develop and deliver IT security awareness training programs and materials for employees to enhance their understanding of security policies, procedures, and best practices. Create training materials and user guides.
- **Continuous Improvement**: Continuously assess and improve IT governance processes, policies, and procedures based on emerging threats, industry trends, and organizational feedback. Document process improvements and best practices.

**REQUIRED SKILLS**:

- Current security compliance certification such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC) or System Security Certified Practitioner (SSCP)
- At least 5 years of experience in IT security, Policy, and SOP writing.
- Proficiency in writing clear, concise, and technically accurate documentation, including policies, procedures, standards, and guidelines.
- Understanding of fundamental cybersecurity principles, including threats, vulnerabilities, and risk mitigation strategies.
- Experience with creating and maintaining IT audit control processes to assess the suitability and applicability of technical, managerial, and operational security controls against security and regulatory frameworks
- Experience with GRC (Governance, Risk, and Compliance) systems or IRM (Information Risk Management) systems for tracking and monitoring multiple systems and assessments against multiple frameworks
- Previous experience working with the HIPAA Security and Privacy Rules, as well as the HITRUST Common Security Framework (CSF)
- MUST HAVE Experience with HIPPA, NIST, ISO 27001, and HITRUST including but not limited to the review and development of security documentation and templates such as Policies, SOPs, and Procedures.
- Excellent verbal and written communication skills
- Familiarity with documentation tools and software, such as Microsoft Office Suite, Adobe Acrobat, markdown languages, etc., to create and maintain documentation effectively.
- Preferred but not required: Bachelor’s degree in management information systems, Computer Science.

**SALARY AND BENEFITS**:
The pay range for this position is **$94,000 - $140,000**.

This position is classified as regular. Regular staff are eligible for NORC’s comprehensive benefits program. Benefits include, but are not limited to:

- Generously subsidized health insurance, effective on the first day of employme



  • Chicago, United States The Judge Group Full time

    Our client is looking for a Data Governance Technical Analyst This is a long term contract that must be done hybrid in ChicagoResponsibilities: Responsible for gathering business and technical requirements to capture metadata and lineage working with Business and Technical SMEs.Lead Data Domain and Data Steward Workgroup meetingsWork closely with Data Domain...


  • Chicago, United States The Judge Group Full time

    Our client is looking for a Data Governance Technical Analyst This is a long term contract that must be done hybrid in ChicagoResponsibilities: Responsible for gathering business and technical requirements to capture metadata and lineage working with Business and Technical SMEs.Lead Data Domain and Data Steward Workgroup meetingsWork closely with Data Domain...


  • Chicago, United States The Fountain Group Full time

    100% Remote role, no expectation of onsite work. W2 Candidates only, C2C not possible. Description Seeking Data and Information Governance Analyst to be part of its Privacy and Data Protection team. The individual will assist the Data Management Lead and the Sr. Manager, Information Governance in continuing to enhance the policies, procedures and execution...

  • GRC Analyst

    2 weeks ago


    Chicago, United States 1872 Consulting Full time

    GRC Analyst - Information Governance Focus Chicago, IL - 3 days onsite in the loop, 2 days WFH Summary The GRC Analyst focuses on information governance, compliance assessments, DLP, records/data retention, technical projects related to records/data management, insider threat and other similar areas. You will play a key role in optimizing data management...


  • Chicago, United States Spectraforce Technologies Full time

    Role: SOC Governance Analyst Duration: 6+ Months (possible extension) Work Location: Tempe, AZ or Chicago, ILThe SOC Governance team is a small but highly performing team at the client, responsible for the governance around the suite of our SOC reports. The team does not perform testing.The team works with business and technology owners throughout the...


  • Chicago, United States CareerAddict Full time

    Senior Analyst - Information Governance/Data Protection Salary: Open + Bonus Location: Chicago, IL Hybrid: 3 days on-site, 2 days remote *We are unable to provide sponsorship for this role* Qualifications Bachelor's degree 5+ years of applicable work experience Previous work with information or data governance control activities in the financial services...

  • Benefits Analyst

    3 weeks ago


    Chicago, United States Solve IT Strategies, Inc. Full time

    Solve IT Strategies is looking for a Benefits Analyst . This role is laocated at Chicago, IL.CONTRACT 5 months.Schedule: 40 hours/week, 8-5 pm M-F Onsite The Main Responsibilities of a person are: Administering benefits, leave of absence (LOA), and workers’ compensation processes. Reporting benefits plan information to upper management. Holding meetings...

  • Benefits Analyst

    2 weeks ago


    Chicago, United States Solve IT Strategies, Inc. Full time

    Job DescriptionJob DescriptionSolve IT Strategies is looking for a Benefits Analyst . This role is laocated at Chicago, IL. CONTRACT 5 months. Schedule: 40 hours/week, 8-5 pm M-F OnsiteThe Main Responsibilities of a person are:Administering benefits, leave of absence (LOA), and workers' compensation processes.Reporting benefits plan information to upper...

  • Benefits Analyst

    1 month ago


    Chicago, United States Solve IT Strategies, Inc. Full time

    Job DescriptionJob DescriptionSolve IT Strategies is looking for a Benefits Analyst . This role is laocated at Chicago, IL. CONTRACT 5 months. Schedule: 40 hours/week, 8-5 pm M-F OnsiteThe Main Responsibilities of a person are:Administering benefits, leave of absence (LOA), and workers' compensation processes.Reporting benefits plan information to upper...


  • Chicago, United States Request Technology, LLC Full time

    Senior Analyst – Information Governance/Data ProtectionSalary: Open + BonusLocation: Chicago, ILHybrid: 3 days on-site, 2 days remote*We are unable to provide sponsorship for this role*QualificationsBachelor's degree5+ years of applicable work experiencePrevious work with information or data governance control activities in the financial services...


  • Chicago, United States Request Technology, LLC Full time

    Senior Analyst – Information Governance/Data ProtectionSalary: Open + BonusLocation: Chicago, ILHybrid: 3 days on-site, 2 days remote*We are unable to provide sponsorship for this role*QualificationsBachelor's degree5+ years of applicable work experiencePrevious work with information or data governance control activities in the financial services...


  • Chicago, United States Request Technology, LLC Full time

    Senior Analyst – Information Governance/Data ProtectionSalary: Open + BonusLocation: Chicago, ILHybrid: 3 days on-site, 2 days remote*We are unable to provide sponsorship for this role*QualificationsBachelor's degree5+ years of applicable work experiencePrevious work with information or data governance control activities in the financial services...


  • Chicago, United States Careeraddict Full time

    *Position is bonus eligible* Prestigious Financial Company is currently seeking an Information Data Governance and Protection Analyst. Candidate will be responsible for supporting the development and implementation of the information governance, data protection, and privacy program. This includes supporting the development of strategies, policies,...


  • Chicago, United States Request Technology, LLC Full time

    ***Position is bonus eligible***Prestigious Financial Company is currently seeking an Information Data Governance and Protection Analyst. Candidate will be responsible for supporting the development and implementation of the information governance, data protection, and privacy program. This includes supporting the development of strategies, policies,...


  • Chicago, United States Request Technology, LLC Full time

    ***Position is bonus eligible***Prestigious Financial Company is currently seeking an Information Data Governance and Protection Analyst. Candidate will be responsible for supporting the development and implementation of the information governance, data protection, and privacy program. This includes supporting the development of strategies, policies,...


  • Chicago, United States Request Technology Full time

    Senior Analyst – Information Governance/Data Protection Salary: Open + Bonus Location: Chicago, IL Hybrid: 3 days on-site, 2 days remote *We are unable to provide sponsorship for this role* Ready to make your application Please do read through the description at least once before clicking on Apply. Qualifications Bachelor's degree 5+ years of applicable...


  • Chicago, United States GoHealth Full time

    GoHealth Intro: As a leading health insurance marketplace, Go Healths mission is to improve access to healthcare in America. For customers, enrolling in a health insurance plan is confusing and difficult, and seemingly small differences between plan Senior Analyst, Risk, Compliance, Analyst, Health, Evaluation

  • Business Analyst

    4 weeks ago


    Chicago, Illinois, United States Midwestern IT Full time

    Jr Business Analyst Full Time Phone Interview ResponsibilitiesProvide expertise in a focused area of the business through analysis and understanding of business needs. Apply fundamental knowledge of a business area's processes and practices. Provide business knowledge and support for resolving technical issues in their focused areas of the business. Use...


  • Chicago, United States Optimum Healthcare IT Full time

    Entry Level Healthcare IT AnalystStart Your Career in Healthcare Information Technology Today!Getting your first job can be difficult when employers want experience, but to gain that experience, you need your first job. We bridge the gap between your education and professional career by helping you gain the experience and training you need within the...


  • Chicago, United States Optimum Healthcare IT Full time

    Entry Level Healthcare IT AnalystStart Your Career in Healthcare Information Technology Today!Getting your first job can be difficult when employers want experience, but to gain that experience, you need your first job. We bridge the gap between your education and professional career by helping you gain the experience and training you need within the...