Jobs
>
Chicago

    IT Governance Analyst Remote - Chicago, IL, United States - U of C NORC

    Default job background
    Description
    JOB DESCRIPTION:

    NORC at the University of Chicago seeks an IT Governance Analyst to join our growing Information Technology Department. The successful candidate will be responsible for the development, implementation, and maintenance of IT security policies, procedures, and frameworks, as well as technical documentation to support IT governance initiatives. This role involves writing and updating clear and comprehensive documentation, including policies, SOPs, framework documentation, training materials, and reports. The incumbent collaborates with cross-functional teams to ensure documentation is accurate, accessible, and aligned with regulatory requirements and industry standards. Additionally, the role involves providing technical writing support for IT security frameworks, metrics, compliance documentation, risk assessments, and incident response procedures. The IT Governance Analyst plays a crucial role in enhancing IT security awareness, ensuring compliance, mitigating risks, and driving continuous improvement in the organization's security posture.

    DEPARTMENT: Information Technology

    NORC's Information Technology program provides technology services to our staff and clients. Given the critical role technology plays in our day-to-day lives, we are committed to providing professional, high-quality solutions in order to further our collective goal of advancing social science research.​

    RESPONSIBILITIES:
    • Policy Development: Develop and maintain comprehensive IT security policies, standard operating procedures (SOPs), and guidelines in alignment with industry best practices, regulatory requirements, and organizational objectives. Ensure documentation is clear, concise, and easily understandable.
    • SOP Creation: Write and update detailed standard operating procedures (SOPs) for IT security processes, ensuring clarity, effectiveness, and adherence to compliance standards. Translate technical information into user-friendly documentation.
    • Procedure Documentation: Document IT security procedures, workflows, and protocols to streamline operations and facilitate consistent execution across the organization. Ensure documentation is accessible and well-organized.
    • Framework Review: Evaluate existing IT security frameworks such as the NIST Cybersecurity Framework, ISO 27001, HIPAA and HITRUST, to assess their effectiveness, relevance, and suitability for the organization's needs. Provide technical writing support for framework documentation and customization.
    • Framework Customization: Customize and tailor IT security frameworks to fit the specific requirements and risk profile of the organization, ensuring maximum effectiveness and efficiency. Document customization processes and rationale.
    • Metric Development: Design, develop, and implement key performance indicators (KPIs) and metrics to measure the effectiveness of IT security controls, processes, and policies. Create documentation explaining metric definitions and calculation methodologies.
    • Metric Tracking: Regularly monitor and track IT security metrics and performance indicators, analyzing trends, identifying areas for improvement, and providing actionable management insights. Produce reports summarizing metric trends and analysis.
    • Report Generation: Prepare monthly, quarterly, and annual reports on IT security metrics, incidents, compliance status, and risk posture for presentation to senior management, stakeholders, and regulatory bodies. Ensure reports are well-written and visually appealing.
    • Training and Awareness: Develop and deliver IT security awareness training programs and materials for employees to enhance their understanding of security policies, procedures, and best practices. Create training materials and user guides.
    • Continuous Improvement: Continuously assess and improve IT governance processes, policies, and procedures based on emerging threats, industry trends, and organizational feedback. Document process improvements and best practices.
    REQUIRED SKILLS:
    • Current security compliance certification such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC) or System Security Certified Practitioner (SSCP)
    • At least 5 years of experience in IT security, Policy, and SOP writing.
    • Proficiency in writing clear, concise, and technically accurate documentation, including policies, procedures, standards, and guidelines.
    • Understanding of fundamental cybersecurity principles, including threats, vulnerabilities, and risk mitigation strategies.
    • Experience with creating and maintaining IT audit control processes to assess the suitability and applicability of technical, managerial, and operational security controls against security and regulatory frameworks
    • Experience with GRC (Governance, Risk, and Compliance) systems or IRM (Information Risk Management) systems for tracking and monitoring multiple systems and assessments against multiple frameworks
    • In-depth understanding of information security practices at all layers of the IT infrastructure, to include network, servers, databases, and applications
    • General understanding of IT infrastructure, operating systems, database, and application operations Previous experience in the advanced use of information security assessment techniques (e.g., vulnerability scanning, penetration testing, verification of application security, etc.)
    • Previous experience working with the HIPAA Security and Privacy Rules, as well as the HITRUST Common Security Framework (CSF)
    • MUST HAVE Experience with HIPPA, NIST, ISO 27001, and HITRUST including but not limited to the review and development of security documentation and templates such as Policies, SOPs, and Procedures.
    • Excellent verbal and written communication skills
    • Familiarity with documentation tools and software, such as Microsoft Office Suite, Adobe Acrobat, markdown languages, etc., to create and maintain documentation effectively.
    • Preferred but not required: Bachelor's degree in management information systems, Computer Science.
    SALARY AND BENEFITS:

    The pay range for this position is $94,000 – $140,000 .

    This position is classified as regular. Regular staff are eligible for NORC's comprehensive benefits program. Benefits include, but are not limited to:

    • Generously subsidized health insurance, effective on the first day of employment
    • Dental and vision insurance
    • A defined contribution retirement program, along with a separate voluntary 403(b) retirement program
    • Group life insurance, long-term and short-term disability insurance
    • Benefits that promote work/life balance, including generous paid time off, holidays; paid parental leave, tuition assistance, and an Employee Assistance Program (EAP).

    NORC's Approach to Equity and Transparency

    Pay and benefits transparency helps to reduce wage gaps. As part of our commitment to pay equity and salary transparency, NORC includes a salary range for each job opening along with information about eligible benefit offerings. At NORC, we take a comprehensive approach to setting salary ranges and reviewing raises and promotions, which is overseen by a formal Salary Review Committee (SRC).

    WHAT WE DO:

    NORC at the University of Chicago is an objective, non-partisan research institution that delivers reliable data and rigorous analysis to guide critical programmatic, business, and policy decisions. Since 1941, our teams have conducted groundbreaking studies, created and applied innovative methods and tools, and advanced principles of scientific integrity and collaboration. Today, government, corporate, and nonprofit clients around the world partner with us to transform increasingly complex information into useful knowledge.

    WHO WE ARE:

    For over 80 years, NORC has evolved in many ways, moving the needle with research methods, technical applications and groundbreaking research findings. But our tradition of excellence, passion for innovation, and commitment to collegiality have remained constant components of who we are as a brand, and who each of us is as a member of the NORC team. With world-class benefits, a business casual environment, and an emphasis on continuous learning, NORC is a place where people join for the stellar research and analysis work for which we're known, and stay for the relationships they form with their colleagues who take pride in the impact their work is making on a global scale.

    EEO STATEMENT:

    NORC is an affirmative action, equal opportunity employer that values and actively seeks diversity in the workforce. NORC evaluates qualified applicants without regard to race, color, religion, sex, national origin, disability, status as a protected veteran, sexual orientation, gender identity, and other legally protected characteristics.



  • Apex Systems Chicago, United States

    Contract Analyst - Vendor Management · Large Financial Client · Duration: 7+ months · 100% Remote · Apex Systems is looking for aContract Analyst, to join our fast growing Financial Services Client. · Job Description · We are actively seeking a Contract Analyst - Vendor Mana ...


  • NORC Chicago, United States

    IT Governance Analyst Remote · Job no: Work type: Regular Full-Time Location: Chicago – 55 East Monroe Street, IL Capability Area: IT Security · JOB DESCRIPTION: · NORC at the University of Chicago seeks an IT Governance Analyst to join our growing Information Technology Departme ...


  • Vyaire Medical Chicago, United States

    REMOTE Senior Analyst, Sales Operations - Respiratory Diagnostics · Help the World Breathe Easier by Collaborating with Innovative Vyaire Employees Around the World · As a global leader in respiratory care, we know what we do enables, improves and extends lives. We are a young ...


  • United Airlines Chicago, United States

    Connecting People. Uniting the World. Theres never been a more exciting time to join United Airlines As a global company that operates in hundreds of locations around the world with millions of customers and tens of thousands of employees we have a unique responsibility to uplift ...


  • Collabera Chicago, United States

    Job Description · Job DescriptionPay rate: $60/hr. - $68/hr. · Experience in implementation and maintenance of cross functional systems for operations in areas such as procurement, contracts, commissions or other financial systems. Experience with procurement, Ironclad, and SAP C ...


  • Aledade Chicago, United States Full time

    Aledade is actively recruiting a Treasury Analyst with a responsibility for cash forecasting, data management, analytics and modeling, covenant reporting, procedures management and other projects as assigned. This role will also assist in the administration of the company's banki ...


  • onShore Chicago, United States

    onShore Security, a 25-year-old firm specializing in managed security services. We are a business casual work environment with strong ties to the Open Source software community. Our talented and passionate team provides reliable technical support and high-tech solutions for any i ...


  • The Jacobson Group Chicago, United States

    Job Description · Job Description · Remote, consulting, pricing configuration analyst opportunity · Our client is looking to add a Senior Pricing Configuration Analyst to join their team for a 3-month long contracting position. · This is a fully remote position, starting in ea ...


  • Global Channel Management Chicago, United States

    Experienced Remote Procurement Supplier Analyst Opportunity · Are you an experienced professional in procurement and supplier management? We are seeking a Remote Procurement Supplier Analyst with 2+ years of relevant experience to join our team. This remote position is based in ...


  • Global Channel Management, Inc Chicago, United States

    Remote Procurement Supplier Analyst needs 2+ years experience · Remote Procurement Supplier Analyst requires: · Remote in Chicago, IL · Excellent customer service and relationship building skills. · Compliance Federal, and State policies and regulations. · Supply · Procurement ...


  • Boston Consulting Group Chicago, IL, United States

    Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitiv ...


  • EDI Staffing Chicago, United States

    Responsibilities: Implement EDI transaction sets with trading partners to improve operational efficiencies. · Collaborate with business partners to implement electronic business transactions (EDI) · Participate in meetings with trading partners to explain EDI capabilities and ...


  • The Midtown Group Chicago, United States

    Job Description · Job DescriptionOur technology solutions client is hiring a remote ThoughtSpot Analyst/Developer at $57/hour (W2) to support their office in Chicago, IL. · Responsibilities: · - Perform development as a ThoughtSpot SME. · - Provide strong data ETL processes and ...


  • United Airlines Chicago, United States

    Connecting People. Uniting the World. There's never been a more exciting time to join United Airlines As a global company that operates in hundreds of locations around the world — with millions of customers and tens of thousands of employees — we have a unique responsibility to u ...


  • United Airlines Chicago, United States

    Job Description · Description · Connecting People. Uniting the World. There's never been a more exciting time to join United Airlines As a global company that operates in hundreds of locations around the world — with millions of customers and tens of thousands of employees — we h ...


  • Vyaire Medical Chicago, United States

    REMOTE Senior Analyst, Sales Operations - Respiratory DiagnosticsHelp the World Breathe Easier by Collaborating with Innovative Vyaire Employees Around the WorldAs a global leader in respiratory care, we know what we do enables, improves and extends lives. We are a young company ...


  • Insight Global Chicago, United States

    Job Description · This Data Analyst will be working in the US Deposits, Strategy and Analytics group of this global bank. They will make sure that their automated SAS jobs on production servers run and complete. Communicating with the product managers when they have questions, or ...


  • United Airlines Chicago, United States

    Connecting People. · Are you ready to apply Make sure you understand all the responsibilities and tasks associated with this role before proceeding. · Uniting the World. · There's never been a more exciting time to join United Airlines As a global company that operates in hund ...


  • Reyes Beer Division Des Plaines, United States

    Pay Transparency Statement: · The compensation philosophy reflects the Company's reasonable expectation at the time of posting. We consider a number of factors when making individual compensation decisions including, but not limited to, skill sets, experience and training, and o ...


  • Maximus Chicago, United States Full time

    Description & Requirements · The Clinical Quality Analyst will support the IL SALT program by completing both retrospective QA of the SMHRF CSR as well as onsite QA of each staff member on a quarterly basis. The incumbent participates in the ongoing operation of an effective qual ...