Risk & Compliance Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

Bennett Thrasher · 2 days ago

Risk & Compliance Analyst

Bennett Thrasher is a premier provider of professional tax, assurance, and consulting services to businesses and high net worth individuals. They are seeking a highly skilled and motivated Risk & Compliance Analyst to ensure the organization's data policies, procedures, and standards follow regulatory requirements and industry best practices.

ConsultingInformation Technology
check
Growth Opportunities

Responsibilities

Develop, implement, and maintain data governance frameworks, policies, and standards to ensure data quality and integrity
Identify, assess, and manage data-related risks to protect the organization’s data assets
Ensure compliance with data protection regulations such as GDPR, CCPA, and other relevant legislation
Conduct regular audits and monitoring activities to identify control gaps and ensure compliance with data governance policies and standards
Provide training and raise awareness on data governance, risk management, and compliance within the organization
Work closely with data owners, IT, legal, and departments to ensure alignment and support for data governance initiatives
Directly oversee annual SOC1/SOC2 reviews, as well as managing compliance with GLBA and GDPR
Coordinate with internal and external auditors during compliance reviews
Complete security questionnaires for prospective and existing clients
Assist in developing and updating privacy and compliance policies, procedures, and training materials
Deliver training and awareness sessions to internal teams
Perform internal information risk classification and maintain inventories of sensitive data
Review application requests for data privacy and security risks
Implement processes to automate and continuously monitor information security controls, exceptions, risks, testing
Develop and implement controls and processes through frameworks like NIST, COSO, COBIT, etc
Develop reporting metrics, dashboards, and evidence artifacts
Conduct and manage end-to-end vendor security risk assessments
Review third-party security documentation (e.g., SOC 2 reports, ISO 27001 certifications)
Assess new software for security and privacy risks and recommend appropriate contract terms

Qualification

Data GovernanceRisk ManagementCompliance RegulationsCybersecurity FrameworksData Protection RegulationsAnalytical SkillsMicrosoft PurviewProfessional CertificationsProblem-Solving SkillsCommunication Skills

Required

Bachelor's degree in information technology, Business Administration, or related field
Minimum of 3-5 years of experience in data governance, risk management, and compliance roles
Experience with cybersecurity frameworks such as NIST CSF, ISO 27001, or Secure Controls Framework (SCF)
Strong knowledge of data protection regulations (e.g., GDPR, CCPA)
Excellent analytical, problem-solving, and communication skills
Ability to work independently and collaboratively with cross-functional teams

Preferred

Experience with Microsoft Purview or similar data governance tools is a plus
Professional certifications such as SSCP, CISM, CIPP, CIPM, or CRISC are a plus

Company

Bennett Thrasher

twittertwittertwitter
company-logo
Bennett Thrasher is the eighth largest Atlanta-based full-service certified public accounting and consulting firm.

Funding

Current Stage
Growth Stage

Leadership Team

leader-logo
Ken Thrasher
Co-Founder
linkedin
leader-logo
Richard A. Bennett
Co-Founder
linkedin
Company data provided by crunchbase