IT Governance Analyst
Reference Number: 406985
Posted: 08/04/2026
Job Type: Contract
- Industry: Technology and IT
Title: IT Governance Analyst
Location: Remote (28 approved states)
Type: Contract
Rate: $40/hour
Job Description
Assists in the development, maintenance, and ongoing improvement of the IT governance, risk management, and IT controls framework, including supporting processes and documentation. Assists with annual SOC audits, internal audit engagements, security governance activities, third-party risk management processes, and the tracking of audit findings, risk mitigation efforts, and security exceptions. Supports business partners in identifying and documenting IT controls, maintaining risk documentation, and responding to security-related requests.
What You'll Do
- Assists with the identification, documentation, and assessment of IT and security risks across the organization.
- Provides support to business owners and technology teams to increase awareness and understanding of IT controls, risks, and governance requirements.
- Assists in the development, assessment, and monitoring of mitigation plans for IT-related and enterprise risks to ensure they are managed to an acceptable level.
- Supports internal and external audit engagements, including annual SOC audits, by gathering evidence, coordinating requests, and tracking remediation activities.
- Assists with the tracking and reporting of audit findings, control deficiencies, security exceptions, and risk remediation efforts.
- Supports the completion of third-party security questionnaires and other vendor risk management activities.
- Assists in the review, documentation, and processing of security exception requests.
- Works with business areas and process owners to identify, document, and maintain IT controls and related governance documentation.
- Assists business partners with updates and responses related to enterprise and IT risk mitigation activities.
- Helps document and maintain records of tactical IT risks and escalates issues as appropriate.
- Develops and maintains processes and procedures to ensure governance and risk documentation is properly maintained in accordance with company policies, industry standards, and regulatory requirements.
- Aids in developing and implementing plans and guidance (which may include formal and informal training) to increase awareness about IT governance, risk management, and security practices.
What You Bring
- Bachelor's degree or advanced degree (where required)
- 1-3 years of experience in IT audit, IT controls, IT risk management, cybersecurity, security operations, compliance, or a related field
- In lieu of degree, 4+ years of experience in a related field
- Foundational understanding of IT controls, risk management principles, and cybersecurity concepts
- Strong organizational, documentation, and communication skills
Bonus Points
- Experience supporting SOC audits, internal audit engagements, or compliance assessments
- Exposure to security operations, incident management, vulnerability management, or security governance activities
- Experience responding to third-party security questionnaires and supporting vendor risk management processes
- Control design and documentation, including process mapping and governance
- Familiarity with NIST, COBIT, ISO 27001, or similar control and risk frameworks
- Experience with Governance, Risk, and Compliance (GRC) tools
- Security+, CISA, CRISC, CISM, or related certifications preferred
CONSULTANT TESTIMONIAL
An Experis consultant
"Communication, instructions, expectations and follow-through were exceptional, throughout the hiring, interviewing and onboarding process. Thank you, Experis!"

