JOB SUMMARY: NORC at the University of Chicago is seeking an IT Risk & Compliance Analyst to join our DSS Security & Compliance team. This role is primarily responsible for supporting NORC's FedRAMP Continuous Monitoring Program, ensuring the ongoing effectiveness of security controls and maintaining compliance with FedRAMP requirements. Working closely with engineering, cloud operations, infrastructure, development, and business teams, the analyst will help assess security control effectiveness, coordinate compliance activities, collect and validate evidence, track remediation efforts, and support ongoing audit readiness. In addition to FedRAMP, the role supports NORC's enterprise governance, risk, and compliance (GRC) program across NIST SP 800-53 Rev. 5, CMMC, ISO 27001, SOC 2, HIPAA, and customer-specific security requirements. The successful candidate will contribute to the continued maturity of NORC's security compliance program by improving continuous monitoring processes, strengthening governance practices, developing compliance metrics, and identifying opportunities to automate and streamline compliance activities. Citizenship: U.S. Citizenship required due to federal project requirements. DEPARTMENT: Digital Data Services & Solutions (DDS) NORC's Digital Services & Solutions (DSS) organization provides enterprise technology services that enable research, innovation, and client success. The Security & Compliance team partners across the organization to strengthen cybersecurity, reduce organizational risk, and maintain compliance with government, client, and industry security requirements. RESPONSIBILITIES: Serve as a primary contributor to NORC's FedRAMP Continuous Monitoring Program, coordinating recurring activities required to maintain FedRAMP authorization. Coordinate monthly, quarterly, annual, and ongoing FedRAMP Continuous Monitoring activities, including evidence collection, security control assessments, vulnerability management, POA&M management, metrics reporting, and security documentation updates. Monitor the effectiveness of administrative, technical, and operational security controls across cloud and enterprise environments. Partner with engineering, cloud, infrastructure, and operations teams to validate security controls, resolve compliance findings, and improve overall security posture. Track security findings, vulnerabilities, and remediation efforts to ensure compliance with FedRAMP and other applicable security requirements. Develop, review, validate, and maintain security documentation, including policies, standards, procedures, System Security Plans (SSPs), control implementation statements, and supporting compliance evidence. Support internal and external audits by coordinating evidence requests, responding to assessor questions, and managing remediation activities. Assist in developing compliance dashboards, metrics, and executive reporting that measure security posture, control effectiveness, and continuous monitoring performance. Support governance and compliance initiatives across NIST SP 800-53 Rev. 5, CMMC, ISO 27001, SOC 2, HIPAA, and customer-specific requirements. Identify opportunities to improve compliance processes through automation, standardization, and continuous improvement. Provide guidance to technical and business teams regarding security requirements, compliance obligations, and cybersecurity best practices. Support Authorization to Operate (ATO) activities, annual assessments, and significant system changes as needed. REQUIRED SKILLS: Education & Certifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent professional experience). CAP, CGRC, CISSP, CISM, CISA or other cybersecurity certification preferred. 1. FedRAMP Continuous Monitoring & Compliance (Primary Focus) Minimum of two years of experience supporting cybersecurity, governance, risk, or compliance programs. Experience supporting or maintaining a Fe
Not specified in the original listing.
Not specified in the original listing.