
Risk and Compliance Associate
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in New York.
• Standardize, format, and transform legacy documentation and templates utilizing Microsoft Word.
• Oversee documentation requests, perform intake, draft documents, and clarify any ambiguous instructions.
• Evaluate policies, plans, and procedures for logical inconsistencies, outdated parameters, and compliance misalignments.
• Map and confirm procedure integrity from business objectives through evidence generation.
• Manage the Document Control Master List, file naming conventions, and version control.
• Oversee annual document revision cycles and report on active document queues.
• Schedule and engage in post-implementation reviews following major document releases.
• Intake, triage, prioritize, and route internal and external security, compliance, and regulatory requests.
• Draft initial responses to client security and compliance questionnaires utilizing GRC systems and answer libraries.
• Maintain queue reports for support tickets and questionnaires to ensure SLA compliance.
• Log non-conformances and corrective actions, coordinate NCAR forms, and track remediation until closure.
• Gather, validate, consolidate, and report KPI and metric data.
• Coordinate quarterly Management Review Meetings, prepare 2–3 presentation slides, and monitor action items.
• Administer annual Conflict of Interest disclosures and Remote Worksite Evaluation Checklists.
• Manage the GDPR Data Subject Request queue and ensure monitoring of statutory SLAs.
• Support vendor risk onboarding, questionnaires, completeness reviews, and updates to the risk-register.
• Coordinate internal audits, prepare checklists, take minutes, and log findings.
• Bachelor’s degree or equivalent practical experience.
• 1–3 years of experience in a highly organized administrative-control capacity.
• Proven ability to work independently and communicate proactively in a fully remote, Virtual-First setting.
• Direct experience in security, compliance, legal, or IT auditing is preferred.
• Familiarity with ISO 9001, ISO 27001, ISO 20000-1, HITRUST CSF, HIPAA, NIST, or GDPR is preferred.
• Experience with GRC platforms such as Thoropass or ticketing tools like Jira and Confluence is preferred.
• Advanced proficiency in Microsoft Word and Google Workspace.
• Ability to design, style, template, and review complex documents using style sheets, headers/footers, section breaks, and tracked changes.
• Exceptional attention to detail regarding document, data, acronym, and cross-reference accuracy.
• Capacity to execute structured, multi-step procedures and track evidence from start to finish.
• Excellent time management skills across multiple GRC queues and compliance schedules.
• Maintain confidentiality and professionalism when managing sensitive HR, legal, financial, and regulatory records.
• Ability to conduct independent data mining, research, and analysis.
• Capacity to work at a computer for extended durations.
• Strong communication skills via video conferencing, chat, and telephone.
• Ability to manage multiple tasks in a self-directed remote environment.
• Ability to occasionally lift and carry equipment such as a company-issued laptop.
• Four health plan options.
• 401(k) matching.
• Flexible Paid Time Off (PTO).
• Wellness programs.
• Financial planning services.
• Fully remote work from a home office or other approved remote location.
• Occasional travel for company meetings or professional development events.
• Mentorship and career development opportunities.
• Knowledge-sharing and a collaborative team environment.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.