IT Risk and Compliance Specialist - Hybrid Washington DC Office or Remote

JOB SUMMARY: NORC at the University of Chicago is seeking a seasoned IT Risk and Compliance Specialist to join our Information Technology Department within the DSS Security and Compliance team. This critical role will focus on driving the organization’s adherence to complex regulatory frameworks, with particular emphasis on FedRAMP, CMMC, NIST 800-171, and ISO 27001. The ideal candidate will bring a wealth of experience in auditing, risk management, and compliance within high-stakes environments, particularly for Government security standards. Preferably, this position will have a hybrid work schedule of one or two days a week in either our Washington, DC or Chicago, IL office. Remote applicants may also be considered. DEPARTMENT: DSS Security and Compliance Technology is integral to NORC’s mission of advancing social science research. The IT department delivers innovative, high-quality solutions that support both our staff and clients, ensuring the highest standards of security and compliance. RESPONSIBILITIES: • * Lead comprehensive internal and external IT compliance audits, ensuring alignment with critical security standards such as FedRAMP, CMMC, NIST 800-171, and ISO 27001. • * Execute in-depth risk assessments and security impact analyses of information systems, identifying potential vulnerabilities and proposing mitigation strategies. • * Develop, review, and manage key audit documentation, including the creation of corrective action and remediation plans to address identified deficiencies. • * Oversee and ensure continuous compliance with contract requirements, with a focus on tracking and reporting the progress of Corrective Action Plans (CAPs). • * Collaborate closely with Security Engineers and stakeholders to remediate compliance issues, ensuring alignment with regulations such as FISMA, Section 508, NIST SP 800-53, HITRUST, and HIPAA Security & Privacy standards. • * Design, implement, and optimize policies, procedures, and automated processes for compliance in hybrid and multi-tenant infrastructures. • * Provide mentorship and strategic guidance to IT teams, translating complex regulatory requirements into actionable technical steps for seamless compliance execution. • * Foster strong, collaborative relationships with NORC’s research community and other key stakeholders, facilitating a culture of compliance and security. • REQUIRED SKILLS: • * Bachelor’s Degree in Management Information Systems, Computer Science, Business Administration, or a related field. Or equivalent experience in IT security, risk, or compliance may be considered. • * Current certifications in IT security compliance, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC). • * Minimum of 6+ years of experience in IT security auditing, risk assessment, or compliance, with a primary focus on government security frameworks and contracts. • * Proven expertise in auditing IT systems for compliance with security frameworks, including preparing and reviewing System Security Plans (SSPs), Corrective Action Plans (CAPs), and Contingency Plans. • * Proficiency in Governance, Risk, and Compliance (GRC) or Information Risk Management (IRM) systems, with a track record of managing compliance across multiple frameworks, including FedRAMP, NIST, and ISO standards. • * Deep knowledge of information security protocols across infrastructure layers, including networks, servers, databases, and applications, with hands-on experience in advanced security assessment techniques. • * Experience managing compliance in hybrid and multi-tenant infrastructures, with strong familiarity with privacy regulations such as GDPR, CCPA/CPRA, and the HIPAA Privacy Rule. • * Extensive experience in the implementation and oversight of frameworks such as FedRAMP, CMMC, NIST 800-171, ISO 27001, and HITRUST. • Qualified applicants must be eligible to work in the U.S. We regret that we are unable to offer visa sponsorship for this position. SALARY AND BENEFITS: The pay range for this position is $110,000 – $165,000. This position is classified as regular. Regular staff are eligible for NORC’s comprehensive benefits program. Benefits include, but are not limited to: • Generously subsidized health insurance, effective on the first day of employment • * Dental and vision insurance • * A defined contribution retirement program, along with a separate voluntary 403(b) retirement program • * Group life insurance, long-term and short-term disability insurance • * Benefits that promote work/life balance, including generous paid time off, holidays; paid parental leave, bereavement leave, tuition assistance, and an Employee Assistance Program (EAP). • NORC’s Approach to Equity and Transparency Pay and benefits transparency helps to reduce wage gaps. As part of our commitment to pay equity and salary transparency, NORC includes a salary range for each job opening a

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...