IT SOX/GRC Compliance Analyst (SOX IT/ HIPAA / Zilla / ITIL) Remote Contract-to-Hire
Quick Overview
Job Description
IT SOX/GRC Compliance Analyst (SOX IT/ HIPAA / Zilla / ITIL) Remote Contract-to-Hire
Location: 100% Remote (U.S.) Employment Type: 6-Month Contract-to-Hire (1099) Pay Rate: $45/hr 1099; conversion salary commensurate with experience Posted by: KayDev Technology LLC
Overview
KayDev Technology is seeking an experienced IT SOX/GRC Compliance Analyst to support our client, a leading national healthcare services provider. This role is the hands-on owner of the IT SOX ITprogram and the broader IT governance, risk, and compliance (GRC) function control execution, evidence collection, audit coordination, risk assessment, and policy management with supporting responsibility for HIPAA Security Rule compliance, identity and access governance in Zilla Security, and ITIL-based change management including chairing the Change Advisory Board (CAB).
This is a high-visibility position working with IT leadership, Internal Audit, InfoSec, control owners, and external auditors. The engagement is a 6-month contract with the intent to convert to a full-time permanent role.
Key Responsibilities
SOX ITProgram Ownership (Primary)
- Own end-to-end execution of SOX IT General Controls across access management, change management, IT operations, and program development for in-scope applications and infrastructure.
- Perform control walkthroughs, operating-effectiveness testing, and evidence collection on a quarterly and annual cadence.
- Serve as primary IT point of contact for Internal Audit and external auditors; manage PBC request lists, sample selections, and testing timelines.
- Track, root-cause, and remediate control deficiencies; maintain the deficiency log and management action plans.
- Maintain the IT control matrix, risk-control narratives, flowcharts, and control-owner documentation.
IT Governance, Risk & Compliance (GRC)
- Conduct IT risk assessments and maintain the IT risk register; map controls to applicable frameworks (SOX, HIPAA, NIST CSF, HITRUST as applicable).
- Own the IT policy and standards lifecycle, including annual review, approval workflow, and version control.
- Manage third-party/vendor IT risk reviews and Business Associate Agreement (BAA) compliance evidence.
- Build and maintain compliance dashboards and status reporting for IT leadership and the Audit Committee.
- Identify and implement automation to reduce manual evidence collection, control testing, and reporting effort.
HIPAA Security & Privacy (Supporting)
- Support HIPAA Security Rule compliance, including risk analysis documentation, safeguard evidence, and policy maintenance.
- Partner with Privacy and InfoSec on ePHI access controls and incident documentation.
Identity & Access Governance Zilla Security (Supporting)
- Administer Zilla Security for user access reviews (UARs), certification campaigns, and SoD monitoring in support of SOX and HIPAA access controls.
- Configure application integrations and review workflows; ensure timely campaign completion and produce audit-ready evidence.
ITIL Change Management / CAB (Supporting)
- Chair the weekly Change Advisory Board (CAB): set agenda, review RFCs, assess risk/impact, and drive approval decisions.
- Enforce the change management policy so standard, normal, and emergency changes are documented, approved, and auditable as SOX evidence.
- Report change management KPIs (success rate, unauthorized changes, emergency change volume) to IT leadership.
Required Qualifications
- 4+ years of experience in IT SOX compliance, IT audit, or IT GRC within a regulated environment.
- Experience leading CAB meetings and operating within an ITIL-based change management process; ITIL Foundation (v3/v4) or equivalent practical experience.
- Hands-on experience owning or executing SOX ITGC controls, testing, and external audit coordination.
- Working knowledge of IT GRC practices: risk assessment, control mapping, policy management, and deficiency remediation.
- Working knowledge of HIPAA Security and Privacy Rule requirements.
- Hands-on experience with Zilla Security or a comparable identity governance / access review platform.
- Experience automating compliance workflows (evidence collection, access review campaigns, control monitoring, or reporting) using scripting, workflow tools, or GRC/IAM platform integrations.
- Strong documentation, stakeholder communication, and audit-facing presentation skills.
- Ability to work independently in a fully remote environment.
Preferred Qualifications
- Healthcare, DME, or health-services industry experience.
- CISA, CRISC, CISSP, CHPS, or HCISPP certification.
- Big 4 or internal audit background.
- Experience with GRC platforms (AuditBoard, ServiceNow IRM/GRC, Workiva, Drata, Vanta).
- Experience with ServiceNow Change Management.
- Familiarity with NIST CSF, HITRUST, or ISO 27001 frameworks.
- Exposure to IAM platforms (Okta, Azure AD/Entra ID, SailPoint, Saviynt, CyberArk).
Work Details
- Schedule: Full-time, Monday Friday, U.S. business hours (Eastern Time preferred).
- Location: Remote; must reside in the U.S.
- Duration: 6 months, with conversion to permanent employment based on performance and business need.
- Compensation: $45/hr 1099. Conversion salary commensurate with experience.
- Work Authorization: Must be authorized to work in the United States. 1099 independent contractor; no C2C.
About KayDev Technology
KayDev Technology LLC is a Service-Disabled Veteran-Owned (SDVOSB) and Native American-Owned cybersecurity, IT services, and staffing firm headquartered in Fort Worth, Texas. We partner with enterprise and public-sector clients to deliver security, compliance, and technology talent.
KayDev Technology is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
Similar jobs
- RH
Laboratory Compliance Manager
NewRythm Health
Omaha, Nebraska🇺🇸On-siteYesterdayAuditingComplianceContinuous Improvement+2 - PI

2027 Summer Intern - Legal & Compliance Analyst
NewPIMCO
Newport Beach, California🇺🇸$35/hrOn-site18 hours agoComplianceRegulatory ComplianceLegal - NB
Compliance Analyst - Mutual Funds
NewNeuberger Berman
New York🇺🇸$80k - $110k/yrOn-site18 hours agoComplianceHTTPSLESS+1 - DP
Clinical Quality and Risk Coordinator - ON SITE
NewDesert Parkway Behavioral Healthcare Hospital
Las Vegas, Nevada🇺🇸On-site11 hours ago401kComplianceContinuous Improvement+2 - ML
Compliance Analyst
NewMandarich Law Group, LLP
Woodland Hills, California🇺🇸On-site13 hours ago401kComplianceMicrosoft Office - ML
Compliance Analyst
NewMandarich Law Group, LLP
Kennesaw, Georgia🇺🇸On-site13 hours ago401kComplianceMicrosoft Office