Green Card Risk Compliance Analyst Jobs
Risk Compliance Analyst roles at U.S. financial institutions, healthcare systems, and tech firms regularly qualify for EB-2 and EB-3 green card sponsorship through PERM labor certification. Employers file on your behalf, covering prevailing-wage documentation and I-140 petition requirements. Your compliance credentials and regulatory experience are what drive sponsorship eligibility.
Find Green Card Risk Compliance Analyst JobsOverview
Showing 5 of 19+ Risk Compliance Analyst jobs










See all Risk Compliance Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Risk Compliance Analyst roles.
Get Access To All Jobs
JOB SUMMARY
This job works collaboratively to support all risk and compliance assessment activities of Highmark Health across a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, etc. The incumbent will partner with the organizational risk and business partners, the technology organization, and global delivery teams to meet Highmark Health’s mission requirements in a manner consistent with the enterprise risk appetite. This individual must have a proactive mindset and approach, and feel comfortable working in a highly matrixed environment.
ESSENTIAL RESPONSIBILITIES
- Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess, prioritize, evaluate and address financial, information security, privacy, and other areas of risk. Prepare draft reports and other management reporting deliverables. Review all work prepared by less experienced team members to ensure audit quality standards are consistently met in all forms of documentation.
- Review and interpret inherent risk assessment results, engagement risks, and develop assurance plans (e.g., on-site audit, contract review, financials assessment, purchasing data analysis) to address relevant risk areas and to ensure proper controls are implemented. Accountable for the review and interpretation of authoritative guidance (including, but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO reports) and performs qualitative and quantitative impact assessments based on physical, technical, and administrative safeguards as well as contractual requirements; conducts additional information gathering and risk assessments as-needed; documents and reports results.
- Lead development of project plans to support risk assessment and decisioning in coordination with business owners and other stakeholders within task-based budgets. Collaborate and communicate with Information Security, Privacy, Procurement, Audit, Compliance, and other teams across the Enterprise to align risk management objectives, practices and procedures.
- Interface with business areas, technical staff, project teams, and third parties to execute cross-functional risk assurance projects. Lead the communication of assessment results and findings with multiple stakeholder groups and provides consultation and direction throughout.
- Interpret complex data flow/information sharing activities, customer integrations, and information safeguards into simplified and high-level terminology and/or process/data flows. Maintains risk management reporting dashboards in RSA Archer applications in order to keep information complete, accurate, and current. Prepare and assist with the delivery of risk assurance reports to management.
- Ensure risk questionnaires and other risk assessments are distributed and completed on-time and prepares initial impact assessments. Ensure compliance requirements are met across the Enterprise. Assist in training and mentoring team members on multi-faceted engagements, platform customer dependencies, and interpretation of complex contract agreements.
- Collaborate with lead in providing input and consultation on risk and assurance reporting. Collaborate and consult with other areas (e.g., Procurement, Privacy, Information Security, Legal) throughout the engagement lifecycle. Assist in providing timely feedback on interpretations regarding authoritative guidance.
- Proactively reviews updates made to departmental desk-level procedures, risk assessment methodology, assessment procedures, questionnaires, training, etc. and is responsible for monitoring compliance with departmental metrics, internal control activities, contractual obligations, regulatory requirements, and responding to customer inquiries/audits.
Other duties as assigned or requested
Education
Required
Bachelor's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Substitution
6 years of related and progressive experience in lieu of Bachelor's degree
Preferred
- Master's Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or related field
Experience
Required
- 5 years in Audit and Compliance
To Include:
- 3 years of Business Process Design
- 3 years of Project Management
Preferred
None
LICENSES or CERTIFICATIONS
Required
- None
Preferred (any of the following)
- Certified Public Accountant (CPA)
- Certified Information Systems Analyst (CISA)
- Certified Information Privacy Professional (CIPP)
- Certified Information Systems Security Professional (CISSP)
SKILLS
- Demonstrate expert knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes.
- Knowledge of relevant regulatory guidelines, vendor management, sourcing and procurement, and completing assessments of vendors.
- Excellent resource and project planning capabilities, decision making skills, history of results-oriented delivery, and effective team building across a cross-campus and diverse team of management and staff.
- Strong written and verbal communication skills for diverse audiences (senior management, board, peer, and team).
- Strong relationship building skills and ability to influence with and without authority in a matrixed organization.
- Leadership qualities with an ability to motivate and inspire a group of individuals to achieve superior results.
- High capacity to think analytically, interpret information/observations, apply judgment and make effective, strategic decisions.
Language (Other than English):
None
Travel Requirement:
0% - 25%
PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS
Position Type
Office-based
Teaches/trains others regularly
Occasionally
Travel regularly from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$79,300.00
Pay Range Maximum:
$127,100.00
Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
See all Green Card Risk Compliance Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Green Card Risk Compliance Analyst Jobs.
Get Access To All JobsTips for Finding Green Card Sponsorship as a Risk Compliance Analyst
Document your regulatory credentials before applying
Gather degree transcripts, professional certifications like CRCM or CAMS, and letters confirming your compliance specialization. PERM labor certification requires your employer to match your actual qualifications to the job description, so gaps in documentation can stall the filing.
Target employers with active PERM filing history
Banks, insurance carriers, and fintech firms that have filed PERM applications for compliance roles before are more likely to sponsor again. Search the DOL's OFLC disclosure data to identify companies with recent Risk Compliance Analyst certifications in your target location.
Search green card sponsoring employers on Migrate Mate
Migrate Mate filters job listings by employers with verified green card sponsorship history, so you're not cold-applying to companies that have never navigated PERM. Use it to find Risk Compliance Analyst openings where sponsorship is already part of the hiring process.
Negotiate PERM start date during the offer stage
Ask your prospective employer when they plan to initiate PERM after you start. Some companies wait 12 months before filing. Knowing the timeline upfront lets you plan for priority date backlogs, especially if you're from a country with EB-3 wait times.
Verify your role meets EB-2 specialty occupation standards
EB-2 requires the position to normally demand an advanced degree. Review the O*NET occupation profile for Risk Compliance Analysts and confirm your employer's job description specifies a master's or bachelor's plus five years, not just a generic degree requirement.
Confirm prevailing wage level matches your experience tier
USCIS scrutinizes wage level assignments during I-140 adjudication. Use the OFLC Wage Search to check whether the employer's offered wage aligns with a Level II or Level III designation for your specific metro area, since a misclassified wage level can trigger a Request for Evidence.
Green Card Risk Compliance Analyst: Frequently Asked Questions
Do Risk Compliance Analyst roles typically qualify for EB-2 or EB-3 sponsorship?
Both categories apply, depending on the employer's job requirements. EB-2 applies when the role normally requires an advanced degree or the employer requests an advanced-degree professional. EB-3 covers positions requiring at least a bachelor's degree. Most compliance analyst roles meet EB-3 requirements at minimum, and senior or specialized positions, such as those focused on AML, BSA, or model risk governance, frequently qualify for EB-2.
How does green card sponsorship differ from H-1B sponsorship for this role?
Green card sponsorship through PERM and I-140 is permanent, leading to lawful permanent residency rather than a temporary work authorization period. Unlike the H-1B visa, there is no annual lottery and no cap concerns at the EB-3 level for most countries. The tradeoff is time: PERM labor certification alone typically takes six to twelve months before USCIS even receives the I-140 petition.
What does the PERM labor certification process look like for compliance roles?
Your employer files with DOL to prove no qualified U.S. worker was available for the position. This involves a supervised recruitment campaign, including job postings and documentation of applicant rejections. For Risk Compliance Analyst roles, employers must demonstrate the position requires your specific credentials, so the job description and your qualifications need to align precisely or DOL may audit the filing.
Where can I find employers who actively sponsor green cards for Risk Compliance Analyst positions?
Migrate Mate is built specifically for this search. It surfaces job listings from employers with verified green card sponsorship history, so you can focus on companies that have completed PERM filings for compliance roles before, rather than spending time in interviews only to learn the employer doesn't sponsor. Financial institutions, healthcare compliance teams, and large tech firms are among the most active sponsors.
Can I switch employers after my green card process has started?
Yes, under certain conditions. Once your I-140 is approved and your priority date is current or your application has been pending for 180 days, you may be able to port your priority date to a new employer in a same or similar occupation under AC21 portability rules. Risk Compliance Analyst roles generally qualify as sufficiently similar to related compliance positions, but your new employer must agree to continue sponsorship.