Associate Analyst, IT Compliance
The Associate Analyst, IT Compliance supports the organization's cybersecurity governance, risk management, and compliance programs in a dynamic and fast-paced environment. This role works closely with Information Security, IT, Internal Audit, business stakeholders, and control owners to help maintain compliance with regulatory, industry, and corporate requirements including Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standard (PCI DSS), and third-party risk management activities.
The Associate Analyst assists with the execution of compliance assessments, risk reviews, control monitoring, policy management, and audit support activities. The position develops a foundational understanding of information security frameworks, risk management practices, and regulatory requirements while contributing to the organization's overall cybersecurity and compliance objectives.
You'll accomplish these goals by:
- Compliance Program Support
- Risk Management
- Audit & Assessment Support
- Policy & Standards Management
- Third-Party Risk Management
- Control Monitoring & Validation
- Data Analysis & Reporting
- Relationship Management
- Continuous Improvement
Additional responsibilities include:
- Coordinate with control owners to collect and validate compliance evidence for audits and assessments.
- Assist with tracking remediation activities for identified control deficiencies, audit findings, and risk treatment plans.
- Support quarterly compliance reviews and periodic control validation activities.
- Maintain governance, risk, and compliance documentation repositories, including policies, standards, risk registers, and control inventories.
- Monitor and document changes to relevant security frameworks, compliance requirements, and industry regulations.
- Assist with cybersecurity awareness and compliance communications across IT and business teams.
- Support development of governance and compliance metrics and reporting for leadership review.
- Participate in special projects and initiatives related to cybersecurity governance, risk management, and regulatory compliance.
Essentials for success include:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Information Systems, Risk Management, or a related field, or equivalent work experience.
- 0-2 years of experience in cybersecurity, IT compliance, IT audit, risk management, governance, information security, or a related technology field.
- Foundational understanding of information security concepts, cybersecurity frameworks, and IT controls.
- Basic knowledge of compliance and risk management frameworks such as SOX, PCI DSS, NIST, ISO 27001, COBIT, or similar standards preferred.
- Strong analytical, organizational, and problem-solving skills with attention to detail.
- Ability to collect, analyze, and interpret data and documentation from multiple sources.
- Excellent verbal and written communication skills with the ability to interact effectively with both technical and non-technical stakeholders.
- Proficiency with Microsoft Office applications, particularly Excel, PowerPoint, and Word.
- Ability to manage multiple priorities and meet deadlines in a fast-paced environment.
- Strong customer service mindset and ability to build collaborative relationships across teams.
- Self-motivated, proactive, and eager to learn new technologies, security concepts, and compliance requirements.
- Relevant coursework, internships, or certifications such as Security+, ISC2 CC, ITIL Foundation, or similar certifications are a plus.
- Flexibility of providing support during odd hours, weekends, and peak seasons.
- Minimal travel required (training/conferences).