Information Security Compliance Analyst
Core
Support compliance programs across a global organization spanning multiple regulatory frameworks, security certifications, and risk management initiatives.
Role type
Information Security Compliance Analyst
Builds
Compliance evidence, audit deliverables, and risk profile reports
Domain
Information Security / Governance, Risk, and Compliance (GRC)
Deliverable
dashboards & analysis
Required skills
SOX ITGC/ITAC controls knowledge, audit lifecycle management, multi-framework compliance (ISO 27001, SOC 2, NIST 800-171, CMMC, Cyber Essentials), third-party risk management, GRC platform operation, regulatory change tracking
Preferred skills
GRC platforms (LogicGate, ServiceNow GRC, AuditBoard), cloud security compliance (AWS, Azure), vulnerability management, external audit support
Technologies
LogicGate, ServiceNow GRC, AuditBoard, AWS, Azure
Responsibilities
Coordinate evidence collection and control testing for internal and external audits; Work with control owners to ensure controls are performed on schedule; Contribute to the organization's risk profile and security metrics; Support third-party risk management activities; Maintain and operate the organization's GRC platform; Conduct periodic reviews of compliance controls to identify gaps; Provide guidance to control owners on evidence requirements and audit readiness
Seniority
Mid-level, hands-on IC