POSITION SUMMARY: As a member of the Cyber Security group, the IT Risk and Compliance Analyst I is responsible for supporting the organization’s IT risk management, third-party risk management, and compliance efforts. The IT Risk and Compliance Analyst will assist in identifying, assessing, and mitigating IT-related risks while ensuring compliance with relevant laws, regulations, and industry standards. This position will collaborate with IT, and other business departments to evaluate IT controls in the context of PCI and NIST standards. PRINCIPAL RESPONSIBILITIES: Perform comprehensive enterprise-wide IT risk assessments and audits, collaborating cross-functionally to identify, prioritize, and mitigate cyber risks and compliance issues. Develop, implement, and maintain robust IT security policies, procedures, and controls aligned with organizational objectives, industry frameworks (e.g., NIST 800-53), and regulatory requirements (e.g., PCI DSS). Design and execute engaging security awareness training programs and campaigns to cultivate a security-minded culture. Create and maintain documentation related to IT risk and compliance activities. Continuously monitor and evaluate emerging IT risks, regulatory changes, and industry trends to proactively adapt security and compliance controls. Conduct third-party cyber risk assessments, ensuring vendors and partners align with core cyber and compliance standards. Establish and maintain a comprehensive risk register, identifying, assessing, and mitigating IT security risks to enhance organizational resilience. Provide expert guidance to stakeholders on interpreting and implementing company standards and regulatory requirements. Complete inbound VSQs, RFPs, and RFIs, ensuring comprehensive and timely responses. Other non-essential duties as assigned or may be necessary.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level
Education Level
No Education Listed