THE IMPACT YOU CAN HAVE:
The Associate Analyst, IT Compliance supports the organization's cybersecurity governance, risk management, and compliance programs in a dynamic and fast-paced environment. This role works closely with Information Security, IT, Internal Audit, business stakeholders, and control owners to help maintain compliance with regulatory, industry, and corporate requirements including Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standard (PCI DSS), and third-party risk management activities.
The Associate Analyst assists with the execution of compliance assessments, risk reviews, control monitoring, policy management, and audit support activities. The position develops a foundational understanding of information security frameworks, risk management practices, and regulatory requirements while contributing to the organization's overall cybersecurity and compliance objectives.
YOU'LL ACCOMPLISH THESE GOALS BY:
• Compliance Program Support
Assists in the execution and maintenance of IT compliance programs, including SOX, PCI DSS, and other applicable regulatory, industry, and corporate requirements. Supports collection, organization, and validation of compliance evidence and documentation.
• Risk Management
Assists with the identification, documentation, and tracking of cybersecurity and technology risks. Supports risk assessment activities and helps maintain risk registers, remediation plans, and related reporting.
• Audit & Assessment Support
Supports internal and external audits by gathering requested documentation, coordinating evidence collection activities, tracking requests, and assisting with remediation follow-up activities.
• Policy & Standards Management
Supports the maintenance, review, and communication of information security policies, standards, procedures, and guidelines. Assists in ensuring documentation remains current and aligned with organizational and regulatory requirements.
• Third-Party Risk Management
Participates in vendor and third-party risk assessment processes by collecting information, reviewing submitted documentation, tracking assessment activities, and escalating identified concerns as appropriate.
• Control Monitoring & Validation
Assists with monitoring the effectiveness of IT and cybersecurity controls. Reviews evidence submitted by control owners and supports control testing activities to validate compliance requirements.
• Data Analysis & Reporting
Collects, analyzes, and interprets governance, risk, and compliance data. Assists with preparing reports, dashboards, metrics, and presentations that communicate compliance status, risk trends, and remediation activities.
• Relationship Management
Develops working relationships with business and technology teams to support compliance initiatives, facilitate information gathering, and promote awareness of governance, risk, and compliance requirements.
• Continuous Improvement
Identifies opportunities to improve governance, risk, compliance, and audit processes. Supports implementation of process improvements, standardization efforts, and documentation enhancements.
ADDITIONAL RESPONSIBILITIES:
• Coordinate with control owners to collect and validate compliance evidence for audits and assessments.
• Assist with tracking remediation activities for identified control deficiencies, audit findings, and risk treatment plans.
• Support quarterly compliance reviews and periodic control validation activities.
• Maintain governance, risk, and compliance documentation repositories, including policies, standards, risk registers, and control inventories.
• Monitor and document changes to relevant security frameworks, compliance requirements, and industry regulations.
• Assist with cybersecurity awareness and compliance communications across IT and business teams.
• Support development of governance and compliance metrics and reporting for leadership review.
• Participate in special projects and initiatives related to cybersecurity governance, risk management, and regulatory compliance.
ESSENTIALS FOR SUCCESS:
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Information Systems, Risk Management, or a related field, or equivalent work experience.
• 0-2 years of experience in cybersecurity, IT compliance, IT audit, risk management, governance, information security, or a related technology field.
• Foundational understanding of information security concepts, cybersecurity frameworks, and IT controls.
• Basic knowledge of compliance and risk management frameworks such as SOX, PCI DSS, NIST, ISO 27001, COBIT, or similar standards preferred.
• Strong analytical, organizational, and problem-solving skills with attention to detail.
• Ability to collect, analyze, and interpret data and documentation from multiple sources.
• Excellent verbal and written communication skills with the ability to interact effectively with both technical and non-technical stakeholders.
• Proficiency with Microsoft Office applications, particularly Excel, PowerPoint, and Word.
• Ability to manage multiple priorities and meet deadlines in a fast-paced environment.
• Strong customer service mindset and ability to build collaborative relationships across teams.
• Self-motivated, proactive, and eager to learn new technologies, security concepts, and compliance requirements.
• Relevant coursework, internships, or certifications such as Security+, ISC2 CC, ITIL Foundation, or similar certifications are a plus.
• Flexibility of providing support during odd hours, weekends, and peak seasons.
• Minimal travel required (training/conferences).
#LI -ML1
#LI-HYBRID
The pay range for this position is $79,900.00 - $85,000.00 / Year with the opportunity for eligible associates to earn additional compensation pursuant to the Company's bonus plan. Exact pay will be based on factors including, but not limited to relevant education, qualifications, certifications, experience, level, shift, geographic location, and business and organizational needs. Full-time positions are eligible for paid time off, health, dental, vision, life and disability benefits. Part-time positions are eligible for dental, vision, life, and disability benefits. For additional information concerning our benefits, visit our Benefits and Career Development page: https://learn.bswift.com/ulta