IHG

Senior Advisor, Security Controls & Compliance

IHG$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or Master's Degree in a related field.
  • 5+ years in information security, IT audit, or technology risk.
  • Experience with audits and compliance frameworks (SOX, PCI, etc.).
  • Proven ability to work with auditors and manage findings.
  • Strong understanding of IT controls across various domains.
  • Excellent communication skills for executive reporting.
  • Familiarity with compliance management platforms (GRC, ServiceNow).

Responsibilities

  • Lead compliance programs across multiple security control areas.
  • Serve as a senior control advisor and escalation point for stakeholders.
  • Manage auditor coordination and remediation tracking effectively.
  • Maintain compliance documents and improve the control library.
  • Build relationships with senior stakeholders and external auditors.
  • Support transformation and gap remediation through root cause analysis.
  • Provide executive-ready updates on audit progress and risks.

Benefits

  • Hybrid work structure with flexibility.
  • Opportunity to engage with high-level stakeholders.
  • Access to challenging and impactful compliance projects.
  • Collaboration with diverse teams across the organization.
Full Job Description
Job Description

As the Senior Analyst IT Information Security responsible for leading senior-level security controls and compliance activities across regulatory and audit programs, including SOX, PCI, SWIFT, SOC 1/SOC 2, privacy-related assessments, and control management. This role provides control advisory support, coordinates auditor and stakeholder engagement, manages RFIs and findings, maintains compliance scope and control documentation, and drives timely remediation of control gaps.

The role partners closely with Security Risk, Governance, Technology, Privacy, Financial Governance, BISOs, external auditors, and delivery partners to strengthen control accountability, improve audit readiness, and provide clear reporting on status, risks, issues, and decisions needed by leadership.

Your Day To Day
  • Lead assigned regulatory compliance programs and control portfolios across SOX, PCI, SWIFT, SOC 1/SOC 2, privacy, and other security control areas, ensuring scope, inventories, evidence expectations, and audit timelines are clearly defined and actively managed.
  • Serve as senior control advisor and escalation point for assigned stakeholders, compliance partners, and delivery resources, providing guidance on control design, operating effectiveness, audit response quality, and remediation approach.
  • Manage auditor coordination, RFIs, walkthroughs, findings, and remediation tracking by holding auditors and control owners accountable to milestones, improving quality of responses, and ensuring issues are escalated early with clear risk and impact framing.
  • Maintain and improve compliance scope, control documentation, and control library data in partnership with GRC, ServiceNow, Axonius, Technology, and Security teams, ensuring control attributes, scope tags, ownership, and evidence requirements remain current and audit-ready.
  • Build strong relationships with VP-level control owners, BISOs, Privacy, Financial Governance, Security Architecture, GIO, GPP, Product & Technology, and external audit partners to identify risks, resolve control gaps, and promote accountability for compliance outcomes.
  • Support regulatory transformation and recurring gap remediation by identifying root causes, developing practical remediation plans, coordinating cross-functional follow-up, and helping implement sustainable control improvements.
  • Provide concise status reporting and executive-ready updates on audit progress, RFIs, findings, indicators, risks, issues, decisions needed, and upcoming milestones for Director, SVP, CISO, and stakeholder reporting.
  • Contribute to control automation and continuous monitoring initiatives by identifying candidate controls, validating business requirements, and ensuring automated indicators and dashboards support regulatory and operational compliance needs without owning the continuous controls monitoring capability.


What We Need From You

  • Bachelor's or Master's Degree in Computer Information Systems, Information Technology, Cybersecurity, Business, Audit, Risk Management, or equivalent years of relevant work experience.
  • 5+ years of progressive experience in information security, IT audit, technology risk, compliance, controls management, or related technology governance roles.
  • Experience coordinating internal or external audits and regulatory compliance activities across frameworks such as SOX, PCI, SWIFT, SOC 1, SOC 2, privacy, NIST, ISO, COBIT, or related control frameworks.
  • Demonstrated experience working with auditors, control owners, technology leaders, and cross-functional teams to manage RFIs, walkthroughs, findings, remediation, and executive reporting.
  • Strong working knowledge of IT general controls, application controls, infrastructure controls, identity and access controls, change management, vulnerability management, incident management, and compliance evidence expectations.
  • Ability to interpret audit requirements, challenge auditor requests where appropriate, and translate complex control topics into clear business impacts and remediation actions.
  • Experience maintaining compliance scope, control inventories, control ownership, and evidence repositories in GRC or related platforms such as ServiceNow.
  • Strong written and verbal communication skills, including the ability to prepare concise updates for Director, SVP, CISO, VP, auditor, and stakeholder audiences.
  • Strong attention to detail, judgment, accountability, stakeholder management, and ability to operate independently in a complex, global environment.
  • Working knowledge of control automation, indicators, dashboards, and analytics sufficient to support continuous monitoring initiatives and ensure outputs align to regulatory and audit needs.

Travel - 10%
Location - Our hybrid work structure is an expectation of three (3) days a week in office. This expectation may be adjusted to evolve with the changing needs of the business.


About IHG

InterContinental Hotels Group (IHG) is a British multinational hospitality company that operates a portfolio of hotel brands, including InterContinental, Crowne Plaza, Holiday Inn, and Kimpton Hotels & Restaurants. The company was founded in 2003 as a result of the merger between British hotel company Six Continents and the hotel and restaurant business of the American conglomerate Bass. IHG is headquartered in Denham, England, and has operations in more than 100 countries. The company's brands cater to a range of travelers, from budget-conscious to luxury-seeking.
Learn more about IHG
Size
40,000 employees
Industry

Similar Jobs

More Jobs at IHG

More Information Technology Jobs

Find similar Senior Advisor, Security Controls & Compliance jobs: