The Senior Technical Compliance Analyst is an integral team member of the QTS Security Risk & Compliance Team and reports to the Manager, Information Security Compliance & Risk.
QTS has adopted a risk-based approach to security risk and compliance, and this role is responsible for implementing, monitoring, and continuously improving QTS's security risk and compliance programs through the enterprise GRC program.
This role may be based in
Overland Park, KS; Suwanee, GA; or Ashburn, VA and requires up to
15% travel to QTS data center locations. The ideal candidate possesses a growth mindset, strong analytical skills, and a natural ability to collaborate across diverse teams. They will play a key role in transforming compliance requirements into actionable controls, meaningful documentation, and scalable processes that strengthen QTS's risk and compliance posture while enabling business objectives.
RESPONSIBILITIES- Leverage the GRC platform to align frameworks, regulatory requirements, risks, controls and documentation into a cohesive governance structure that supports operational execution, continuous monitoring, and data driven reporting on the effectiveness of QTS security and compliance programs.
- Provide visibility into the program maturity, risk posture, and control effectiveness through reporting and dashboards.
- Provide internal support for internal audits of the program as well as the external audits of the SOC1 & SOC2, ISO 27001 & ISO 22301, PCI DSS, FISMA / NIST 800-53, DOD CMMC, and HITRUST audit cycles, by facilitating evidence collection, stakeholder engagement, and issue remediation
- Compliance Program Execution - Partner with control owners to monitor reviews, scope coverage, and assessment on control effectiveness and completeness of internal documentation.
- Compliance Implementations - Facilitate the implementation, adoption, and continuous improvement of new and existing compliance frameworks, standards, and regulatory requirements, ensuring controls and documentation are effectively integrated into data center and corporate operations.
- Customer Compliance Support - Assist in responding to customer security, compliance, and risk inquiries by coordinating evidence requests, completing questionnaires, and audit requests.
- Security Risk Program - Coordinate with the risk team as issues are reported that require documentation or control updates to reduce risk through continual improvements.
- Bachelor's degree or equivalent professional experience.
- Minimum of 2 years of experience supporting compliance, risk management, governance, or a related operational function.
- Hands-on experience administering, implementing, or utilizing Governance, Risk, and Compliance (GRC) or Integrated Risk Management (IRM) platforms.
- Written skills to demonstrate ability to translate complex requirements in a clear, concise manner in communications and documentation.
- Strong analytical, organizational, and problem-solving skills, with the ability to manage multiple priorities and deadlines in a fast-paced environment.
- Proven ability to build and maintain collaborative relationships across a diverse group of stakeholders, including technology teams, operational teams, auditors, and corporate support functions.
Preferred Knowledge & Experience Working knowledge of one or more of the following frameworks, standards, and regulatory requirements:
- NIST Cybersecurity Framework (CSF)
- DoD Cybersecurity Maturity Model Certification (CMMC)
ADDITIONAL QUALIFICATIONS The ideal candidate may hold, or be actively pursuing, one or more of the following certifications:
- Certified Information Systems Security Professional (CISSP)
- GIAC Security Essentials Certification (GSEC)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- GIAC Critical Controls Certification (GCCC)
KNOWLEDGE, SKILLS, AND ABILITIES In addition to QTS Core Values, the successful candidate will demonstrate:
- Quality Decision Making - Strong analytical skills to evaluate risks, assess control solutions, and synthesize diverse inputs from cross-functional stakeholders.
- Consultative Communication - Builds trusted relationships and effectively communicates with technical and non-technical stakeholders to achieve compliance and risk management objectives
- Team Collaboration - - Establishes and maintains positive working relationships across business functions, management teams, and risk/compliance stakeholders. Adapts to diverse perspectives and works collaboratively to drive continuous improvement and program success.
- Technical Aptitude - Demonstrates curiosity and a commitment to professional growth by continuously expanding knowledge of compliance, risk, regulatory requirements, and enabling technologies. Quickly adapts to evolving tools, processes, and business needs.