Sr. Information Security Compliance Analyst

Warner Bros. Entertainment Inc.$89K — $166K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science, business administration or related technical field.
  • 4+ years of experience in audit or compliance, in a corporate or technical environment.
  • 3+ years of hands-on PCI regulatory assessments, with a PCI Qualified Security Assessor (QSA) certification.
  • Proficiency in testing cloud controls across AWS, Azure, and GCP platforms.
  • Relevant certifications such as CISA, PCIP, CISM, CISSP, etc. are preferred.
  • Strong attention to detail and the ability to apply training and feedback effectively.
  • Experience in defining compliance roadmaps that balance requirements and resource allocation.

Responsibilities

  • Lead and support PCI assessments and audits across various business units.
  • Communicate security compliance status to executive leadership effectively.
  • Maintain detailed project plans to meet critical deadlines and milestones.
  • Assist in risk mitigation and remediation during information security assessments.
  • Drive process improvements and address control deficiencies.
  • Document findings and communicate results to stakeholders clearly and concisely.
  • Collaborate cross-functionally to uphold regulatory compliance across projects.

Benefits

  • Flexible work environment with a hybrid schedule (3 days onsite).
  • Opportunity to work with diverse and iconic brands in the entertainment industry.
  • Engagement in continuous learning and professional development initiatives.
  • Access to advanced security tools and technologies to enhance compliance efforts.
Full Job Description
*Must work a hybrid schedule (3 days onsite) out of our Atlanta office.* The Job Warner Bros. Discovery is looking for a skilled Sr. Information Security Compliance Analyst who will join the Global Information and Content Security (GICS) team to support the organization globally across all US and international brands and divisions. As part of the GICS team, you will lead and support PCI audits globally and will collaborate with key business units and stakeholders to ensure security and compliance with Payment Card Industry (PCI) requirements and other cybersecurity regulatory and policy requirements. The ideal candidate will have experience as a PCI Qualified Security Assessor (QSA) with experience across multiple compliance domains in audit process/procedure, risk analysis and mitigation, control testing, and continuous improvement initiatives.The candidate will have experience completing PCI 4.0 assessment types including but not limited to SAQ-A, ROC, SAQ-D, SAQ B-IP, and SAQ P2PE, as well as experience remediating vulnerabilities related to PCI ASV scanning processes. We support critical brands such as DC Universe, Harry Potter, Warner Bros Studio Hollywood Tours, Adult Swim, Cartoon Network, Discovery+, Max, TNT Sports, Golf Digest, Food Network, NCAA, etc. The WBD PCI program is inclusive of different types of environments collecting payments such as ecommerce systems including retail, ticketing, DTC Subscriptions, PPV Sports, donations & partner payments, mobile in app purchases, and vendor invoicing, and physical locations such as call centers, museums, retail physical stores, physical tours, pop up shops, and virtual reality experiences. We cultivate a security culture across all teams and disciplines, providing policy, standards, guidance, and awareness training to everyone. We work closely with departments across the company to understand their workflows and help ensure they are following the best security practices. We partner with technology stakeholders to assess our posture, build controls, and mitigate security risks. This team concentrates on validating that critical processes and controls are functioning end-to-end, identifying risk areas and control mitigation, as well as participating in projects to understand and determine potential impact to regulatory compliance components. You will identify areas of improvement and non-compliance which may lead to process changes and/or new controls. The Information Security Compliance Senior Analyst will drive various initiatives to completion and assist in managing and developing an effective Compliance Program. You will be accountable for a variety of functions centered on effective implementation of all the elements of a compliance program (project): compliance with applicable laws, rules, and regulations, internal policies, and procedures, and accepted business practices.   Responsibilities: Cybersecurity Compliance and Assessments  - Lead and support PCI assessments.  - Communicate status of security compliance efforts to executive leadership and management across technology disciplines.   - Keep current with the latest security technology advances and evolving compliance requirements and propose innovations that may benefit the business.   - Maintain detailed project plans and tasks lists to ensure you meet major milestone and critical due dates.  - Assist in information security assessments, audits, risk mitigation, and remediation.  - Track status of implementing remediation plans for control deficiencies, regulatory and policy gaps and make recommendations for process efficiencies.  - Drive process improvements and control implementation across business functions, including resolution of assessment findings and independent initiatives.  - Effectively communicate and build rapport with various partners and teams globally.  - Lead targeted compliance assessments, audits, and reviews, communicating results and recommendations in clear and concise written reports; and collaborate with management to ensure corrective actions are implemented effectively.  - Validate system requirements, flows, and written procedures through testing and observations, and to ensure regulatory compliance operating procedures and controls are working as intended.  - Participate in cross-functional teams to support various regulatory compliance subject matters ensuring that user activities continue to support systematic processes in place and drive positive compliant behaviors or that proposed new system changes fully meet Regulatory, Security and Legal requirements.  - Perform analysis based on the testing results through observations and reports to identify system and process gaps reducing risk for WBD.  - Document all work, and findings resulting from testing and communicate to relevant stakeholders within defined standard processes.  - Conduct related ongoing security compliance monitoring activities in coordination with the organization’s other compliance and operational assessment functions.  - Lead compliance assessments including testing to demonstrate the effectiveness of controls, and supporting team members to ensure reviews are critical, comprehensive, and thorough.  Collaboration - Accountable for organizing and leading meetings with various stakeholders across the company, and across the globe.  - Technical and process experienced professional who will ensure data and evidence meet audit expectations and regulatory requirements.  - Responsible for establishing and tracking goals, project plans, and assessment status, and is able to effectively communicate risks and overall status to your management on a timely basis.  - Stay abreast of existing and upcoming projects to effectively plan your work.  - Make updates to the centralized issues log, audit calendar, and other key team documents, ensuring accuracy, attention to detail, and overall status.  - Assist in the implementation of the Company GRC system, policies, standards, and processes.   - Assist in creation of comprehensive and meaningful metrics and status update for your manager.  - Ability to partner with other team members, contribute to building a positive team culture, learn internal processes, and contribute to building effective deliverables.  Reporting - Identify and measure key metrics reflecting the status of audits and assessments.   - Monitor the effectiveness of the compliance assessment process in accordance with agreed team metrics and performance measures to drive continuous improvements.  - Actively participate in stakeholder meetings with the goal of understanding all major projects and initiatives planned.  - Actively drive and report on status of audit completion, as well as remediation of regulatory and policy issues.  The Essentials:  - Bachelor’s degree in computer science, business administration or related technical field.  - 4+ or more years working in audit or compliance environments in a corporate or consulting capacity, with experience in a highly technical setting.  - 3+ years working in PCI regulatory assessments / requirements; previous PCI Qualified Security Assessor “QSA” certification required.   - The ability to be precise and display superb attention to detail is essential.  - Ability to effectively apply training and feedback.  - Experience testing cloud controls across AWS, Azure, and GCP.  - Experience defining certification/action plan roadmaps balancing compliance deliverables, business requirements, and resource allocation.   - Relevant certification (CISA, PCIP, CISM, CISSP, etc.).  - Experience with cross-functional risk, compliance and/or information security disciplines. 

About Warner Bros. Entertainment Inc.

Warner Bros. Interactive Entertainment is an American video game publisher based in Burbank, California, and part of the newly-formed Global Streaming and Interactive Entertainment unit of Warner Bros. Discovery. WBIE was founded on January 14, 2004 under Warner Bros. and transferred to the Home Entertainment division when that company was formed in October 2005. WBIE manages the wholly owned game development studios TT Games, Rocksteady Studios, NetherRealm Studios, Monolith Productions, WB Games Boston, Avalanche Software, and WB Games Montréal, among others.
Learn more about Warner Bros. Entertainment Inc.
Industry
Founded
1918

Similar Jobs

More Jobs at Warner Bros. Entertainment Inc.

More Information Technology Jobs

Find similar Sr. Information Security Compliance Analyst jobs: