Job role -Sr. IT Compliance Analyst Location-Mesa, AZ. (Local) Duration- 12+ Months Contract (Long term) Interview -First Round Virtual, final round Onsite We need Sr. Analyst with strong background in Audit and Compliance programme. The primary responsibility of the IT Compliance Analyst is to ensure the processes and associated controls for the compliance frameworks are designed, managed, and assessed for effectiveness to reduce overall compliance risk across the organization. This includes performing continuous monitoring and driving audit actions to ensure adherence to the in-scope compliance frameworks. As part of their day to day, the IT Compliance Analyst will liaise closely with Internal Audit and key stakeholders to ensure full alignment on all IT regulatory compliance issues. Key Responsibilities: - Audit & Compliance
- Establish a comprehensive understanding of the organization's audit and compliance programs (i.e., SOX, PCI, ISO 27001, SOC 2, Cyber Essentials +, FedRAMP, etc.).
- Serve as the:
primary subject matter expert leading assigned audit program(s). backup support to other audit programs as assigned. - This includes scoping the audit, scheduling activities, leading calls, coordinating and fulfilling document request lists, leading walkthroughs, and other audit tasks as appropriate.
- Work collaboratively with control owners on audit remediation work.
- Policies & Procedures
- Assist control owners in development and refinement of controls (i.e., policy requirements and/or ITGCs) for in-scope systems.
- Work collaboratively with internal and external auditors to ensure controls are consistent with expectations and leading practices.
- Assist control owners to identify any potential issues prior to formal audits.
- Documentation & Program Maintenance
- Efficiently manage tasks, prioritize responsibilities, and maintain order in a fast-paced environment.
- Perform and support the continuous monitoring of IT controls.
- Report and present metrics on monitoring and audit activities to senior leadership.
- Support general tasks including but not limited to
i) process improvement initiatives ii) RFI/RFP/contract responses iii) risk management assessments iv) vendor risk reviews v) ticket responses vi) project work. |