IT Compliance Analyst
Position Overview
The primary responsibility of the IT Compliance Analyst is to ensure the processes and associated controls for the compliance frameworks are designed, managed, and assessed for effectiveness to reduce overall compliance risk across the organization. This includes performing continuous monitoring and driving audit actions to ensure adherence to the in-scope compliance frameworks. As part of their day-to-day, the IT Compliance Analyst will liaise closely with Internal Audit and key stakeholders to ensure full alignment on all IT regulatory compliance issues.
Essential Responsibilities
Audit & Compliance
Lead assigned audit program(s) as the primary subject matter expert.
Provide backup support to other audit programs as assigned.
Establish a comprehensive understanding of the organization's audit and compliance programs (SOX, PCI, ISO 27001, SOC 2, Cyber Essentials+, FedRAMP, etc.).
Scoping the audit, scheduling activities, leading calls, coordinating and fulfilling document request lists, leading walkthroughs, and other audit tasks as appropriate.
Work collaboratively with control owners on audit remediation work.
Policies & Procedures
Assist control owners in development and refinement of controls (policy requirements and/or ITGCs) for in-scope systems.
Work collaboratively with internal and external auditors to ensure controls are consistent with expectations and leading practices.
Help control owners identify potential issues prior to formal audits.
Documentation & Program Maintenance
Efficiently manage tasks, prioritize responsibilities, and maintain order in a fast-paced environment.
Perform and support the continuous monitoring of IT controls.
Report and present metrics from monitoring and audit activities to senior leadership.
Support general tasks including process improvement initiatives, RFI/RFP/contract responses, risk-management assessments, vendor risk reviews, ticket responses, and project work.
Qualifications
Required
Bachelor's degree in an appropriate field from an accredited university or equivalent experience.
Extensive PCI-DSS audit and continuous monitoring experience.
SOX working experience.
Experience performing audits, leading controls walkthroughs, interviewing stakeholders, gathering information, and identifying relevant information for documentation.
Coachable and willing to learn.
Ability to take initiative and drive results.
Successful completion of the Nlet's fingerprinting background assessment.
Must be locally located and comfortable working a 3-day-in-office hybrid model and 2 days remote.
Preferred
ISO 27001 working experience and/or certification(s).
Strong organizational and time-management abilities with formal project-management experience and/or certification(s).
Ability to work collaboratively with diverse stakeholders.
Experience working in AuditBoard.
Proficiency in Microsoft Office (Excel xlookup, Power BI report building).
Desired
QSA or ISA.
SOC 2 & NIST working experience and/or certification(s).
Experience working in a regulated industry.
Experience with ERP systems (e.g., Oracle, SAP, NetSuite, Great Plains).
This position is not eligible for sponsorship now or in the future and is only considering local talent.
Verra Mobility is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.
J-18808-Ljbffr