Senior Advisor, Security Controls & Compliance
Summary
The Senior Analyst IT Information Security leads regulatory compliance and audit programs, including SOX, PCI, and SOC 1/2, while serving as a senior advisor for control design and remediation. The role involves coordinating with auditors, managing control documentation in GRC platforms like ServiceNow, and reporting status to executive leadership.
As the Senior Analyst IT Information Security responsible for leading senior-level security controls and compliance activities across regulatory and audit programs, including SOX, PCI, SWIFT, SOC 1/SOC 2, privacy-related assessments, and control management. This role provides control advisory support, coordinates auditor and stakeholder engagement, manages RFIs and findings, maintains compliance scope and control documentation, and drives timely remediation of control gaps.
The role partners closely with Security Risk, Governance, Technology, Privacy, Financial Governance, BISOs, external auditors, and delivery partners to strengthen control accountability, improve audit readiness, and provide clear reporting on status, risks, issues, and decisions needed by leadership.
Your Day To Day
- Lead assigned regulatory compliance programs and control portfolios across SOX, PCI, SWIFT, SOC 1/SOC 2, privacy, and other security control areas, ensuring scope, inventories, evidence expectations, and audit timelines are clearly defined and actively managed.
- Serve as senior control advisor and escalation point for assigned stakeholders, compliance partners, and delivery resources, providing guidance on control design, operating effectiveness, audit response quality, and remediation approach.
- Manage auditor coordination, RFIs, walkthroughs, findings, and remediation tracking by holding auditors and control owners accountable to milestones, improving quality of responses, and ensuring issues are escalated early with clear risk and impact framing.
- Maintain and improve compliance scope, control documentation, and control library data in partnership with GRC, ServiceNow, Axonius, Technology, and Security teams, ensuring control attributes, scope tags, ownership, and evidence requirements remain current and audit-ready.
- Build strong relationships with VP-level control owners, BISOs, Privacy, Financial Governance, Security Architecture, GIO, GPP, Product & Technology, and external audit partners to identify risks, resolve control gaps, and promote accountability for compliance outcomes.
- Support regulatory transformation and recurring gap remediation by identifying root causes, developing practical remediation plans, coordinating cross-functional follow-up, and helping implement sustainable control improvements.
- Provide concise status reporting and executive-ready updates on audit progress, RFIs, findings, indicators, risks, issues, decisions needed, and upcoming milestones for Director, SVP, CISO, and stakeholder reporting.
- Contribute to control automation and continuous monitoring initiatives by identifying candidate controls, validating business requirements, and ensuring automated indicators and dashboards support regulatory and operational compliance needs without owning the continuous controls monitoring capability.
What We Need From You
- Bachelor's or Master's Degree in Computer Information Systems, Information Technology, Cybersecurity, Business, Audit, Risk Management, or equivalent years of relevant work experience.
- 5+ years of progressive experience in information security, IT audit, technology risk, compliance, controls management, or related technology governance roles.
- Experience coordinating internal or external audits and regulatory compliance activities across frameworks such as SOX, PCI, SWIFT, SOC 1, SOC 2, privacy, NIST, ISO, COBIT, or related control frameworks.
- Demonstrated experience working with auditors, control owners, technology leaders, and cross-functional teams to manage RFIs, walkthroughs, findings, remediation, and executive reporting.
- Strong working knowledge of IT general controls, application controls, infrastructure controls, identity and access controls, change management, vulnerability management, incident management, and compliance evidence expectations.
- Ability to interpret audit requirements, challenge auditor requests where appropriate, and translate complex control topics into clear business impacts and remediation actions.
- Experience maintaining compliance scope, control inventories, control ownership, and evidence repositories in GRC or related platforms such as ServiceNow.
- Strong written and verbal communication skills, including the ability to prepare concise updates for Director, SVP, CISO, VP, auditor, and stakeholder audiences.
- Strong attention to detail, judgment, accountability, stakeholder management, and ability to operate independently in a complex, global environment.
- Working knowledge of control automation, indicators, dashboards, and analytics sufficient to support continuous monitoring initiatives and ensure outputs align to regulatory and audit needs.