Jobs · Legal · Kentucky

Compliance Analyst II

Waystar · Louisville, KY · 4 days ago
LegalFull-time

About This Position

The Compliance Analyst II plays a key role in supporting and coordinating Waystar's information technology compliance and assurance programs. This position is responsible for managing day-to-day activities related to regulatory and industry assessments, including HITRUST, PCI DSS, SOC 2 / 3 + HIPAA, and TX-RAMP. The Compliance Analyst II serves as a primary liaison between internal stakeholders and external auditors, helping ensure successful completion of assessments and maintaining audit readiness throughout the year. This role requires strong organizational skills, attention to detail, project management capabilities, and the ability to work effectively with technical and non-technical teams across the organization.

What You'll Do

  • Coordinate and manage assigned compliance assessments and audits, including HITRUST, PCI DSS, SOC 2 / 3 + HIPAA, and TX-RAMP.
  • Develop and maintain assessment project plans, timelines, request trackers, and status reporting.
  • Facilitate audit planning activities, kick-off meetings, stakeholder interviews, walkthroughs, and evidence collection efforts.
  • Assign audit requests to appropriate control owners and monitor progress through completion.
  • Serve as a primary point of contact for internal teams and external auditors during assessments.
  • Maintain ongoing communication with stakeholders regarding audit requirements, deadlines, risks, and remediation efforts.
  • Monitor assessment status and escalate issues or delays when necessary.
  • Maintain an audit-ready compliance posture by collecting, organizing, and maintaining evidence throughout the year.
  • Develop, review, and update compliance documentation, procedures, narratives, inventories, and process flows.
  • Aid in the development and maintenance of policies, standards, and supporting compliance documentation.
  • Support continuous monitoring activities designed to maintain compliance with organizational and regulatory requirements.
  • Partner with Information Security, Infrastructure, Engineering, Product Development, Legal, Privacy, Human Resources, Procurement, and other business units to support compliance initiatives.
  • Facilitate meetings and communications between internal stakeholders and external assessors.
  • Assist process owners in understanding audit requirements and evidence expectations.
  • Support remediation efforts by tracking corrective actions and validating completion of assigned tasks.
  • Manage and respond to requests submitted through the Compliance team inbox.
  • Track and maintain compliance metrics, assessment schedules, documentation inventories, and ongoing compliance activities.
  • Support responses to customer and regulatory inquiries related to compliance certifications and attestations.
  • Participate in internal process improvement initiatives that increase efficiency and strengthen compliance programs.

What You'll Need

  • Stay current on emerging regulatory requirements, industry frameworks, and compliance best practices.
  • Contribute to special projects and strategic initiatives assigned by the Manager, IT Compliance.
  • Perform other duties as assigned.

Minimum Qualifications

  • Bachelor's degree in Information Systems, Cybersecurity, Business, Risk Management, Compliance, Accounting, or a related field; or equivalent combination of education and experience.
  • 2+ years of experience in information technology compliance, audit, risk management, cybersecurity, or a related discipline.
  • Experience supporting one or more compliance frameworks including HITRUST, PCI DSS, SOC 2 / 3, HIPAA, TX-RAMP, NIST, or similar regulatory frameworks.
  • Experience coordinating audits and working directly with external assessors or auditors.
  • Experience managing multiple concurrent projects and competing priorities.

Preferred Qualifications

  • Experience managing compliance assessments from planning through final reporting.
  • Knowledge of healthcare regulatory requirements and HIPAA security and privacy requirements.
  • Familiarity with cloud environments, information security controls, and third-party risk management.
  • Relevant certifications such as: HITRUST CCSF, PCISAC, CRISP, CCISSP, PSP/US, PCI, ISA.

Similar jobs

Compliance Analyst II

University of RochesterRochester, New York Metropolitan Area· 2 mo ago
Legal$64k–$96k/yrapply on rochester.wd5.myworkdayjobs.com

Compliance Analyst II

HomeXpress Mortgage CorpSanta Ana, CA· 1 mo ago
RemoteOTHRapply on jobs.smartrecruiters.com

Compliance Analyst II

TierPointUnited States· 2 wk ago
RemoteLegal$60k–$98k/yrapply on careers-tierpoint.icims.com

Compliance Analyst-2

New Hampshire Mutual BancorpConcord, NH· 2 wk ago
Legal$60k–$72k/yrapply on workforcenow.adp.com