IT Security Compliance Analyst
About the Role
As the IT Security Compliance Analyst, you'll serve as a key connection point between IT Operations, Software Development, management, and the Internal Audit functions. You'll help ensure that systems, processes, and controls are implemented effectively while meeting both regulatory compliance and internal security standards. This hybrid role involves working cross-functionally across Watkins Wellness and Masco, partnering with IT teams, business leaders, and audit stakeholders to coordinate reviews, maintain documentation, respond to audit requests, and support cybersecurity and compliance initiatives.
During your first several months, you'll focus on learning Watkins and Masco audit requirements, understanding key business processes, and building knowledge of how information is managed and secured across the organization. This position offers excellent growth potential as the organization continues to expand its security and compliance capabilities.
Responsibilities
- Partner with stakeholders across Watkins Wellness and Masco to coordinate audit activities, respond to compliance inquiries, communicate requirements, and ensure audit requests are addressed efficiently and accurately.
- Conduct and administer recurring audits and control reviews, monitor compliance with established security policies and regulatory frameworks, and help maintain a strong IT security and compliance posture.
- Review employee access requests, account changes, privileged access assignments, department transfers, and deprovisioning activities to ensure appropriate controls are followed and security risks are minimized.
- Track audit findings and remediation efforts, support corrective action plans, and identify opportunities to streamline processes, strengthen controls, and improve the effectiveness of compliance activities.
- Collect, validate, and maintain audit evidence and documentation, prepare reports and responses for audit reviews, coordinate audit schedules, and ensure key information is available when needed.
- Support security and risk management initiatives by coordinating cybersecurity assessments and penetration testing activities, assisting with NIST/CIS evaluations, and helping ensure IT practices remain secure, compliant, and current.
Requirements
- Bachelor's degree in Business Administration, Accounting, Finance, or a related field with an IT background preferred.
- 3+ years of experience in IT security, compliance, auditing, or a related field.
- Proven audit experience supporting internal, external, or regulatory audits.
- Understanding of IT General Controls (ITGCs), access management, and security best practices.
- Experience working with compliance and regulatory frameworks such as SOX, PCI, NIST, CIS, ISO, or similar standards.
- Familiarity with IT administration concepts and systems such as Active Directory or similar technologies.
- Strong verbal and written communication skills with the ability to collaborate effectively with IT teams, management, auditors, and cross-functional stakeholders.
- Excellent organizational skills, attention to detail, and ability to manage multiple priorities while meeting deadlines.
- Proficiency with Microsoft 365 applications, including Outlook, Word, Excel, and other business productivity tools.
- Experience with ServiceNow, ITIL-based processes, or related service management practices is a plus.
- CISA and/or CISSP certifications are desirable.
Benefits
- Exceptional health and wellness benefits.
- Paid time off.
- Company bonus and profit sharing.
- 401k match.
- Education assistance.
Pay
Hiring range: $62,600.00 - $98,340.00. Many factors are taken into consideration in determining pay, including education and location.
Schedule
This is a full-time, hybrid role.
The employee must frequently lift and move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, color vision, peripheral vision, and depth perception. The noise level in the work environment is usually quiet. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.