Sr. Information Security Compliance Analyst
Who We Are… Behind WBD’s vast portfolio of iconic content and beloved brands are the storytellers, creators, and dreamers. From brilliant creatives to technology trailblazers, WBD offers career-defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.
Must work a hybrid schedule (3 days onsite) out of our Atlanta office.
About the Role
Warner Bros. Discovery is looking for a skilled Sr. Information Security Compliance Analyst to join the Global Information and Content Security (GICS) team, supporting the organization globally across all US and international brands and divisions. As part of the GICS team, you will lead and support PCI audits globally and collaborate with key business units and stakeholders to ensure security and compliance with Payment Card Industry (PCI) requirements and other cybersecurity regulatory and policy requirements.
The ideal candidate will have experience as a PCI Qualified Security Assessor (QSA) with expertise across multiple compliance domains in audit process/procedure, risk analysis and mitigation, control testing, and continuous improvement initiatives. The candidate will have experience completing PCI 4.0 assessment types including but not limited to SAQ-A, ROC, SAQ-D, SAQ B-IP, and SAQ P2PE, as well as experience remediating vulnerabilities related to PCI ASV scanning processes.
The WBD PCI program includes diverse environments collecting payments such as ecommerce systems (retail, ticketing, DTC subscriptions, PPV sports, donations, partner payments, mobile in-app purchases, vendor invoicing) and physical locations (call centers, museums, retail stores, physical tours, pop-up shops, and virtual reality experiences).
We cultivate a security culture across all teams, providing policy, standards, guidance, and awareness training. We work closely with departments to understand workflows and ensure best security practices, partnering with technology stakeholders to assess posture, build controls, and mitigate risks. This role focuses on validating critical processes and controls, identifying risk areas, and participating in projects to determine potential regulatory compliance impacts.
Responsibilities
- Lead and support PCI assessments globally.
- Communicate status of security compliance efforts to executive leadership and management across technology disciplines.
- Maintain current knowledge of security technology advances and evolving compliance requirements; propose innovations to benefit the business.
- Maintain detailed project plans and task lists to meet major milestones and critical due dates.
- Assist in information security assessments, audits, risk mitigation, and remediation.
- Track status of remediation plans for control deficiencies, regulatory and policy gaps; recommend process efficiencies.
- Drive process improvements and control implementation across business functions, including resolution of assessment findings.
- Effectively communicate and build rapport with global partners and teams.
- Lead targeted compliance assessments, audits, and reviews; communicate results and recommendations in clear written reports.
- Collaborate with management to ensure corrective actions are implemented effectively.
- Validate system requirements, flows, and written procedures through testing and observations to ensure regulatory compliance.
- Participate in cross-functional teams to support regulatory compliance, ensuring user activities align with systematic processes and proposed changes meet regulatory, security, and legal requirements.
- Perform analysis based on testing results to identify system and process gaps, reducing risk for WBD.
- Document all work and findings; communicate results to relevant stakeholders within defined standard processes.
- Conduct ongoing security compliance monitoring in coordination with other compliance and operational assessment functions.
- Lead compliance assessments, including testing to demonstrate control effectiveness, and support team members to ensure thorough reviews.
- Organize and lead meetings with stakeholders globally.
- Ensure data and evidence meet audit expectations and regulatory requirements.
- Establish and track goals, project plans, and assessment status; communicate risks and status to management.
- Stay abreast of existing and upcoming projects to plan work effectively.
- Update centralized issues log, audit calendar, and key team documents with accuracy and attention to detail.
- Assist in the implementation of the Company GRC system, policies, standards, and processes.
- Create comprehensive and meaningful metrics and status updates for management.
- Partner with team members to build a positive team culture, learn internal processes, and contribute to effective deliverables.
- Identify and measure key metrics reflecting audit and assessment status.
- Monitor compliance assessment process effectiveness using agreed team metrics and performance measures to drive continuous improvements.
- Actively participate in stakeholder meetings to understand major projects and initiatives.
- Drive and report on audit completion status and remediation of regulatory and policy issues.
Requirements
- Bachelor’s degree in computer science, business administration, or related technical field.
- 4+ years working in audit or compliance environments in a corporate or consulting capacity, with experience in a highly technical setting.
- 3+ years working in PCI regulatory assessments/requirements; previous PCI Qualified Security Assessor (QSA) certification required.
- Precision and superb attention to detail.
- Ability to effectively apply training and feedback.
- Experience testing cloud controls across AWS, Azure, and GCP.
- Experience defining certification/action plan roadmaps balancing compliance deliverables, business requirements, and resource allocation.
- Relevant certification (CISA, PCIP, CISM, CISSP, etc.).
- Experience with cross-functional risk, compliance, and/or information security disciplines.
- Subject matter expertise in PCI, Data Privacy, SSAE 18, Swift, SOX, etc.
- Superior analytical and problem-solving skills.
- Superb relationship-building skills.
- Ability to prioritize and execute tasks in a high-pressure environment.
- Ability to assess customer/client needs, creatively approach solutions, and influence appropriate courses of action.
- Ability to work with changing priorities and multiple projects.
- Highest integrity commensurate with a compliance & ethics position.
- Excellent communication and project management skills.
- Produce clear and polished work product in narrative and visual form.
- Ability to work independently, flexibility, and adaptability in a dynamic, fast-growing environment.
- Strong quantitative, qualitative, and analytical skills with sound business judgment and skepticism as needed.
Preferred Qualifications
- 3+ years of Big 4 experience in a related field.
- 3+ years of prior experience in media, tech, entertainment, business development, or streaming services.
- Knowledge of and passion for media, entertainment, and technology industries (key players, growth trends, new media models, industry structure).
- Familiarity with streaming and similar products/services.
- Experience working in a national or global company.
- Knowledge of visualization tools (e.g., Tableau, Power BI).
- Comfortable working in a highly iterative environment.
- Creative problem solver with sound business discernment and high attention to detail.
- Passion for accuracy and translating insights into a compelling narrative; ability to balance details with the larger picture.
Pay
Base pay range: $89,390.00 - $166,010.00 salary per year. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards.
Benefits
Warner Bros. Discovery provides a variety of benefits to employees, including health, retirement, and wellness programs.