GRC Regulatory Compliance Senior Analyst
$90,000–$105,000 year
HybridChicago, Illinois, United States or Houston, Texas, United States
Job Summary
Conduct regulatory compliance audits, risk assessments, and investigations to ensure Kura Sushi meets legal and internal standards including CCPA/CPRA, SOX, and cybersecurity frameworks. Draft and update privacy policies, review vendor contracts for PII, and manage Data Subject Requests while maintaining Records of Processing Activities. Prepare compliance reports for the VP of ACAS and Integrated GRC Senior Manager, facilitate annual risk assessments, and coordinate with Internal Audit and cross-functional teams to remediate control deficiencies. Liaise with regulatory bodies during inspections and provide guidance to the Security team on building a compliant IT environment.
Required Qualifications
- Bachelor's degree in business, Finance, Law, Accounting, or related field
- 5 years of experience in regulatory compliance with legal, compliance and/internal audit role
- prefer multi-location restaurant and/or retail businesses background
- Big 4 consulting experience
- Proficiency with Office 365 (O365), particularly: PowerPoint, Outlook, Excel, and Word
- Proficient with regulatory requirements related to CCPA/CPRA, PCI, ESG, Information Security (Cybersecurity), Information Technology, SOX, ADA, FDA etc.
- Proficient with Optro (formerly Audit Board)-Cross Comply, Risk Oversight, BigID, Contract Management Systems, NAVEX
- Strong regulatory compliance background
- Excellent leadership and people management skills
- Skills in documenting risk, and regulatory compliance activities
- Familiar with dashboard creation
- Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with different ACAS functional areas, e.g., Security, GRC and Internal Audit to ensure appropriate compliance controls. Demonstrates ability to articulate business cases for identified technology solutions.
- Demonstrates ability to articulate regulatory compliance and information services activities to the Audit Committee or the Board, at the request of the VP of ACAS, if needed
- Excellent analytical and troubleshooting skills
- Ability to work under pressure
Desired Qualifications
- MBA, Juris Doctorate, Information Technology or advanced degree preferred
- Prefer Juris Doctorate degree with compliance certifications such as: Certified Information Privacy Professional (CIPP/US), Certified Regulatory Compliance Manager (CRCM), Certified Compliance & Ethics Professional (CCEP); desirable to possess CIA/CISA/CPA certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.