IT Compliance Lead
$110,000–$120,000 year
On-siteOak Brook, Illinois, United States
Job Summary
Support IT compliance activities across PCI DSS, GLBA, IT controls, security awareness, and related cybersecurity requirements. Assist with IT testing, audits, assessments, and regulatory examinations by coordinating with security, IT, and stakeholders throughout the review lifecycle. Gather, prepare, and retain detailed audit-ready evidence while maintaining a centralized library of compliance documentation. Document testing results, compliance gaps, and exceptions to communicate findings clearly to control owners and management. Track and report remediation status for issues resulting from audits and regulatory findings, escalating material concerns as appropriate. Partner with information security and IT teams on key control domains including identity management, vulnerability management, and incident response. Prepare compliance metrics and dashboards for leadership and auditors to support decision-making. Monitor changes in laws and regulations to translate updates into actionable control and process improvements.
Required Qualifications
- Bachelor's degree in information technology, information security, cybersecurity, computer science, business, accounting, risk management, or a related field
- 3+ years of experience in information security, IT general controls, IT compliance, IT audit, cybersecurity governance, and/or technology risk management
- Experience supporting internal and external auditors, regulators, and cross-functional stakeholders in audits, assessments, examinations, and remediation activities
- Knowledge of security and risk frameworks, standards, and best practices, including PCI DSS v4.0.1, GLBA Safeguards Rule, NIST Cybersecurity Framework 2.0, and related guidance
- Working knowledge of key cybersecurity control areas such as access control, multifactor authentication, vulnerability management, endpoint and network security, logging and monitoring, incident response, and business continuity
- Experience with audit-ready documentation, evidence management, issue tracking, and remediation support
- Strong communication, documentation, presentation, facilitation, and stakeholder management skills, with the ability to communicate effectively with both technical teams and business stakeholders
- Strong analytical skills and experience with process improvement, automation, and continuous compliance monitoring
- Must be able to sit and/or stand for extended periods
- Must be able to lift up to 15 lbs. with little assistance
Desired Qualifications
- Experience with regulatory and compliance requirements applicable to financial services, payments, retail, or other regulated environments
- Experience with Governance, Risk, and Compliance (GRC) platforms and control management workflows
- Experience in cloud or hybrid environments, including SaaS and third-party service provider risk considerations
- Experience in retail, payments, or financial services
- Professional certifications such as CISA, CRISC, CISSP, CISM, or similar qualifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.