
Senior Compliance and Audit Analyst
Posted Aug 13

Posted Aug 13
This is a fully remote position, open to applicants in United States.
• Address customer security inquiries, due diligence requests, security questionnaires, and RFP/RFI security sections utilizing approved content and guidelines.
• Oversee customer security, audit evidence, contract review, and third-party risk requests through ServiceNow or other authorized systems.
• Collaborate with Security, Legal, Procurement, Sales, Product teams, business owners, and technical experts.
• Craft precise customer-facing responses regarding security controls, policies, standards, certifications, audit reports, privacy practices, and compliance activities.
• Assist in customer and vendor contract evaluations related to information security, privacy, audit rights, incident notification, data protection, compliance, and third-party obligations.
• Assess customer and vendor security requirements against company policies, standards, controls, and risk guidance.
• Identify non-standard commitments, control deficiencies, policy discrepancies, ambiguous requirements, and risk indicators, escalating them as necessary.
• Coordinate, authenticate, track, and document requests for audit evidence and their approvals.
• Support third-party risk management efforts, including conducting vendor security reviews, due diligence, risk assessments, renewal evaluations, and ongoing monitoring.
• Review vendor questionnaires, certifications, audit reports, policies, and security documentation.
• Monitor the status of third-party risk assessments, questions, documentation, approvals, risk decisions, exceptions, remediation, and follow-up actions.
• Develop and sustain publicly suitable Trust Center content.
• Maintain response libraries, standard security language, FAQs, Trust Center materials, third-party risk guidance, and customer assurance content.
• Keep records of inquiries, responses, contract reviews, evidence, Trust Center updates, assessments, escalations, approvals, and outcomes.
• Supervise requests for timely completion and accurate reporting on status, volume, aging, and recurring themes.
• Identify common questions, vendor risk patterns, response gaps, evidence trends, content needs, and process challenges, recommending improvements.
• Assist in creating internal process documentation and guidance.
• Bachelor’s degree in Information Systems, Cybersecurity, Risk Management, or a related discipline, or equivalent professional experience.
• At least six (6) years of experience in information security, compliance, customer assurance, third-party risk management, audit support, contract support, customer service, vendor management, or a similar role.
• Knowledge of ISO 27001, NIST SP 800-171, GDPR, and SOC 2 is essential.
• Experience in responding to customer security inquiries, due diligence requests, security questionnaires, RFP/RFI security sections, or similar information requests.
• Understanding of security-related contract topics, including information security requirements, audit rights, incident notification, data protection, privacy, third-party obligations, and compliance requirements.
• Capability to read and interpret organizational policies, standards, procedures, customer requirements, vendor documentation, audit materials, and contract language.
• Excellent written communication skills for delivering clear, accurate, and professional responses.
• Strong attention to detail with the ability to spot inconsistencies, missing information, ambiguous language, non-standard commitments, and escalation items.
• Ability to work collaboratively with Legal, Security, Procurement, Sales, business owners, and technical subject matter experts.
• Strong organizational, documentation, and time management abilities.
• Proficiency in Microsoft Office, ServiceNow, knowledge management tools, and collaboration platforms.
• Must be authorized to work in the United States on a full-time basis.
• This position is not eligible for employer-sponsored work authorization, including OPT, TN, H1B, or other work visas.
• Experience with common controls, control mapping, or cross-framework control alignment is preferred.
• Familiarity with ServiceNow or similar ticketing, workflow, case management, or risk management tools is preferred.
• Experience in supporting third-party risk management, vendor due diligence, supplier risk assessments, or vendor security reviews is preferred.
• Professional certifications in cybersecurity, compliance, or risk-related fields are preferred but not mandatory.
• Comprehensive Health, Dental & Vision Insurance.
• Retirement 401(k) Savings Plan.
• Generous paid time off policy, including paid parental leave.
• Potential eligibility for a discretionary annual incentive plan.
• Life insurance.
• Disability retirement plans.
• Equal opportunity employment.
• Reasonable accommodation during the employment selection process.
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.