Chewy
At Chewy, our mission is to be the most trusted and convenient destination for pet parents and partners, everywhere.
Hybrid

Sr IT Compliance Analyst

Sorry, this job was removed at 2:34 p.m. (EST) on Wednesday, June 3, 2020
Find out who's hiring in Greater Boston Area.
See all Cybersecurity + IT jobs in Greater Boston Area
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Our Opportunity:

Chewy is looking for a Senior IT Governance, Risk & Compliance (GRC) Analyst to join our Information Technology Team based in Boston, MA or Dania Beach, FL and the ideal candidate would be able to:

What you'll do:

  • Oversee processes on development and maintenance of information security policies, standards, and procedures to address risk and security compliance requirements;
  • Work with IT Leadership to support the execution of strategies and objectives in accordance with IT Compliance frameworks, guidelines and requirements;
  • Advise and train IT process owners on best practices related to IT General Controls, IT security, remediation of any issues and deficiencies;
  • Conduct risk assessments of information systems which includes creating asset profiles, evaluating threat likelihood and impact, and identifying mitigating controls to determine inherent and residual risk to systems;
  • Help IT management to maintain an effective SOX control environment and ensure adequate controls are in place to mitigate risks;
  • Support ongoing internal audit reviews to ensure all required documentation is provided
  • Work with the IT Teams in the completion of the SOX certification for new systems and during significant upgrades/updates of existing systems;
  • Monitor and test IT compliance metrics for SOX, PCI, Cybersecurity, and Privacy to ensure the program is meeting regulatory requirements and internal corporate goals and timelines;
  • Lead the ongoing development, implementation, and enforcement of security awareness training programs, requirements and initiatives;
  • Develop training, newsletters and other educational material that is engaging and promotes adoption of security & compliance best practices;
  • Responsible for supporting Data Privacy activities including PCI and CCPA compliance.
  • Review SSAE 18 and/or third-party assessments/reviews performed by external parties.

Must have(s):

  • Sustainable knowledge of compliance requirements associated with SOX (ITGCs & ITACs), Cybersecurity and PCI;
  • Extensive knowledge of general information security best practices and standards such as ISO 27000, COBIT 5, NIST SP 800 series, NIST CSF;
  • Solid knowledge/experience in Software development life cycle, DevOps, networks, databases, operating systems, application controls and IT operations;
  • General understanding of internal audit methodologies and processes;
  • Work with Internal Audit, external auditors, IT management and staff to identify feasible implementation of controls and resolutions to manage weaknesses and create opportunities for improvement;
  • Ability to create and maintain IT policies & procedures, management and executive level reports on effectiveness of IT governance controls and exceptions;
  • Excellent interpersonal and presentation skills.
  • Ability to perform assigned tasks and responsibilities with moderate supervision, which includes planning, executing and reporting on required compliance tasks within assigned timelines
  • 5+ years of IT experience covering Internal or External IT audit, Risk Management, vulnerability management, data security, regulatory compliance, vendor management, incident response
  • Bachelor’s Degree in Information Systems, Risk Management, Business Administration, or a related field
  • At least one of the following certifications: CISA, CISM or CISSP

Nice to have(s):

  • Prior experience in eCommerce or start-up organization
  • Prior experience with implementing Service Now, GRC tool or ITSM solutions
  • Prior experience in automating controls and control testing, data analytics and Agile methodology
  • Prior experience in the following areas: risk management, internal or external IT audit, vulnerability management, data security, regulatory compliance, vendor management, incident response
  • ITIL, PMP, Six Sigma certification a plus.

If you have a disability under the Americans with Disabilities Act or similar law, or you require a religious accommodation, and you wish to discuss potential accommodations related to applying for employment at our company, please contact [email protected].

To access Chewy’s Privacy Policy, which contains information regarding information collected from job applicants and how we use it, please click here: Chewy Privacy Policy (https://www.chewy.com/app/content/privacy).

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Chewy Perks + Benefits

Chewy Benefits Overview

We offer competitive salaries and 401k, unlimited time off, comprehensive medical, dental, and vision benefits, in addition to wellness programs, online communities, and resources for improved physical and mental health... enabling you to be your best self - in and outside of work. With mentorship programs, employee resource groups, cross-functional job trainings, events, and customized development tracks for advancement, we're proud to help develop and promote our team members from within.

True to our business, we're pet-friendly and have fun pet-related perks like Paw-ternity leave for new pup parents and Chewy employee discounts. We offer countless volunteer opportunities, recreational club teams, company outings, happy hours, and team events to enable you to bond with fellow Chewtopians and have some fun!

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
We're currently 100% remote due to caution and care for the health & well-being of our team. Post-pandemic, we plan to operate in a combination of onsite and remote, with logistics still being defined
Diversity
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
We offer a commuter transit, parking, and dependent care FSA.
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Performance bonus
Child Care & Parental Leave Benefits
Childcare benefits
Generous parental leave
Family medical leave
Return-to-work program post parental leave
Vacation & Time Off Benefits
Unlimited vacation policy
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Pet friendly
Recreational clubs
Chewy sponsors office sports leagues year-round.
Relocation assistance
Professional Development Benefits
Job training & conferences
Lunch and learns
Cross-functional lunch and learns.
Promote from within
Mentorship program
Online course subscriptions available
Customized development tracks

More Jobs at Chewy

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about ChewyFind similar jobs like this