Compliance Program Analystst

Infosys Limited

Santiago

Presencial

CLP 56.603.773 - 84.905.660

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Infosys Chile is seeking a Compliance Program Analyst to join the ATE Compliance Program. You will validate ITGC, ISP, and QMS controls, test evidence, facilitate audits, and support control design conversations.

You will partner with IT product teams, security, risk management, and auditors to ensure compliance and audit readiness throughout the year. You will focus on ITGC control testing, understand PwC's ISP and Controls Standard, and help teams apply requirements to their environments while

Formación

  • Experience in compliance testing across ISP, ITGC, and QMS domains.
  • Ability to review and validate evidence for audits and controls.
  • Proven capability to communicate complex controls to cross-functional teams.

Responsabilidades

  • ITGC control testing and validation across access, change, operations, and security domains.
  • Test and validate ISP and Controls Standard application to environments.
  • Audit facilitation, evidence collection, validation, and delivery to auditors.
  • QMS testing for Global and Territory-specific controls with evidence management.
  • Provide clear test results, escalate deficiencies with practical recommendations.
  • Support control design conversations and stakeholder engagement across teams.
  • Prepare compliance status reports and maintain dashboards for CPL.

Conocimientos

ITGC control testing
QMS control testing
Standards expertise
Complex problem solving
Strong communication
Stakeholder management
Coordination and organization
Collaboration
Attention to detail
Proactivity
Adaptability
Learning orientation
Analytical thinking

Descripción del empleo

Domain|Compliance Services|Compliance Services|Assessment & implementation of Regulatory Standards, Domain|Design & Implementation of Common Control Framework

Domain

Delivery

Interest Group

Infy Chile

Company

IL Chile

Requisition ID

150976BR

Infosys Chile is looking for a Compliance Program Analyst. Your role will be: Be a critical part of the ATE Compliance Program, reporting directly to the Compliance Program Lead. Your focus? Understanding client's compliance standards inside and out — and helping the teams around you apply them correctly. This role centers on validating that controls are designed and operating effectively across ITGC, ISP, and QMS domains. You'll test controls, review evidence, facilitate audits, field inquiries, support escalations, and contribute to control design conversations — making sure the right standards are understood, applied, and met. You'll also support Quality Management System (QMS) testing for both Global and Territory-specific controls, including facilitating audit evidence collection, validation, and delivery throughout the year. You won't work in isolation. You'll partner with IT product teams, security, risk management, QMS resource owners, and internal/external auditors — serving as a knowledgeable, responsive resource who helps teams stay compliant and audit-ready.

Your main activities will be:ITGC control testing and validation (primary focus)

Develop a deep understanding of PwC's Information Security Policy (ISP) and Controls Standard — and help product and technology teams understand and apply the requirements to their environments.

Test and validate that ITGC controls are designed effectively and operating as intended across key domains — Access Controls, System Development and Change Management, Cyber Security and Data Protection, Service Management, and Resilience.

Validate controls across:

Identity and access management — confirm that provisioning and de-provisioning, privileged access reviews, segregation of duties, and authentication mechanisms are in place and functioning as required.

Change management — verify that SDLC controls, change management procedures, emergency change processes, and application development security controls are designed appropriately and operating effectively.

Cyber security operations — validate that incident management, malware protection, vulnerability and patch management, encryption, certificate administration, and logging and monitoring controls meet ISP requirements.

Database and network controls — confirm that database configuration and administration, firewall configuration, and system performance monitoring are compliant and evidenced.

Resilience — validate that business continuity and disaster recovery plans have been tested (at a minimum, annually) and that evidence supports compliance.

Validate that application penetration testing has been performed by independent third parties in accordance with ISP requirements. Review and validate the evidence, ensure it's complete and audit-ready, and provide it in support of audit requests. Escalate any gaps or concerns to the CPL.

Perform compliance checks to assess adherence against PwC's ISP, controls, and relevant standards — reviewing vulnerability scans, security control validations, and other evidence to confirm controls are met.

Evaluate control design and operating effectiveness. Document test results clearly and escalate deficiencies, gaps, or areas of concern to the CPL with practical recommendations.

Support control design conversations with product and technology teams — helping them understand what 'good' looks like and how to meet ISP and ITGC requirements before issues arise.

QMS testing — Global and Territory-specific controls

Support QMS control testing for both Global controls (firm-wide standards) and Territory-specific controls (local and regional regulatory and operational requirements).

Validate that QMS controls are designed effectively and operating as intended across applicable territories — through walkthroughs, sample testing, re-performance, and inspection.

Review and validate QMS evidence for completeness, accuracy, and audit-readiness. Facilitate evidence delivery to auditors and QMS program owners as needed.

Audit facilitation and evidence management

Facilitate internal and external audits — SOC 2, ISO 27001, 7216, and internal control reviews — on behalf of the CPL. That means fielding auditor inquiries, coordinating evidence requests, and ensuring smooth execution throughout the audit lifecycle.

Collect, review, and validate audit evidence to confirm it's complete, accurate, and aligned to the control requirements being tested. If something's missing or insufficient, follow up with control owners to close the gap.

Maintain audit-ready repositories of evidence, policies, control documentation, and test results — covering both ITGC and QMS testing artefacts.

Support walkthroughs and access reviews. Ensure teams are prepared, evidence is organized, and auditor questions are addressed promptly.

Serve as a responsive point of contact during audits — fielding questions, coordinating across teams, and escalating issues to the CPL when needed.

Inquiries, escalations, and control design support

Field compliance-related inquiries from product teams, control owners, and stakeholders. Provide clear, accurate guidance grounded in ISP, ITGC, and QMS standards.

Help teams interpret and apply compliance requirements to their specific environments. Translate standards into practical, actionable guidance that makes sense for the teams implementing them.

Support control design conversations — helping teams understand what's required, what evidence they'll need to produce, and how to build controls that will meet testing and audit expectations.

Escalate complex or high-risk inquiries to the CPL with context and a recommended path forward.

Track and follow up on open inquiries and escalations to ensure timely resolution.

Remediation support and continuous monitoring

Document remediation plans for audit findings, ITGC deficiencies, and QMS control gaps. Track progress through closure in coordination with product, control, and QMS owners.

Follow up with stakeholders to validate that remediation activities have been completed effectively and meet timelines and SLAs. Escalate overdue items or high-risk issues to the CPL.

Support the CPL in continuously monitoring applications and controls — confirming that compliance is maintained between audit cycles and that emerging risks are identified early.

Proactively flag potential compliance risks and control weaknesses across ITGC, ISP, and QMS domains. Bring findings and recommendations to the CPL.

Stakeholder engagement and communication

Serve as a knowledgeable, approachable point of contact for IT, security, risk management, product teams, and Global and Territory QMS program owners on behalf of the CPL.

Communicate complex compliance and control topics clearly and concisely. Whether you're explaining an ISP requirement, walking a team through a control gap, or briefing senior leadership — you adjust your message to the audience.

Support the CPL in rolling out compliance education and training to ATE stakeholders. Track completions and help drive awareness across the portfolio.

Respond promptly and accurately to stakeholder inquiries with reliable compliance data.

Reporting, metrics, and data‑driven insights

Prepare compliance status reports for the CPL and senior management — covering audit findings, ITGC and QMS control testing results, risk posture, and remediation progress.

Maintain and update compliance dashboards, trackers, and monitoring tools so metrics stay current and actionable.

Use data‑driven metrics to evaluate control testing coverage and compliance program effectiveness. Surface insights and improvement opportunities to the CPL.

Policy, procedure, and access review support

Help the CPL review and maintain compliance policies and procedures aligned to ISP, QMS, and regulatory frameworks.

Support and coordinate quarterly and ad‑hoc access reviews. Track results, exceptions, and alignment with access control standards.

Candidate core competencies are:

ITGC control testing and validation: You validate that IT General Controls are designed and operating effectively across access management, change management, operations, and security domains — with precision and confidence.

QMS control testing: You validate Global and Territory QMS controls, review evidence for completeness and accuracy, and identify gaps across jurisdictions.

Standards expertise : You understand PwC's ISP and Controls Standard deeply — and you help teams around you understand and apply them correctly.

Complex problem solving: You don't just find issues — you find root causes. You develop thoughtful recommendations under ambiguity and escalate effectively.

Strong communication: You translate complex compliance and control standards into clear, actionable guidance. Whether it's a technical team or senior leadership, you adjust and connect.

Stakeholder management: You build trust and credibility across functions and jurisdictions. You field inquiries with confidence, support control design conversations with clarity, and manage competing priorities diplomatically.

Coordination and organization: Multiple audits, testing cycles, evidence requests, remediation workstreams, and reporting deadlines — you manage them simultaneously with precision and reliability.

Collaboration: You work seamlessly across IT, security, risk, product, QMS, and audit teams to support the CPL and drive outcomes.

Attention to detail: You validate evidence with care — confirming completeness, accuracy, and alignment to control requirements.

Proactivity: You flag potential compliance gaps and control weaknesses early — before they become audit findings.

Adaptability: Shifting priorities, cross-jurisdictional complexity, and ambiguous situations don't slow you down. You move forward with composure and sound judgement.

Learning orientation: You're always expanding your knowledge of ITGC, QMS, ISP frameworks, control testing practices, and emerging regulatory requirements.

Analytical thinking: You leverage data and metrics to evaluate compliance effectiveness and surface actionable insights to the CPL.

Technical skills

Proficiency in SOC 2, ISO 27001, 7216, and ISP control frameworks.

Experience with ITGC and QMS testing methodologies — walkthroughs, sample testing, re-performance, and inspection.

Familiarity with vulnerability scanning tools, penetration testing evidence review, and security monitoring.

Proficient in Microsoft Office, evidence management platforms, GRC tools, and compliance reporting and dashboard tools.

Understanding access control systems, identity management, encryption standards, and change management workflows.

Familiarity with Global and Territory-specific regulatory and quality management requirements.

Certifications (preferred)

CISA (Certified Information Systems Auditor) — strongly preferred.

CRISC (Certified in Risk and Information Systems Control).

ISO 42001 or QMS-related certifications.

ITGC-specific training or certifications.

English fluency and 5 years of experience in similar roles are required. Work will be performed on a hybrid modality

About UsInfosys is a global leader in next-generation digital services and consulting. We enable clients in more than 50 countries to navigate their digital transformation. With over four decades of experience in managing the systems and workings of global enterprises, we expertly steer our clients through their digital journey. We do it by enabling the enterprise with an AI‑powered core that helps prioritize the execution of change. We also empower the business with agile digital at scale to deliver unprecedented levels of performance and customer delight. Our always‑on learning agenda drives their continuous improvement through building and transferring digital skills, expertise, and ideas from our innovation ecosystem.

EEOInfosys provides equal employment opportunities to applicants and employees without regard to race; color; sex; gender identity; sexual orientation; religious practices and observances; national origin; pregnancy, childbirth, or related medical conditions; or disability.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Compliance Program Analystst
Compliance Program Analystst

Infosys • Santiago

Híbrido
CLP 18.000.000 - 32.000.000
Compliance Program Analyst
Compliance Program Analyst

Infosys • Santiago

Híbrido
CLP 20.000.000 - 40.000.000
Compliance Program Analyst: ITGC & QMS Audit Readiness
Compliance Program Analyst: ITGC & QMS Audit Readiness

Infosys Limited • Santiago

Híbrido
CLP 56.603.000 - 84.906.000
Hybrid ITGC & ISP/QMS Compliance Analyst
Hybrid ITGC & ISP/QMS Compliance Analyst

Infosys • Santiago

Híbrido
CLP 18.000.000 - 32.000.000
Compliance Program Analyst: ITGC & QMS Auditing
Compliance Program Analyst: ITGC & QMS Auditing

Infosys • Santiago

Híbrido
CLP 20.000.000 - 40.000.000
IT / GRC External Auditor SOC 2 - LATAM
IT / GRC External Auditor SOC 2 - LATAM

Insight Assurance • Santiago

Presencial
CLP 40.834.000 - 68.059.000
Flexible Paid Time Off
Performance Bonuses
100% Remote
Operational Continuity Engineer
Operational Continuity Engineer

Infosys Limited • Santiago

Híbrido
CLP 7.000.000 - 11.000.000
DevOps Engineer -Azure
DevOps Engineer -Azure

Infosys Limited • Chile

Presencial
CLP 25.000.000 - 45.000.000
Senior Network Engineer
Senior Network Engineer

Infosys Limited • Santiago

Híbrido
CLP 18.000.000 - 32.000.000
Site Reliability Engineer (SRE)
Site Reliability Engineer (SRE)

Infosys Limited • Santiago

Híbrido
CLP 20.088.000 - 37.944.000