Analyst II, Cybersecurity- Information Risk Management

CarMax

Richmond (VA)

On-site

USD 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CarMax is seeking an Analyst II for Information Risk Management at the Richmond, VA Technology Innovation Center. The essential duties include coordinating data subject access requests and implementing privacy risk management programs. Ideal candidates will have a relevant Bachelor's degree, over 2 years of experience, and certifications in privacy. This role offers an opportunity to lead privacy operations and process improvements in a dynamic environment. Applicants must have valid U.S. work authorization.

Qualifications

  • 2+ years of experience in privacy, technology compliance, IT audit, cybersecurity or related field.
  • One or more privacy‑focused certifications such as CIPP, CIPM, CIPT, CIA, CRSC, CISA.
  • Experience with relevant U.S. legal frameworks and privacy regulations such as CCPA, GLBA, PCI, NYDFS, CFPB.

Responsibilities

  • Coordinate with multiple teams to process data subject access requests (DSAR).
  • Implement and measure the privacy risk management program and deliver updates with KPIs.
  • Facilitate ongoing data privacy assessments of internal systems.

Skills

Detail oriented
Analytical
Customer focus
Collaboration

Education

Bachelor’s degree in business, computer science, information systems or related field

Tools

Data analysis tools

Job description

8901 – Corp Office West Crk – 12800 Tuckahoe Creek Parkway, Richmond, VA 23238

We are looking for an Analyst II, Information Risk Management to maintain and enhance the Information Risk Management posture of an innovative and fast‑paced company that is leveraging technology to improve the car buying experience.

Responsibilities
  • Privacy Request Support – Coordinate with multiple technology teams to capture, assess and process data subject access requests (DSAR) timely and accurately.
  • Privacy Operations Management – Use service delivery principles to implement, execute and measure the program and related services consistently and effectively. Prepare and deliver regular program updates with KPIs that illustrate volumes, trends and risk areas to stakeholders. Maintain appropriate work management practices and backlogs to meet or exceed SLAs.
  • Process Improvement – Identify and implement opportunities to simplify and strengthen our privacy risk management processes and capabilities using process analysis, automation and AI where applicable.
  • Privacy Technology Administration – Utilize standalone and integrated platforms in daily operations and perform system improvements and administration.
  • Privacy Impact Assessment – Facilitate ongoing data privacy assessments of internal systems to effectively manage data sensitivity risk across the enterprise.
  • Policy Governance Lifecycle Management – Own and manage the technology and information security focused guidance to ensure all policies, procedures, standards and job aids remain current, published and available for our associates.
  • Knowledge Management – Document and maintain clear, effective reference documentation (playbooks, processes, job aids, technical diagrams) as an internal knowledge base and for ease of customer experience.
  • Projects – Participate in related strategic and tactical projects as necessary to mature the privacy operations function.
  • Exhibit ownership, follow‑through, initiative, awareness and effective communication with peers and management and ability to speak to details of privacy operations.
  • Maintain a strong knowledge base and awareness of industry and technological trends, external regulations for new or changed requirements within privacy and technology for core processes (e.g. NiST, PCI, ITIL, data privacy etc.).
Qualifications And Requirements
  • Bachelor’s degree in business, computer science, information systems or related field.
  • 2+ years of experience in privacy, technology compliance, IT audit, cybersecurity or related field.
  • One or more privacy‑focused certifications such as CIPP, CIPM, CIPT, CIA, CRSC, CISA.
  • Experience or familiarity with relevant U.S. legal frameworks and privacy regulations such as CCPA, GLBA, PCI, NYDFS, CFPB.
  • Detail oriented – possess a keen eye for detail and accuracy in all operations.
  • Analytical – ability to perform data analysis, trending, problem solve obstacles and find alternative ways to meet and achieve privacy goals.
  • Understand and implement information risk and privacy principles across disciplines applying a risk‑based approach in a fast‑paced environment.
  • Customer focus – provide exceptional customer service for internal partners, with a mindset for understanding their needs and consistently exceeding expectations.
  • Excellent verbal and written communication skills, ability to structure and deliver clear, accurate messaging and facilitate discussions.
  • Collaboration – strong emphasis on effective relationship building and partnership.
  • Demonstrate initiative, ownership, and a service‑oriented mindset in all interactions.
Work Location and Arrangement

This role will be based out of the Richmond, VA Technology Innovation Center. Associates based in Richmond work onsite 4 days per week.

Work Authorization

Applicants must be currently authorized to work in the United States on a full‑time basis. Sponsorship will not be considered for this specific role.

Equal Opportunity Employment

CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, gender expression, genetic information, national origin, protected veteran status, disability status, and any other characteristics protected by law.

Reasonable Accommodation

Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Analyst II, Cybersecurity- Information Risk Management
Analyst II, Cybersecurity- Information Risk Management

CarMax Business Services • Richmond (VA)

On-site
USD 70,000 - 90,000
Privacy & Information Risk Analyst II (Onsite Richmond)
Privacy & Information Risk Analyst II (Onsite Richmond)

CarMax • Richmond (VA)

On-site
USD 80,000 - 100,000
Privacy Operations Analyst II – AI-Driven Risk & Compliance
Privacy Operations Analyst II – AI-Driven Risk & Compliance

CarMax Business Services • Richmond (VA)

On-site
USD 70,000 - 90,000
Engineer II, Cybersecurity
Engineer II, Cybersecurity

CarMax Business Services • Richmond (VA)

On-site
USD 80,000 - 121,000
Bonus eligibility
Engineer II, Cybersecurity - Application Security
Engineer II, Cybersecurity - Application Security

CarMax Business Services • Richmond (VA)

On-site
USD 80,600 - 120,900
Bonus and equity
Sr. Advisor, Compliance Services
Sr. Advisor, Compliance Services

CarMax Business Services • Richmond (VA)

On-site
USD 82,000 - 125,000
Sick leave
Vacation time
Holiday pay
+1
Engineer II, Cybersecurity - Application Security
Engineer II, Cybersecurity - Application Security

CarMax • Richmond (VA)

On-site
USD 80,600 - 120,900
Bonus potential
Equity
Sr. Analyst, Retail Strategy & Analytics
Sr. Analyst, Retail Strategy & Analytics

CarMax • Richmond (VA)

On-site
USD 70,000 - 90,000
Engineer II, Cybersecurity
Engineer II, Cybersecurity

CarMax • Richmond (VA)

On-site
USD 80,000 - 121,000
Bonus eligibility
Equity
Sr. Auditor, IT Internal Audit
Sr. Auditor, IT Internal Audit

CarMax • Richmond (VA)

On-site
USD 80,000 - 110,000