Cybersecurity Compliance Analyst

Hobbsnews

Columbus, Northern (IN, KY)

Hybrid

USD 85,000 - 115,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cummins in Columbus, IN is seeking a Cybersecurity Compliance Analyst to lead risk identification and assessment within corporate IT. You will guide mitigation strategies and implement controls to strengthen security across critical systems and data.

Apply frameworks like NIST, ISO, ITIL, and COBIT while coordinating with business and technology stakeholders. You will mentor teammates and promote a culture of cybersecurity excellence through proactive governance.

Qualifications

  • Degree in Cybersecurity, CS, or IT or related field, or relevant experience.
  • 3–5 years of relevant work experience.
  • Licensing for export controls or sanctions regulations may be required.
  • Experience with HIPAA and PCI compliance is advantageous.

Responsibilities

  • Lead cybersecurity risk identification and assessment using Cummins frameworks and prioritize threats.
  • Provide guidance on risk severity, mitigation strategies, and control implementation.
  • Advise stakeholders on secure technology decisions and cybersecurity best practices.
  • Apply cybersecurity policies and data privacy principles to protect systems and data.
  • Leverage NIST, ISO, ITIL, and COBIT to align controls with processes and compliance.
  • Deliver technical cybersecurity expertise for secure design, deployment, and operations.
  • Build cross-functional relationships to drive collaboration and measurable business value.

Skills

Cybersecurity risk management
Regulatory risk compliance
Stakeholder management
Threat assessment

Education

Bachelor's degree in Cybersecurity, Computer Science, or Information Technology

Job description

We are looking for a talented Cybersecurity Compliance Analyst to join our team specializing in Systems/Information Technology for our Corporate organization in Columbus, IN.

In this role, you will make an impact in the following ways:
  • Lead cybersecurity risk identification and assessment efforts, ensuring potential threats are evaluated using Cummins risk management frameworks and prioritized appropriately.
  • Provide expert guidance on risk severity, mitigation strategies, and control implementation to strengthen the organization's security posture.
  • Serve as a trusted advisor to business and technology stakeholders by influencing secure technology decisions and promoting cybersecurity best practices.
  • Apply Cummins cybersecurity policies and data privacy principles to protect critical systems, information, and business operations.
  • Leverage industry frameworks such as NIST, ISO, ITIL, and COBIT to align security controls with organizational processes and compliance requirements.
  • Deliver technical cybersecurity expertise for new and existing technology solutions, helping ensure secure design, deployment, and ongoing operations.
  • Build and maintain strong cross-functional relationships that drive collaboration, trust, and measurable business value through effective Business Relationship Management practices.
  • Coach, mentor, and develop less experienced team members, fostering a culture of continuous learning, accountability, and cybersecurity excellence.
To be successful in this role you will need the following:
  • Action oriented - Taking on new opportunities and tough challenges with a sense of urgency, high energy, and enthusiasm.
  • Balances stakeholders - Anticipating and balancing the needs of multiple stakeholders.
  • Business insight - Applying knowledge of business and the marketplace to advance the organization’s goals.
  • Ensures accountability - Holding self and others accountable to meet commitments.
  • Manages complexity - Making sense of complex, high quantity, and sometimes contradictory information to effectively solve problems.
  • Organizational savvy - Maneuvering comfortably through complex policy, process, and people-related organizational dynamics.
  • Persuades - Using compelling arguments to gain the support and commitment of others.
  • Resourcefulness - Securing and deploying resources effectively and efficiently.
  • Tech savvy - Anticipating and adopting innovations in business-building digital and technology applications.
  • Training Delivery - Instructs learners in a manner that engages and adjusts to individual and group needs resulting in knowledge, skills and abilities that can be applied on the job.
  • Cybersecurity Risk Management - Identifies and assesses the potential impact of Cybersecurity risks against established Cybersecurity industry frameworks, regulations and organizational policies to develop and implement risk mitigation strategies in alignment with business objectives.
  • Regulatory Risk Compliance Management - Evaluates the design and effectiveness of controls against established industry frameworks and regulations to assess adherence with legal/regulatory requirements.
  • Values differences - Recognizing the value that different perspectives and cultures bring to an organization.
Education, Licenses, Certifications:
  • College, university, or equivalent degree in Cybersecurity, Computer Science, or Information Technology, or related subject, or relevant equivalent experience required.
  • This position may require licensing for compliance with export controls or sanctions regulations.
Experience:
  • Intermediate level of relevant work experience required.
  • 3-5 years of experience
Customer Cybersecurity Survey Responses:

Review and respond to customer cybersecurity surveys, questionnaires, and related information requests within required deadlines.

Translate technical information, control evidence, and program documentation into clear, accurate, customer-appropriate responses.

Maintain a catalog of standard responses and supporting evidence to improve consistency, efficiency, and reuse.

HIPAA Compliance Support:

Support HIPAA cybersecurity compliance activities related to electronic protected health information (ePHI), documentation, evidence collection, and control alignment.

Gather and organize information related to administrative, physical, and technical safeguards.

Partner with privacy, legal, IT, security, and business stakeholders on HIPAA-related inquiries, assessments, and evidence readiness.

PCI Compliance Support:

Support PCI DSS compliance activities, including evidence collection, assessment preparation, control documentation, and response coordination.

Coordinate with business, IT, application, infrastructure, and security stakeholders to obtain accurate PCI information and evidence.

Maintain PCI response materials, control narratives, and reusable documentation for audits, assessments, and stakeholder requests.

Data Collection, Stakeholder Coordination & Evidence Management:

Identify information owners and coordinate across teams to collect required documentation, evidence, and approvals.

Validate that information is responsive to the request, aligned to control intent, and appropriate for the intended audience.

Maintain organized records of evidence, decisions, response rationale, supporting documentation, and GRC updates.

Compliance Monitoring, Metrics & Reporting:

Track and report status for PCI, HIPAA, and customer request activities, including open items, due dates, blockers, and completion status.

Prepare compliance summaries, status updates, and leadership-ready reporting as needed.

Identify recurring trends, process gaps, and improvement opportunities across compliance response workflows and knowledge management practices.

100% On-Site No

As Cummins continues to grow, you'll be provided with continuous learning opportunities, supportive benefits and a culture that values your wellbeing, safety and work-life balance. Here, you'll have the power to determine your future with innovative technology, a focus on sustainability and with a company positioned for long-term growth.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Compliance Analyst
Cybersecurity Compliance Analyst

PowerToFly • Columbus (OH)

On-site
USD 85,000 - 110,000
Cybersecurity Assurance Analyst
Cybersecurity Assurance Analyst

Hobbsnews • Columbus (IN), Northern (KY)

Hybrid
USD 80,000 - 120,000
Cybersecurity Assurance Analyst
Cybersecurity Assurance Analyst

Cummins Inc. • Lansing (MI)

On-site
USD 90,000 - 130,000
Cybersecurity Remediation Specialist
Cybersecurity Remediation Specialist

Hobbsnews • Columbus (IN), Northern (KY)

Hybrid
USD 80,000 - 110,000
Cybersecurity Compliance Lead: HIPAA & PCI Controls
Cybersecurity Compliance Lead: HIPAA & PCI Controls

PowerToFly • Columbus (OH)

On-site
USD 85,000 - 110,000
Cybersecurity Risk & Assurance Analyst
Cybersecurity Risk & Assurance Analyst

Hobbsnews • Columbus (IN), Northern (KY)

Hybrid
USD 80,000 - 120,000
Cross-functional Engineering Associate - OCU - Technical - 1st Shift
Cross-functional Engineering Associate - OCU - Technical - 1st Shift

Cummins Inc. • Columbus (IN)

On-site
USD 55,000 - 95,000
Relocation assistance
Cybersecurity Compliance Specialist: Risk & Controls
Cybersecurity Compliance Specialist: Risk & Controls

Hobbsnews • Columbus (IN), Northern (KY)

Hybrid
USD 85,000 - 115,000
Strategic Cybersecurity Assurance Analyst
Strategic Cybersecurity Assurance Analyst

Cummins Inc. • Lansing (MI)

On-site
USD 90,000 - 130,000
Principal Technical Engineer – Identity Access Management
Principal Technical Engineer – Identity Access Management

PowerToFly • Georgia

On-site
USD 100,000 - 140,000