IT - Security Compliance Analyst II

GFB

Macon (GA)

On-site

USD 65,000 - 90,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

GFB is seeking a Security & Compliance Analyst to help develop and refine security policies, map controls to industry frameworks, and conduct risk assessments. You will coordinate with internal teams and vendors to ensure regulatory alignment and effective remediation of findings.

The role requires strong communication, documentation, and the ability to translate complex requirements into actionable guidance. On-site position with growth opportunities in a evolving security program.

Qualifications

  • Bachelor's degree or equivalent in IT, security, risk, or related field.
  • Experience in information security, compliance, governance, risk management, or audit.
  • Familiarity with security policies, standards, procedures.
  • Exposure to risk assessments, control testing, audit support.

Responsibilities

  • Adhere to, evaluate, and assist in the development of security policies, standards, and procedures; recommend updates to align with legal, regulatory, and business requirements.
  • Perform security and compliance assessments to evaluate adherence to internal policies, standards, and applicable regulatory frameworks.
  • Assist in identifying control gaps, document findings, and support remediation activities.
  • Track compliance status, risks, exceptions, and remediation activities, ensuring documentation and evidence is maintained.
  • Assist in internal and external risk assessments, including identifying, analyzing, and documenting security and compliance risks.
  • Maintain knowledge of relevant security and privacy frameworks and regulations (e.g., NIST, CIS, ISO, NAIC, PCI, SOX, HIPAA).
  • Deliver guidance and awareness materials to internal teams based on established policies and direction.
  • Monitor regulatory changes and provide updates to management for review and direction.
  • Prepare compliance metrics, status reports, and risk summaries for management review.
  • Document activities, assessments, issues, and remediation tracking in designated systems or tools.
  • Complete tasks and projects as assigned.
  • Escalate issues, risks, and exceptions to management.

Skills

Policy development
Security governance
Risk assessment
Compliance awareness
Documentation
Stakeholder communication

Education

Bachelor’s degree in Information Technology, Information Security, Risk Management, Business

Tools

NIST CSF
NIST SP 800-53
ISO/IEC 27001
CIS Controls

Job description

Home Office

1620 BASS RD

MACON, GA 31210, USA

Home Office

1620 BASS RD

MACON, GA 31210, USA

  • Adhere to, evaluate, and assist in the development of security policies, standards, and procedures; recommend updates to align with legal, regulatory, and business requirements.
  • Perform security and compliance assessments to evaluate adherence to internal policies, standards, and applicable regulatory frameworks.
  • Assist in identifying control gaps, document findings, and support management and stakeholders in remediation activities.
  • Track compliance status, risks, exceptions, and remediation activities, ensuring appropriate documentation and evidence is maintained.
  • Assist in internal and external risk assessments, including identifying, analyzing, and documenting security and compliance risks.
  • Maintain working knowledge of relevant security and privacy frameworks and regulations (e.g., NIST, CIS, ISO, NAIC, PCI, SOX, HIPAA, or similar, as applicable).
  • Assist in delivering guidance and awareness materials to internal teams based on established policies and direction.
  • Monitor changes in regulatory requirements, industry standards, and emerging risks, and provide updates to management for review and direction.
  • Prepare compliance metrics, status reports, and risk summaries for management review.
  • Document activities, assessments, issues, and remediation tracking within designated systems or tools.
  • Complete task and project work as assigned.
  • Escalates issues, risks, and exceptions to management for review and decision-making.

OTHER RESPONSIBILITIES/REQUIREMENTS:

  • Develop and maintain positive working relationships with internal and third-party vendors as needed.
  • Provide management and team members with clear, accurate, and timely information regarding compliance posture, risks, and issues.
  • Continually improve the security program by identifying gaps in documentation, processes, or controls, and recommending enhancements.
  • Demonstrate strong communication and interpersonal skills with the ability to interact effectively with both technical and non-technical stakeholders.
  • Support team members by sharing knowledge of security and compliance practices.
  • Ability to follow sound business ethics when executing job responsibilities.
  • Demonstrate a commitment to continuous learning and professional development.
  • Be a self-motivated individual with the ability to complete assigned tasks and priorities within established timelines, escalating issues or competing demands to management as needed.

QUALIFICATION, EDUCATION AND EXPERIENCE REQUIREMENTS:

  • Bachelor’s degree in Information Technology, Information Security, Risk Management, Business, or a related field, or an equivalent combination of education, training, and experience.
  • Background or experience in information security, compliance, governance, risk management, audit, IT operations, or a related discipline is desired.
  • Familiarity with developing, maintaining, reviewing, or assessing security policies, standards, and procedures.
  • Exposure to security or compliance assessments, risk evaluations, audit support activities, or control testing is beneficial.
  • General understanding of IT systems, security controls, and enterprise technology environments.
  • Experience working with, interpreting, or mapping controls to recognized frameworks such as NIST CSF, NIST SP 800-53, CIS Controls, ISO/IEC 27001, or similar.
  • Knowledge of regulatory, legal, or contractual security and compliance expectations in regulated or complex environments.
  • Security-related professional certifications (e.g., Security+, CISSP, CISA, CISM, CRISC, or similar) are a plus.
  • Strong organizational, analytical, and documentation skills with attention to detail.
  • Ability to interpret requirements and translate them into clear, practical, and business-aligned guidance.
  • Strong written and verbal communication skills, with the ability to engage effectively with both technical and non-technical stakeholders.
  • Demonstrates curiosity and willingness to learn, with interest in understanding the "what", "why", and "how" behind security controls and compliance requirements.
  • Self-motivated, adaptable, and comfortable working in an evolving security and compliance program.

SUPERVISORY RESPONSIBILITIES:

None

PHYSICAL DEMANDS/WORK ENVIRONMENT:

None

The above statements reflect the general details necessary to describe the principle functions of the occupation described and shall not be construed as a detailed description of all the work requirements that may be inherent in the occupation.

Qualifications
Skills
Behaviors

:

Motivations

:

Education
Experience
Licenses & Certifications

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT - Security Compliance Analyst II
IT - Security Compliance Analyst II

Georgia Farm Bureau • Alabama

On-site
USD 60,000 - 80,000
IT - Security Compliance Analyst II
IT - Security Compliance Analyst II

Georgia Farm Bureau • Macon (GA)

On-site
USD 70,000 - 110,000
Enterprise Security Analyst II
Enterprise Security Analyst II

Associated Credit Union • Peachtree Corners (GA)

On-site
Information Security Analyst
Information Security Analyst

Comtech LLC • Atlanta (GA)

On-site
USD 80,000 - 120,000
Security Analyst (NIST/CMMC) _ Atlanta, GA (Local /Direct)
Security Analyst (NIST/CMMC) _ Atlanta, GA (Local /Direct)

Datum Technologies Group • Atlanta (GA)

On-site
USD 90,000 - 130,000
IT Security Administrator
IT Security Administrator

Daikin Comfort • Waller (TX)

On-site
USD 65,000 - 90,000
Information Security Analyst
Information Security Analyst

Key2Source Inc • Atlanta (GA)

On-site
USD 90,000 - 120,000
Information Security Compliance Specialist
Information Security Compliance Specialist

Securiport • Reston (VA)

On-site
USD 75,000 - 95,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Information Systems Security Officer
Information Systems Security Officer

Georgia Institute of Technology • Atlanta (GA)

On-site
USD 78,000 - 114,000