Senior Advisor, Security Controls & Compliance

InterContinental Hotels Group

Atlanta (GA)

Hybrid

USD 110,000 - 140,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

InterContinental Hotels Group is seeking a Senior Analyst IT Information Security to lead senior-level security controls and compliance programs across SOX, PCI, SWIFT, SOC 1/SOC 2, and privacy. The role partners with Security Risk, Governance, Privacy, and external auditors to strengthen control accountability and drive remediation.

You will coordinate RFIs, findings, and remediation tracking, maintain control documentation, and deliver concise executive updates to leadership while supporting

Qualifications

  • Bachelor's or Master's degree in Computer Information Systems, IT, Cybersecurity, Audit, Risk Management, or equivalent years of relevant work experience.
  • 5+ years of progressive experience in information security, IT audit, technology risk, compliance, controls management, or related technology governance roles.
  • Experience coordinating internal or external audits and regulatory compliance activities across frameworks such as SOX, PCI, SWIFT, SOC 1, SOC 2, privacy, NIST, ISO, COBIT, or related control frameworks.
  • Demonstrated experience working with auditors, control owners, technology leaders, and cross-functional teams to manage RFIs, walkthroughs, findings, remediation, and executive reporting.

Responsibilities

  • Lead assigned regulatory compliance programs and control portfolios across SOX, PCI, SWIFT, SOC 1/SOC 2, privacy, and other security control areas, ensuring scope, inventories, evidence expectations, and audit timelines are clearly defined and actively managed.
  • Serve as senior control advisor and escalation point for assigned stakeholders, compliance partners, and delivery resources, providing guidance on control design, operating effectiveness, audit response quality, and remediation approach.
  • Manage auditor coordination, RFIs, walkthroughs, findings, and remediation tracking by holding auditors and control owners to milestones and ensuring timely escalation with clear risk framing.
  • Maintain and improve compliance scope, control documentation, and control library data in partnership with GRC, ServiceNow, Axonius, Technology, and Security teams.
  • Build strong relationships with VP-level control owners, BISOs, Privacy, Financial Governance, Security Architecture, and external audit partners to identify risks and promote accountability.
  • Support regulatory transformation and recurring gap remediation by identifying root causes and developing practical remediation plans.
  • Provide concise status reporting and executive-ready updates on audit progress, RFIs, findings, indicators, risks, issues, and milestones.
  • Contribute to control automation and continuous monitoring initiatives by identifying candidate controls and validating business requirements.

Skills

Stakeholder management
Auditing coordination
Regulatory compliance
Communication
Independent work
Risk assessment

Education

Bachelor's or Master's Degree in Computer Information Systems / IT / Cybersecurity / Audit / Risk Management

Tools

ServiceNow
Axonius

Job description

As the Senior Analyst IT Information Security responsible for leading senior-level security controls and compliance activities across regulatory and audit programs, including SOX, PCI, SWIFT, SOC 1/SOC 2, privacy-related assessments, and control management. This role provides control advisory support, coordinates auditor and stakeholder engagement, manages RFIs and findings, maintains compliance scope and control documentation, and drives timely remediation of control gaps.

The role partners closely with Security Risk, Governance, Technology, Privacy, Financial Governance, BISOs, external auditors, and delivery partners to strengthen control accountability, improve audit readiness, and provide clear reporting on status, risks, issues, and decisions needed by leadership.

Your Day To Day
  • Lead assigned regulatory compliance programs and control portfolios across SOX, PCI, SWIFT, SOC 1/SOC 2, privacy, and other security control areas, ensuring scope, inventories, evidence expectations, and audit timelines are clearly defined and actively managed.
  • Serve as senior control advisor and escalation point for assigned stakeholders, compliance partners, and delivery resources, providing guidance on control design, operating effectiveness, audit response quality, and remediation approach.
  • Manage auditor coordination, RFIs, walkthroughs, findings, and remediation tracking by holding auditors and control owners accountable to milestones, improving quality of responses, and ensuring issues are escalated early with clear risk and impact framing.
  • Maintain and improve compliance scope, control documentation, and control library data in partnership with GRC, ServiceNow, Axonius, Technology, and Security teams, ensuring control attributes, scope tags, ownership, and evidence requirements remain current and audit-ready.
  • Build strong relationships with VP-level control owners, BISOs, Privacy, Financial Governance, Security Architecture, GIO, GPP, Product & Technology, and external audit partners to identify risks, resolve control gaps, and promote accountability for compliance outcomes.
  • Support regulatory transformation and recurring gap remediation by identifying root causes, developing practical remediation plans, coordinating cross-functional follow-up, and helping implement sustainable control improvements.
  • Provide concise status reporting and executive-ready updates on audit progress, RFIs, findings, indicators, risks, issues, decisions needed, and upcoming milestones for Director, SVP, CISO, and stakeholder reporting.
  • Contribute to control automation and continuous monitoring initiatives by identifying candidate controls, validating business requirements, and ensuring automated indicators and dashboards support regulatory and operational compliance needs without owning the continuous controls monitoring capability.
What We Need From You
  • Bachelor's or Master's Degree in Computer Information Systems, Information Technology, Cybersecurity, Business, Audit, Risk Management, or equivalent years of relevant work experience.
  • 5+ years of progressive experience in information security, IT audit, technology risk, compliance, controls management, or related technology governance roles.
  • Experience coordinating internal or external audits and regulatory compliance activities across frameworks such as SOX, PCI, SWIFT, SOC 1, SOC 2, privacy, NIST, ISO, COBIT, or related control frameworks.
  • Demonstrated experience working with auditors, control owners, technology leaders, and cross-functional teams to manage RFIs, walkthroughs, findings, remediation, and executive reporting.
  • Strong working knowledge of IT general controls, application controls, infrastructure controls, identity and access controls, change management, vulnerability management, incident management, and compliance evidence expectations.
  • Ability to interpret audit requirements, challenge auditor requests where appropriate, and translate complex control topics into clear business impacts and remediation actions.
  • Experience maintaining compliance scope, control inventories, control ownership, and evidence repositories in GRC or related platforms such as ServiceNow.
  • Strong written and verbal communication skills, including the ability to prepare concise updates for Director, SVP, CISO, VP, auditor, and stakeholder audiences.
  • Strong attention to detail, judgment, accountability, stakeholder management, and ability to operate independently in a complex, global environment.
  • Working knowledge of control automation, indicators, dashboards, and analytics sufficient to support continuous monitoring initiatives and ensure outputs align to regulatory and audit needs.
Travel - 10%
Location - Our hybrid work structure is an expectation of three (3) days a week in office. This expectation may be adjusted to evolve with the changing needs of the business.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Sylvan, Inc. • Detroit (MI)

On-site
USD 90,000 - 130,000
Sr. Analyst, Technology Compliance
Sr. Analyst, Technology Compliance

CarMax • Richmond (VA)

On-site
USD 120,000 - 150,000
Onsite at Richmond VA
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Senior Manager, IT Controls & Audit Compliance
Senior Manager, IT Controls & Audit Compliance

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
Senior Manager, IT Control, Assurance, SOX
Senior Manager, IT Control, Assurance, SOX

Jobtailor • Town of Florida (NY)

On-site
USD 170,000 - 230,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Lead DI Security and Compliance Analyst
Lead DI Security and Compliance Analyst

Jobtailor • Kentucky

On-site
USD 110,000 - 165,000
Manager - IT Internal Controls
Manager - IT Internal Controls

Dana Corp • Novi (MI)

On-site
USD 120,000 - 180,000