Sr. Analyst, Technology Compliance

CarMax

Richmond (VA)

On-site

USD 120,000 - 150,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Onsite at Richmond VA

Job summary

CarMax is seeking a Senior Technology Compliance Analyst to strengthen the IT control environment. The role focuses on designing controls, validating compliance, and enabling automated evidence collection across domains such as PCI DSS, HIPAA, and data privacy.

The ideal candidate has 5+ years in IT compliance, relevant certifications, and strong communication skills to drive remediation and cross-functional collaboration in a fast-paced environment.

Qualifications

  • Bachelor's degree or equivalent experience in IT audit or compliance.
  • Familiarity with NIST, OWASP, SANS, ISO-27001/2, Cobit frameworks.
  • 5+ years in enterprise technology compliance, ITGC and PCI assessments.
  • CISA and/or CISSP required; CRISC, CIA, CISM, PCI are a plus.
  • Strong communication, analytical, and mentoring abilities.

Responsibilities

  • Develop and maintain a framework for technology compliance across IT domains (PCI DSS, HIPAA, Data Privacy).
  • Execute enterprise governance frameworks and translate findings into actionable steps.
  • Lead assessments and pre-implementation reviews to ensure controls are designed and documented.
  • Design, implement, and maintain enterprise-wide GITCs and compliance programs.
  • Enforce processes to align with policies, laws, and standards (NIST, ITIL).
  • Advise on strategy, risk, and remediation; partner to evaluate control effectiveness.
  • Assist management in automation and configuration to support evidence collection.
  • Facilitate internal and external audits and communicate findings clearly.
  • Monitor controls, analyze weakness trends, and propose enhancements.

Education

Bachelor's degree or equivalent in IT auditing/compliance

Job description

What you will do – Essential Responsibilities
  • Develop and maintain a comprehensive framework for Technology Compliance, including validation, classification, and control testing across IT domains (e.g., PCI DSS, HIPAA, Data Privacy).
  • Execute enterprise compliance governance frameworks, balancing risk appetite with business needs and translating findings into actionable steps.
  • Lead compliance assessments and pre-implementation reviews to ensure proper controls are designed, implemented, and documented.
  • Design, implement, and maintain enterprise-wide General IT Controls (GITCs) and compliance frameworks aligned with regulatory requirements (PCI DSS, SOX, HIPAA, Data Privacy, etc.).
  • Develop and enforce processes and procedures to ensure adherence to company policies, laws, and industry standards (e.g., NIST, ITIL).
  • Influence compliance strategy and direction within established standards and guidance.
  • Act as a trusted advisor and subject matter expert on technology key controls, partnering to evaluate control effectiveness, identify risks, and support remediation efforts.
  • Leverage technical experience to assist management in designing appropriate automation and system configurations to support the enforcement and collection of compliance-related evidence.
  • Facilitate internal and external audits, and provide clear, timely communication of findings, recommendations, and remediation plans.
  • Monitor and validate information security controls, analyze trends in control weaknesses, and recommend enhancements to meet evolving compliance standards.
  • Collaborate cross-functionally while demonstrating ownership, initiative, and effective communication on compliance matters.
  • Execute enterprise compliance governance frameworks, balancing risk appetite with business needs and translating findings into actionable steps.
  • Assess compliance exposure and deficiencies across internal and external systems, recommending effective solutions.
  • Lead remediation and design review meetings, build consensus on compliance strategies, and influence direction across teams.
  • Maintain awareness of emerging technology trends and evolving external regulations to proactively adapt compliance processes.
Purpose of the role

As a Senior Technology Compliance Analyst, you will play a pivotal role in strengthening our IT control environment by driving innovation, collaboration, and continuous improvement. You will work closely with product, technology, and compliance teams to design controls, assist with control execution, and perform testing and validation. This role is ideal for someone who thrives in a fast-paced environment, is passionate about technology and compliance, and embraces automation and data-driven insights to modernize practices. Success in this role requires strong communication skills, attention to detail, a proactive mindset, and a commitment to delivering high-impact solutions that enhance operational resilience and ensure regulatory alignment.

Qualifications and Requirements
  • Bachelor's degree (or equivalent experience), with solid IT audit or compliance experience.
  • Familiarity with Technology Compliance management industry frameworks and standards: NIST, OWASP, SANS, ISO-27001/2, SANS, and Cobit
  • 5+ years working experience with enterprise technology compliance management programs, or auditing experience, controls testing, conducting ITGC and PCI assessments
  • Possession of industry certifications required: CISA and/or CISSP. Desired CRISC, CIA, CISM, PCI
  • Strong Communication skills with the ability to clearly communicate through tailored messaging, organized presentations, and group facilitation.
  • Strong technical skills with the ability to design IT controls and system functions that enforce or collect compliance evidence.
  • Demonstrates expertise in mentoring colleagues on compliance principles and leads effective training and awareness programs.
  • Demonstrates strong analytical, problem-solving, and organizational skills under pressure, with a commitment to world-class service, flexibility, and continuous improvement.
  • Effective organization and time management skills with strong attention to detail.

Work Location and Arrangement: This role will be based out of the Richmond, VA Technology Innovation Center. Associates based in Richmond work onsite 5 days per week.

Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Senior IT Controls & Compliance Analyst
Remote Senior IT Controls & Compliance Analyst

Compass Group USA • Georgia

Hybrid
USD 110,000 - 160,000
Medical insurance
Vision plan
Retirement plan
+2
Compliance Analyst
Compliance Analyst

ThinkTech Advisors • Greensboro (NC)

Hybrid
USD 52,000 - 65,000
Profit sharing
Overtime eligibility
Hybrid work environment (Raleigh/Grens
IT Compliance Auditor
IT Compliance Auditor

Compunnel, Inc. • Irving (TX)

On-site
USD 90,000 - 120,000
Compliance and Risk Analyst - PCC
Compliance and Risk Analyst - PCC

ViziRecruiter,LLC. • Merrimack (NH)

On-site
USD 70,000 - 90,000
401k plans
Medical insurance
Mental health resources
+1
IT Security Compliance Analyst
IT Security Compliance Analyst

Technology Recruiting Solutions • Dallas (TX)

On-site
USD 80,000 - 110,000
Governance Analyst
Governance Analyst

SMART TECH SKILLS LLC • Boston (MA)

On-site
USD 140,000 - 170,000
Competitive salary
IT SOX Compliance Specialist
IT SOX Compliance Specialist

Compunnel Inc. • Richmond (VA)

Remote
IT Compliance Analyst
IT Compliance Analyst

QUANTUM COMPUTING, INC. • Hoboken (NJ)

On-site
USD 80,000 - 100,000
Compliance Analyst
Compliance Analyst

Forbes Technical Consulting • Chicago (IL)

Hybrid
USD 65,000 - 85,000
Cyber Security Controls Assessor
Cyber Security Controls Assessor

Heyer Expectations LLC • Oakland (CA)

On-site
USD 90,000 - 120,000