It Compliance Analyst

Chewy Chewy · Retail · Plantation, FL +1

This role is for an entry-level GRC Analyst I to join the Cyber Governance Risk & Compliance team. The analyst will assist in assessing risk statements, mapping controls to frameworks like PCI and NIST, participating in PCI assessments, supporting control effectiveness validation, maintaining risk registers, and assisting with internal/external audits and policy reviews. The role requires familiarity with IT infrastructure and security controls, strong attention to detail, and communication skills. Experience with AI technologies and GRC tooling are considered bonuses.

What you'd actually do

  1. Assist in assessing risk statements and mapping controls to established compliance frameworks such as PCI and NIST.
  2. Participate in the execution of PCI assessments across the organization, including evidence collection, documentation review and coordination with control owners.
  3. Support subject matter experts in maintaining and validating control effectiveness, audit readiness and risk management processes.
  4. Contribute to governance, risk & compliance initiatives by assisting with compliance framework implementations.
  5. Help maintain risk registers, track remediation activities and follow up on action plans.

Skills

Required

  • Bachelor's degree or higher in Computer Science, Computer Information Systems, or similar; or equivalent experience.
  • Familiarity with industry frameworks and standards such as PCI-DSS, NIST CSF, NIST 800-53, SOC 2 or similar.
  • Comfortable reading, interpreting and analyzing policy documents, audit reports and technical control descriptions.
  • Strong attention to detail and ability to organize and manage documentation effectively.
  • Basic understanding of IT infrastructure, cloud environments, applications and security controls.
  • Strong written and verbal communication skills with the ability to collaborate across technical and non-technical teams.
  • Ability to prioritize tasks and manage multiple initiatives in a structured, deadline-driven environment.
  • A proactive mindset with a desire to learn and grow within the GRC domain.

Nice to have

  • Experience supporting PCI environments (Levels 1 – 3) or participating in formal PCI assessments.
  • Experience working in organizations with strong adoption of AI technologies and understanding associated governance or compliance considerations.
  • Exposure to GRC tooling (e.g., AuditBoard, Drata, Vanta, etc.).
  • Relevant certifications such as Security+, CISA or similar.

What the JD emphasized

  • PCI
  • NIST