Principal Analyst, Technology Compliance
16 hours ago
About this Job
The Principal Technology Compliance Analyst is a subject matter expert in compliance management, information security controls, and auditing. This role is responsible for establishing, maintaining, and continuously improving the compliance management framework and processes in alignment with regulatory requirements and industry standards. You will collaborate with Technology management teams to evaluate and design controls, conduct compliance reviews (audits), report results, track issues, and monitor remediation plans. As a hands-on compliance expert, you will advise business and control owners, assist with compliance-related activities, and provide consulting direction on cross-functional projects. You will ensure compliance with policies, procedures, leading practices, access control, asset classification, data privacy, architecture, and company security standards.
Essential Responsibilities
- Design, implement, and maintain enterprise-wide General IT Controls (GITCs) and compliance frameworks aligned with regulatory requirements (PCI DSS, SOX, HIPAA, Data Privacy, etc.).
- Develop and enforce processes and procedures to ensure adherence to company policies, laws, and industry standards (e.g., NIST, ITIL).
- Influence compliance strategy and direction within established standards and guidance.
- Plan and execute compliance testing, control assessments, and documentation for technology environments.
- Validate key controls, identify risks, analyze root causes, and recommend improvements to meet compliance standards.
- Communicate remediation and prevention strategies using leading practices and drive completion of corrective actions.
- Facilitate internal and external audits across technology teams.
- Collaborate with GRC teams to strengthen assessment processes.
- Serve as a trusted advisor and subject matter expert for technology controls.
- Maintain strong knowledge of industry trends, regulations, and emerging standards.
- Assess, design, and implement technical improvements to control testing processes leveraging automation, AI, etc.
- Develop and deliver compliance training and awareness programs across all domains.
- Mentor team members and support professional development to foster organizational maturity.
Qualifications and Requirements
- Degree in Technology, Computer Science, or Business, with solid IT audit or compliance management experience or equivalent work experience
- 7+ years of experience with enterprise compliance, audit, and/or risk management programs, privacy, data security, and control issues across cloud and on-premises environments.
- Strong understanding of key compliance regulations (Sarbanes-Oxley, GLBA, HIPAA, PCI).
- Ability to stay abreast of industry trends, emerging threats, and changing external regulations, and adapt core compliance processes accordingly.
- Experience in designing and implementing enterprise Compliance Governance frameworks, including identification, assessment, and mitigation of compliance exposure.
- Detailed knowledge and experience with IT General Controls and operational testing procedures for SOX, PCI, and privacy.
- Ability to assess alternative compliance approaches and methodologies, both quantitatively and qualitatively, to meet business needs.
- Effective communication skills to convey risks, gather test evidence, and translate compliance findings into actionable steps.
- Ability to assess, identify, and document third-party system compliance deficiencies and recommend solutions.
- Excellent facilitation skills for group discussions, diplomacy, and seeking diverse opinions.
- Strong organizational and time management skills.
- In-depth knowledge of information security, compliance management frameworks, and standards (NIST, OWASP, SANS, ISO-27001/2, COBIT, ITIL).
- Commitment to top-quality service and exceeding customer expectations.
- Demonstrated leadership and ability to gain consensus across teams without direct reporting responsibility.
- Possession of CISA certification (required); CRISC, CIA, CISM, CISSP, PCI certifications (desired).
Work Location and Arrangement: This role can be based out of the CarMax Home Office in Richmond, VA or Dallas Technology Hub and will have a Hybrid work arrangement
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis. Sponsorship will not be considered for this specific role.
About CarMax
CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation's largest retailer of used cars, with over 250 locations nationwide.
Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For.
Our Commitment to Diversity and Inclusion:
CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment.
CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.
Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.
-
Compliance Analyst
2 weeks ago
Richmond, British Columbia, Canada New Horizon Bank Full time $60,000 - $90,000 per yearAt New Horizon, we're building a bank that runs on grit, speed, and execution.We move fast, challenge assumptions, and obsess over doing things better — for our clients and for each other. This isn't a place for red tape; it's a place for builders. From product design to client experience to operations, we're constantly pushing for sharper thinking and...
-
Trade Compliance Analyst
2 weeks ago
Richmond, British Columbia, Canada Heli-One Full time $60,000 - $90,000 per yearCHC provides unmatched helicopter services that enable our customers to reach beyond – to work in remote and challenging destinations that limit others – and come home safely. We are dedicated to our purpose of getting our customers where they need to be, when they need to be there, anywhere in the world – safely and reliably. All you have to do is get...
-
Principal Software Engineer
23 hours ago
Richmond, British Columbia, Canada CarMax Full time $120,000 - $180,000 per year8117 - Dallas Technology Hub Granite Parkway, Plano, Texas, 75024CarMax, the way your career should be About this jobAt CarMax, we are industry disruptors. At the heart of our innovation is new digital products. Working on many different aspects of the customer experience, our Principal Engineers research and discover new opportunities and shape products to...
-
Project Systems Analyst
1 day ago
Richmond, British Columbia, Canada FPS Food Process Solutions Corporation Full time US$80,000 - US$120,000 per yearPosition ScopeFPS is seeking a highly organized and technically proficient Project Systems Analyst to support our Project Management Office (PMO). This role is responsible for managing project information systems, maintaining data integrity, and supporting key project workflows. Acting as the backbone of project information flow, the Project Systems Analyst...
-
Operations Analyst
1 week ago
Richmond, British Columbia, Canada Paladin Airport Security Services Full time $65,000 - $75,000 per yearOperations AnalystReporting to the Senior Director, Operations (YVR), we are seeking a highly organized and self-driven Operations Analyst to elevate operational performance through BI-driven reporting and practical process improvements. This role oversees key administrative functions, including minute-taking, event planning, operational scheduling, and...
-
Policy & Reporting Analyst (RCMP)
1 week ago
Richmond, British Columbia, Canada City of Richmond (BC) Full time $60,000 - $80,000 per yearPolicy & Reporting Analyst (RCMP)The City of Richmond is committed to be the most appealing, livable, well-managed community in Canada, a vision that is only made possible by developing our most valuable asset – our people. This is a great opportunity to join our team and shape our community. The City of Richmond offers competitive pay programs,...
-
Analyst, Command Center
6 days ago
Richmond, British Columbia, Canada CarMax Full time $60,000 - $90,000 per year8901 - Corp Office West Crk Tuckahoe Creek Parkway, Richmond, Virginia, 23238CarMax, the way your career should be Job Description About this jobThe Command Center Analyst operates and maintains a highly technical CCTV system to protect assets of CarMax locations across the country and is responsible for communicating with local law enforcement and store...
-
Sr. Analyst, Supply Strategy
1 week ago
Richmond, British Columbia, Canada CarMax Full time $80,000 - $120,000 per year8901 - Corp Office West Crk Tuckahoe Creek Parkway, Richmond, Virginia, 23238CarMax, the way your career should be About The Team The Supply Strategy team is a community of analysts with a variety of strategic and technical skillsets. We work together to continually improve CarMax's ability to optimize the acquisition, movement, and reconditioning of each...
-
Business Analyst
7 days ago
Richmond, British Columbia, Canada Harris Computer Full time $60,000 - $70,000Cayenta and Opportunity Overview:Cayenta is involved in some of the most challenging and interesting projects in the information technology industry and we're always looking for talented, highly motivated individuals who seek the same. One of our most important decisions is the next person we invite to join our team. As a Cayenta employee, you will be...
-
Support Analyst I
1 week ago
Richmond, British Columbia, Canada WorkSafeBC Full time $69,000 - $194,000 per yearOverview We're looking for experienced Support Analyst I to provide first-level technical support for all business and technology inquires for internal customers through phone, email, and in person assistance. How you'll make a difference: As a Support Analyst I at WorkSafeBC, you'll be using leading-edge technology to help connect British...