> Markdown version of [/jobs/ext/1321486-it-compliance-analyst](https://www.wearedevelopers.com/jobs/ext/1321486-it-compliance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Compliance Analyst - **Company:** CNA National - **Location:** Scottsdale, AZ, United States - **Salary:** $90,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Disaster Recovery, Smartsuite - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aed2e34fb14cf17c ## About the Role * Strong experience in IT, security, audit, risk, or compliance, with hands-on knowledge of common security frameworks and control environments. * Experience supporting audits, managing evidence requests, documenting controls, and working with GRC tools. * Excellent communication skills with the ability to explain technical and compliance requirements clearly to a variety of stakeholders. * A collaborative, solutions-oriented mindset and the ability to manage multiple priorities with accuracy and follow-through. * Curiosity and adaptability as compliance expectations evolve, including emerging areas such as AI governance and security risk management. ## Description We are looking for an experienced IT Compliance Analyst to help strengthen and mature our technology risk, security, and compliance programs. This is an excellent opportunity for a detail-oriented, collaborative professional who enjoys building strong controls, supporting audit readiness, and partnering across IT, Security, and business teams to protect the organization and support continued growth. In this role, you will serve as a trusted compliance partner and subject matter expert, helping align internal controls and security practices with key frameworks such as SOX, CMMC, SOC 2, NIST, and ISO/IEC 27001. You will support audits, assess risks, coordinate evidence, strengthen vendor and customer security review processes, and contribute to emerging areas such as AI risk governance and business continuity readiness. Why This Role Matters Technology compliance is critical to CNA National's ability to operate securely, serve our customers, and continue advancing our security and risk programs. The IT Compliance Analyst will play a key role in reducing compliance risk, improving audit preparedness, and helping teams translate complex regulatory and security expectations into clear, practical actions. Schedule and Location Role is based in Scottsdale, Arizona, working a hybrid schedule of four days in the office and one day remote. What You'll Do * Support IT compliance programs through control assessments, audit coordination, evidence preparation, and continuous monitoring. * Partner with IT, Security, Development, and business teams to identify risks, address control gaps, and improve compliance readiness. * Lead or support security and privacy assessments, vendor risk reviews, and customer security questionnaire responses. * Map internal policies and technical safeguards to applicable frameworks, including SOX, CMMC, SOC 2, NIST, and ISO/IEC 27001. * Contribute to AI risk and governance activities by helping assess use cases, document controls, and support responsible AI practices. * Assist with business continuity, disaster recovery, and team documentation efforts to support operational resilience. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [AI is dead, long live AK](https://www.wearedevelopers.com/videos/1093-ai-is-dead-long-live-ak) - [System Resilience: Surviving the Software Storm](https://www.wearedevelopers.com/videos/874-system-resilience-surviving-the-software-storm) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)