> Markdown version of [/jobs/ext/1578718-analyst-it-audit-and-compliance](https://www.wearedevelopers.com/jobs/ext/1578718-analyst-it-audit-and-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Analyst, IT Audit and Compliance - **Company:** Foundation Building Materials LLC - **Location:** Santa Ana, CA, United States - **Experience:** Starter - **Salary:** $72,800.0 - $93,600.0 - **Contract:** Internship / Graduate position - **Skills:** Microsoft Excel, Cyber Security, Information Systems, Information Technology Audit, PCI Data Security Standards, IT General Controls (ITGC), Information Technology, Tools for Reporting - **Published:** July 11, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3317188208&tx=CT4038THD&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Information Systems, Computer Science, Accounting, Cybersecurity, or a related field. * CISA, CISM, CISSP, CRISC, or similar certifications preferred but not required. * 1-3 years of experience in IT audit, compliance, cybersecurity, risk management, or related fields. * Foundational understanding of IT general controls, cybersecurity frameworks, and regulatory requirements. * Exposure to SOX, IT audits, compliance testing, or risk assessments through professional experience, internships, or public accounting preferred. * Strong analytical, problem-solving, and organizational skills. * Effective communication skills with the ability to work with both technical and non-technical stakeholders. * Ability to manage multiple priorities and deadlines in a fast-paced environment. * Proficiency with Microsoft Excel and experience working with audit documentation and reporting tools preferred. ## Description The Analyst, IT Audit and Compliance, is responsible for handling IT audit, risk assessment, and compliance program work. This role ensures that IT systems, processes, and controls comply with internal policies, industry standards, and regulatory requirements. This role will work closely with IT, security, finance, and business teams to strengthen internal controls, mitigate risks, and support strategic initiatives under the leadership of the Manager, IT Audit and Compliance., * Support the planning and execution of IT audits to evaluate the design and effectiveness of internal controls, security measures, and operational processes. * Assist with testing and documentation of SOX controls within a publicly traded company environment to support compliance with financial and IT regulatory requirements. * Participate in risk assessments to identify gaps and vulnerabilities in IT systems and processes. * Support third-party risk assessments of vendors in accordance with established frameworks such as NIST. * Assist in maintaining audit plans and supporting audit activities aligned with business priorities and regulatory changes. * Track and monitor remediation efforts from audit findings and assist in ensuring timely closure of action items. Compliance & Governance * Support compliance activities related to regulatory requirements and frameworks, including SOX, NIST, and PCI. * Assist with PCI-DSS 4.0 compliance efforts, including evidence collection and documentation related to scope reduction initiatives such as segmentation, iFrame, and P2PE. * Maintain IT compliance documentation, policies, procedures, and supporting materials to promote effective governance practices. * Collaborate with Legal, Finance, IT, and business stakeholders to support compliance initiatives across systems and processes. * Monitor regulatory updates and communicate relevant changes and potential impacts to the broader team. Leadership & Collaboration * Support internal and external audit activities by coordinating requests, gathering documentation, and assisting with audit inquiries. * Assist with monitoring compliance risks through established internal controls and process improvement initiatives. * Coordinate with internal stakeholders and external auditors to support audit and compliance activities. Continuous Improvement * Participate in initiatives to improve IT audit, risk management, and compliance processes and controls. * Partner with IT and Security teams to promote best practices in information security and data protection. * Assist with external audits, assessments, and compliance reviews conducted by auditors, regulators, and third-party assessors. * Prepare reports, metrics, and documentation to support management visibility into audit and compliance activities. Additional Responsibilities & Miscellaneous * Perform other duties as assigned to support IT Audit and Compliance objectives. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)