> Markdown version of [/jobs/ext/1727277-it-compliance-and-security-analyst](https://www.wearedevelopers.com/jobs/ext/1727277-it-compliance-and-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Compliance and Security Analyst - **Company:** Foundation Building Materials LLC - **Location:** Santa Ana, CA, United States - **Salary:** $73,000.0 - $94,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software Applications, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cyber Security, Computer Networks, Information Technology Audit, Systems Integration, Google Cloud, Cloud Platform System, Information Technology, Vulnerability Analysis - **Published:** July 11, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3317188206&tx=CT3836THI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Experience in an information security related role with exposure to PCI, SOC compliance, risk assessments, and related security initiatives. * Experience with networking security technologies and integrating security technologies into enterprise environments. * Experience with computer network penetration testing, vulnerability testing, and related techniques. * Experience identifying, mitigating, and communicating cloud, network, and system vulnerabilities and misconfigurations across Azure, AWS, and GCP environments. * Experience interpreting and communicating security-related information to employees and business stakeholders. * Prior experience performing security reviews and risk assessments preferred. * Experience evaluating security products and managing vendor relationships preferred. * Strong communication and time management skills ## Description The IT Compliance and Sec Analyst is responsible for supporting the day-to-day operational aspects of IT system security designs, policies, and solutions in partnership with Security Architects, Technical Operations, and Information Security leadership. This role participates in projects across business and IT teams and supports enterprise information security initiatives that protect company systems, networks, applications, and information assets while reducing organizational risk and maintaining compliance requirements., * Assess information security risks and facilitate remediation of identified vulnerabilities across the enterprise. * Assess information risks and facilitate remediation of identified vulnerabilities affecting networks, systems, and applications. * Monitor computer networks, systems, and cloud environments for security-related events and concerns. * Prepare findings and recommendations for corrective actions related to identified security risks and vulnerabilities. * Investigate and document security breaches and cybersecurity incidents. * Facilitate and monitor risk remediation activities and report findings related to risk mitigation efforts. * Perform vulnerability scans in partnership with Technical Operations teams and support remediation efforts. Security Compliance, Audits & Governance * Support IT audits, IT risk assessments, and regulatory compliance activities. * Perform assessments of the IT security and risk posture across networks, systems, software applications, and third-party vendors as part of the Vendor Management Program. * Support compliance initiatives related to PCI, SOC, and other applicable security requirements. Infrastructure Security & Technical Collaboration. * Collaborate with Technical Operations teams to implement and maintain security measures designed to protect systems and information infrastructure. * Support the implementation and operation of security technologies including firewalls and data encryption solutions. * Participate in cross-functional initiatives involving business and IT stakeholders to support enterprise information security objectives. Security Awareness & Continuous Improvement. * Stay current on information security trends, standards, emerging threats, and industry developments. * Develop company-wide information security best practices and recommendations. * Research security enhancements and provide recommendations to management. * Support and administer the organization's Security Awareness Program. Additional Responsibilities & Miscellaneous * Perform other duties as assigned to support IT and corporate objectives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)