> Markdown version of [/jobs/ext/220205-information-security-compliance-analyst](https://www.wearedevelopers.com/jobs/ext/220205-information-security-compliance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security & Compliance Analyst - **Company:** Cooper's Hawk Winery & Restaurants - **Location:** Downers Grove, IL, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, PCI Data Security Standards, IT General Controls (ITGC), Information Technology - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d81a0d7065cc599b ## About the Role Do you have experience in Project stakeholder communication?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent professional experience * 3-6 years of experience in information security, risk, or compliance * Experience supporting PCI DSS and/or SOX/ITGC programs * Experience with audit coordination, control testing, and evidence collection * Exposure to risk management practices and frameworks. * Certifications such as Security+, CISA, PCI ISA, or similar are a plus. Other Skills/Abilities: * Strong organizational and prioritization skills, with the ability to manage multiple initiatives, deadlines, and competing requests. * Hospitality industry experience will be a plus. * Excellent analytical and problem-solving skills, with a practical, customer-focused approach to security challenges. * Ability to communicate clearly and effectively with technical and non-technical stakeholders across IT, business, and restaurant operations. * Experience in hospitality or retail environments. ## Description The Information Security & Compliance Analyst supports the execution of Cooper's Hawk Winery & Restaurants' Governance, Risk, and Compliance (GRC) program, with a primary focus on PCI DSS 4.0, SOX/ITGC, and NIST CSF 2.0. This individual contributor role is responsible for audit support, control validation, policy governance, and risk management activities. The Analyst plays a key role in maintaining audit readiness, supporting successful audit outcomes, and advancing a structured and sustainable compliance and risk program. This includes supporting Third-Party Risk Management (TPRM) and Privacy initiatives through coordination, tracking, and execution activities, while program ownership remains with the VP of Information Security & GRC. The role partners closely with IT, business teams, and external auditors to ensure security controls are operating effectively and compliance obligations are consistently met. This position reports to the VP of Information Security & GRC and works closely with the Manager, Security Engineering & Operations to align security controls with compliance and risk requirements. How You Will Succeed: PCI DSS & SOX/ITGC Compliance Execution * Support execution of PCI DSS 4.0 compliance activities, including coordination with QSAs and audit preparation * Support SOX/ITGC control execution, testing coordination, and evidence collection * Maintain audit-ready documentation for all in-scope systems and controls * Track control effectiveness and remediation activities * Partner with IT and application teams to ensure timely completion of audit requests Audit Coordination & Assurance * Coordinate internal and external audits, including PCI and SOX * Manage audit requests, evidence collection, and responses * Track audit findings, remediation plans, and closure status * Support reduction of repeat findings through structured follow-up and validation Risk Management * Maintain and update the cybersecurity risk register * Support risk assessments across applications, infrastructure, and vendors * Track remediation plans and risk acceptance decisions * Prepare risk summaries and reporting for leadership and governance forums * Partner with engineering and operations teams to ensure risks are understood and addressed Policy & Governance * Support development, maintenance, and lifecycle management of security policies, standards, and procedures * Track policy reviews, updates, and approvals * Support communication and awareness of policy requirements across the organization * Ensure alignment with PCI DSS, SOX, and internal governance standards Metrics, Reporting & Program Tracking * Develop and maintain dashboards for compliance status, audit progress, and risk metrics * Track remediation activities and key program initiatives * Prepare reporting for leadership and governance committees Program Support (TPRM & Privacy) * Support execution of Third-Party Risk Management activities, including: * + Vendor risk assessments and security questionnaires + SOC report reviews (SOC 1, SOC 2) + Risk tracking and follow-ups * Support Privacy program activities through documentation, tracking, and coordination * Assist with intake and workflow management, while program ownership remains with leadership ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Create DSL (Domain Specific Language) on top of Swift](https://www.wearedevelopers.com/videos/707-create-dsl-domain-specific-language-on-top-of-swift) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)