Key to success in this role is combining strong cybersecurity and compliance expertise with an understanding of technology and business operations to translate complex requirements into practical, sustainable controls. The Sr. Analyst will help scale the compliance program as regulatory requirements and business operations expand, partnering across Technology, Security, Privacy, Legal, Internal Audit, and business teams to maintain compliance while enabling continued growth and change at Tractor Supply.
Own and execute assigned technology compliance programs, including CCPA/CPRA cybersecurity requirements, PCI DSS, and emerging cybersecurity regulatory and industry requirements.
Plan, coordinate, and execute required compliance assessments and audits, including scope definition, control assessment, evidence collection, testing, documentation, and management of deliverables.
Interpret regulatory, legal, and industry requirements and translate them into clear technology control requirements, procedures, and compliance activities.
Assess the design and operating effectiveness of technology, cybersecurity, privacy, and data protection controls against applicable compliance requirements.
Serve as a primary compliance subject matter expert for assigned regulatory and industry frameworks, partnering with Technology, Information Security, Privacy, Legal, Internal Audit, and business stakeholders.
Manage compliance findings and remediation activities from identification through closure, ensuring corrective actions are appropriately documented, supported, and completed within required timelines.
Maintain audit-ready documentation and evidence to demonstrate compliance with applicable regulatory, cybersecurity, privacy, and industry requirements.
Identify compliance gaps and emerging requirements, assess their impact to the organization, and develop recommendations and action plans to address identified obligations.
Develop and maintain compliance procedures, control mappings, assessment methodologies, and supporting documentation to enable a consistent and scalable Technology Compliance program.
Monitor changes to applicable cybersecurity, privacy, and payment-card requirements and support implementation of new or changing compliance obligations across the organization.
Develop compliance metrics, reporting, and status updates that communicate compliance posture, open issues, remediation progress, and emerging areas of concern to leadership.
Support the continued expansion and maturity of the Technology Compliance program as regulatory requirements, business operations, and the company's portfolio of brands and services evolve
Must haves:
6+ years of IT Governance, Risk, and Compliance experience in technology, retail or similar environments.
Education:
Bachelor’s Degree in Computer Science or a related field from an accredited college or university. Any suitable combination of education and experience will be considered.
Other knowledge, skills, or abilities:
Hands-on experience managing IT risk management programs using NIST, CCPA, FAIR, ISO, or other relevant IT control frameworks
Demonstrated ability to build new compliance programs and controls from the ground up
Experience with PCI, SOX, IT General Controls, change management, data privacy, CCPA, third party risk management, identity and access management, cloud security, IAAS, PAAS, SAAS
Strong analytical, problem-solving, project management, and planning skills
Strong negotiation/mediation skills
Mentorship, collaborative skills, and ability to work well within a team
Ability to work with and influence senior management
Ability to work in a fast-paced and deadline-oriented environment
Self-motivated with attention to detail, deadlines, and reporting
Pluses/Strongly Preferred:
Experience with IT GRC related tools: OnSprig, ServiceNow and OneTrust. Audit Command Language (ACL) and integration experience
Experience in Retail, Big 4 IT Audit, Internal IT Audit, and Security Consulting
Professional Certifications: CISSP, CISA, CRISC, CISM, SANS GIAC, or another relevant security or governance certification(s) desired.
Experience supporting California privacy compliance (CCPA/CPRA) strongly prefe