- Company Name
- Little Caesars Pizza
- Job Title
- Cybersecurity Governance and Compliance Specialist
- Job Description
-
**Job Title**
Cybersecurity Governance and Compliance Specialist
**Role Summary**
Own and advance cybersecurity compliance and risk management initiatives, leading design, implementation, monitoring, and audit readiness across PCI DSS, ITGC, and other regulatory frameworks. Operate independently while influencing cross‑functional teams to embed security controls and improve governance posture.
**Expectations**
- Autonomous ownership of compliance programs.
- Proactive risk assessment, control gap analysis, and remediation.
- Documentation and evidence management for internal and external audits.
- Continuous improvement of policies, standards, and training.
**Key Responsibilities**
- Lead compliance programs for PCI DSS, ITGC, and other relevant frameworks.
- Conduct cyber risk assessments, identify control gaps, and recommend compensating controls.
- Prepare for and execute internal/external audits, ensuring evidence collection, documentation, and remediation tracking.
- Author and maintain cybersecurity policies, standards, and procedures.
- Develop dashboards and metrics in GRC platforms to track compliance posture and risk trends.
- Collaborate with infrastructure, cloud, QA, and security teams to embed compliance into system design, change management, and operations.
- Deliver security awareness training on compliance obligations and best practices.
- Monitor vulnerability remediation and ITGC performance, including access reviews, logging, and backup validation.
**Required Skills**
- Independent ownership of compliance functions.
- Deep understanding of cybersecurity risk management, control frameworks, and compensating control strategies.
- Proficiency with GRC platforms (e.g., ServiceNow), audit documentation, and evidence management.
- Familiarity with cloud security (e.g., Azure) and enterprise IT environments.
- Strong communication, influencing, and education skills across technical and non‑technical audiences.
**Required Education & Certifications**
- Minimum 2 years of hands‑on cybersecurity compliance experience (PCI DSS, ITGC).
- Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or similar.
- PCI Information System Audit (ISA) certification preferred.
- Knowledge of NIST CSF, ISO 27001, SOC 2, GDPR frameworks is an advantage.