1

Security And Compliance Analyst Jobs (NOW HIRING)

Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters * Improve our security tooling ...

Lead Security & Compliance Analyst

OR · On-site +1

$80K - $135K/yr

Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters * Improve our security tooling ...

... analysis. * Drive audit readiness and execution, coordinating evidence collection and remediation for internal and external audits. Policy Integration & Enablement * Embed security and compliance ...

... analysis. * Drive audit readiness and execution, coordinating evidence collection and remediation for internal and external audits. Policy Integration & Enablement * Embed security and compliance ...

Showing results 21-40

Security And Compliance Analyst information

See salary details

$46K

$104.1K

$147.5K

How much do security and compliance analyst jobs pay per year?

As of Aug 9, 2026, the average yearly pay for security and compliance analyst in the United States is $104,051.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,500.00 and $125,000.00 per year, depending on experience, location, and employer.

What is a security and compliance analyst?

Security and Compliance Analysts are professionals responsible for ensuring that an organization’s information systems comply with regulatory requirements and internal security policies. They monitor, assess, and report on security controls, identify vulnerabilities, and recommend improvements to protect sensitive data. Their role often involves conducting audits, risk assessments, and staying updated with changing laws and industry standards to keep the organization secure and compliant.

How does a security and compliance analyst typically collaborate with other departments to ensure organizational compliance?

Security and Compliance Analysts frequently work cross-functionally with IT, legal, HR, and business operations teams to develop and implement security policies and compliance procedures. They often act as a bridge, translating regulatory requirements into actionable processes and ensuring all departments understand their roles in maintaining compliance. Regular meetings, training sessions, and audits are common, enabling analysts to proactively identify risks and resolve issues before they become major problems. This collaborative environment not only helps maintain regulatory standards but also fosters a culture of security awareness throughout the organization.

What are the key skills and qualifications needed to thrive as a security and compliance analyst?

To thrive as a Security and Compliance Analyst, you need a solid understanding of information security frameworks, risk assessment, regulatory standards, and a relevant degree such as in cybersecurity or information technology. Familiarity with compliance management tools, security information and event management (SIEM) systems, and certifications like CISSP or CISA are commonly required. Attention to detail, analytical thinking, and strong communication skills help you interpret complex regulations and collaborate across departments. These skills ensure organizations maintain regulatory compliance, mitigate risks, and protect sensitive information effectively.

What is the difference between Security And Compliance Analyst vs Security Analyst?

AspectSecurity And Compliance AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentFocus on regulatory compliance, audits, policiesFocus on threat detection, incident response
Employer & Industry UsageFinancial, healthcare, government sectorsIT, cybersecurity firms, corporate IT teams
Search & Comparison IntentUnderstanding compliance roles, regulationsSecurity threats, incident handling

The Security And Compliance Analyst primarily focuses on ensuring organizations meet regulatory standards and internal policies, often working with audits and compliance frameworks. In contrast, a Security Analyst concentrates on identifying and mitigating security threats, monitoring systems, and responding to incidents. While both roles require cybersecurity certifications and work within similar environments, their core responsibilities differ—compliance versus threat management.

More about Security And Compliance Analyst jobs
What cities are hiring for Security And Compliance Analyst jobs? Cities with the most Security And Compliance Analyst job openings:
Who are the top companies hiring for Security And Compliance Analyst jobs? The top employers for Security And Compliance Analyst jobs are:
What states have the most Security And Compliance Analyst jobs? States with the most job openings for Security And Compliance Analyst jobs include:
What job categories do people searching Security And Compliance Analyst jobs look for? The top searched job categories for Security And Compliance Analyst jobs are:
Infographic showing various Security And Compliance Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $104,051 per year, or $50 per hour.

Security Compliance Analyst III

Bridgehead IT

San Antonio, TX • On-site

Full-time

Posted 19 days ago


Job description

Job Type
Full-time
Description
Position Summary:
As a Security Compliance Analyst III, you will serve as a senior compliance professional responsible for assessing, implementing, and maintaining security and regulatory compliance programs for client environments. You will lead compliance initiatives, perform risk assessments, coordinate audits, and work directly with clients to ensure compliance with industry standards and regulatory requirements.
This role requires a strong understanding of cybersecurity frameworks, governance, risk management, and technical security controls. You will work primarily out of a ticketing system to manage compliance requests, audit activities, remediation efforts, and client deliverables while collaborating closely with security engineers, system administrators, cloud engineers, and executive stakeholders. You will also mentor junior compliance analysts and assist in developing internal compliance processes and best practices.
Participation in after-hours work may be required to support audit deadlines, security incidents, or client engagements.
Key Responsibilities:
  • Work within a structured ticketing system to manage compliance requests, audit activities, remediation tasks, client communications, and documentation.
  • Lead compliance assessments across client environments using frameworks such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CMMC, SOC 2, HIPAA, PCI DSS, and other applicable standards.
  • Conduct formal security and compliance gap assessments and develop remediation plans to address identified deficiencies.
  • Perform technical and administrative reviews of security controls to validate compliance with applicable frameworks.
  • Lead and facilitate client readiness assessments for regulatory audits and certification initiatives.
  • Coordinate internal and external audits, including evidence collection, documentation, interviews, and audit response activities.
  • Conduct formal cybersecurity risk assessments and document identified risks, mitigation strategies, and residual risk.
  • Review security policies, standards, procedures, and technical documentation to ensure regulatory alignment.
  • Work closely with cloud, infrastructure, networking, and security engineering teams to validate technical control implementation.
  • Monitor remediation activities and verify corrective actions have been successfully completed.
  • Develop compliance reports, executive summaries, dashboards, and client deliverables.
  • Assist clients with security governance initiatives, including policy development, security awareness recommendations, and compliance roadmaps.
  • Maintain detailed documentation including risk registers, assessment reports, audit evidence, and compliance matrices.
  • Research changes to regulatory requirements and recommend updates to internal processes and client security programs.
  • Mentor Security Compliance Analyst I and II team members by providing guidance on assessment methodologies, framework interpretation, and documentation standards.
  • Participate in client meetings to present assessment findings, explain compliance requirements, and provide remediation guidance.
  • Support security incident response activities when compliance reporting or regulatory notification requirements are involved.
  • Perform additional duties as assigned.

Skills and Qualifications:
  • 5-7 years of experience in cybersecurity, governance, risk management, compliance, IT auditing, or information security.
  • Strong working knowledge of cybersecurity frameworks including ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CMMC, SOC 2, HIPAA, and PCI DSS.
  • Experience conducting security risk assessments, compliance assessments, and audit preparation activities.
  • Understanding of Microsoft 365, Azure, AWS, Active Directory, identity management, networking, endpoint security, vulnerability management, and cloud security concepts.
  • Experience interpreting regulatory requirements and translating them into practical technical and administrative controls.
  • Excellent technical writing, documentation, and report development skills.
  • Strong communication and presentation skills with the ability to communicate effectively with technical teams, executive leadership, auditors, and clients.
  • Experience working in ticketing systems such as ConnectWise, ServiceNow, Autotask, or similar service management platforms.
  • Strong analytical, organizational, and project coordination skills.
  • Ability to manage multiple client engagements simultaneously while meeting deadlines.
  • Preferred certifications include ISC2 Certified Information Systems Security Professional (CISSP), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), CompTIA Security+, CompTIA CySA+, ISO 27001 Lead Implementer or Lead Auditor, Certified in Risk and Information Systems Control (CRISC), or CMMC Certified Professional (CCP).

Disclaimer:
The duties and responsibilities described in this job description are not a comprehensive list and additional tasks may be assigned to the employee from time to time. This job description in no way states or implies that these are the only duties to be performed by the employee(s) in this position. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. To perform this job successfully, the employees will possess the skills, aptitudes, and abilities to perform each duty proficiently. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities.