IT Compliance Lead

PLSOak Brook, IL
$110,000 - $120,000Onsite

About The Position

The IT Compliance Lead supports PLS’s IT governance, risk, and compliance activities. This role partners with Information Security, Infrastructure, Application Development, Audit, and Legal departments, as well as business stakeholders to help assess control effectiveness, support audits and regulatory examinations, as well as track remediation activities and strengthen ongoing compliance with applicable requirements. This role requires a risk-based mindset, strong technical and analytical capabilities, and the ability to translate regulatory and control requirements into practical operational support across multiple environments. Candidates must be able to manage assigned work while contributing to compliance, policy maturity, and operational resilience.

Requirements

  • Bachelor’s degree in information technology, information security, cybersecurity, computer science, business, accounting, risk management, or a related field; equivalent relevant experience may be considered.
  • 3+ years of experience in information security, IT general controls, IT compliance, IT audit, cybersecurity governance, and/or technology risk management.
  • Experience supporting internal and external auditors, regulators, and cross-functional stakeholders in audits, assessments, examinations, and remediation activities.
  • Knowledge of security and risk frameworks, standards, and best practices, including PCI DSS v4.0.1, GLBA Safeguards Rule, NIST Cybersecurity Framework 2.0, and related guidance.
  • Working knowledge of key cybersecurity control areas such as access control, multifactor authentication, vulnerability management, endpoint and network security, logging and monitoring, incident response, and business continuity.
  • Experience with audit-ready documentation, evidence management, issue tracking, and remediation support.
  • Strong communication, documentation, presentation, facilitation, and stakeholder management skills, with the ability to communicate effectively with both technical teams and business stakeholders.
  • Strong analytical skills and experience with process improvement, automation, and continuous compliance monitoring.

Nice To Haves

  • Experience with regulatory and compliance requirements applicable to financial services, payments, retail, or other regulated environments is preferred.
  • Experience with Governance, Risk, and Compliance (GRC) platforms and control management workflows is preferred.
  • Experience in cloud or hybrid environments, including SaaS and third-party service provider risk considerations, is preferred.
  • Experience in retail, payments, or financial services is preferred.
  • Professional certifications such as CISA, CRISC, CISSP, CISM, or similar qualifications are preferred.

Responsibilities

  • Support IT compliance activities across PCI DSS, GLBA, IT controls, security awareness, technology risk management, and related cybersecurity and regulatory requirements.
  • Assist with IT testing, audits, assessments, and regulatory examinations conducted by internal and external auditors, and coordinate with security, IT, and other stakeholders throughout the review lifecycle.
  • Work with control owners to communicate scope, evidence requirements, testing approaches, and assessment expectations for in-scope controls and processes.
  • Gather, prepare, evaluate, and retain detailed audit-ready evidence to support control design and operating effectiveness testing.
  • Maintain a centralized library of compliance and information security evidence, including audit artifacts, control documentation, policy records, assessment materials, and supporting evidence needed for ongoing audits, regulatory examinations, and control monitoring.
  • Document testing results, compliance gaps, exceptions, and observations, and communicate findings clearly to control owners, management, and other stakeholders.
  • Support development, tracking, and ongoing revision of remediation plans for issues resulting from audits, assessments, risk reviews, and regulatory findings.
  • Track and report remediation status, overdue actions, and risk acceptance decisions for IT compliance-related issues and escalate material concerns when appropriate.
  • Help maintain and improve a risk-based control framework aligned to applicable standards and regulations, including PCI DSS v4.0.1, GLBA Safeguards Rule, NIST Cybersecurity Framework 2.0, and other relevant requirements.
  • Perform or support compliance impact assessments for new systems, infrastructure changes, cloud services, SaaS platforms, material process changes, and other technology initiatives.
  • Support third-party and vendor risk oversight by reviewing security and compliance documentation, control attestations, remediation commitments, and ongoing compliance obligations.
  • Partner with information security and IT teams on key control domains including identity and access management, multi-factor authentication, vulnerability management, secure configuration, logging and monitoring, incident response, and business continuity.
  • Assist in the review and enhancement of IT policies, standards, procedures, and control documentation to ensure alignment with regulatory expectations and operational practices.
  • Prepare compliance metrics, dashboards, and management reporting for leadership, committees, and auditors to support decision-making and continuous improvement.
  • Monitor changes in laws, regulations, standards, and threat trends, and help translate those changes into actionable control, policy, and process updates for the organization.

Benefits

  • medical/dental/vision
  • 401(k)
  • vacation
  • opportunities for advancement
  • ongoing training
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service