Sr. IT Compliance Analyst
Prestige Brands · Tarrytown, NY ·
- Work mode
- Hybrid
- Seniority
- Senior
- Category
- Legal
- Experience
- 3+ years
Prestige Consumer Healthcare is a company that focuses on product innovation and quality in the over-the-counter healthcare and women’s health categories to better improve the lives of our customers and their world. For generations, our trusted brands have helped consumers care for themselves and their loved ones. We are one of the largest independent providers of over-the-counter products in North America, and we are constantly improving and creating products that match the ever-changing lifestyles and needs of people and families everywhere.
JOB SUMMARY:
The Sr. IT Compliance Analyst supports Prestige Consumer Healthcare’s information security, IT compliance, vendor risk management, AI governance, and project management activities for key initiatives. This role is responsible for helping maintain effective IT controls, supporting audit readiness, coordinating compliance and governance activities, improving documentation practices, and partnering with IT, business, vendor, and leadership stakeholders to reduce risk and strengthen operational effectiveness across the enterprise.
The role will support the following key areas:
MAJOR RESPONSIBILITES/ACTIVIES:
QUALIFICATIONS:
Education and Training Requirements:
Travel: 5% ability to travel via car, plane, rail.
LANGUAGE SKILLS:
Ability to read, analyze, and interpret general business periodicals, professional journals, technical procedures, or governmental regulations. Ability to write reports, business correspondence, and procedure manuals. Ability to effectively present information and respond to questions from groups of managers, clients, customers, and the general public.
MATHEMATICAL SKILLS:
Ability to calculate figures and amounts such as discounts, interest, commissions, proportions, percentages, area, circumference, and volume. Ability to apply concepts of basic algebra and geometry.
REASONING ABILITY:
Ability to apply common sense understanding to carry out instructions furnished in written, oral, or diagram form. Ability to deal with problems involving several concrete variables in standardized situations.
PHYSICAL DEMANDS:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to sit. The employee frequently is required to talk or hear. The employee is occasionally required to stand; walk; use hands to finger, handle, or feel; reach with hands and arms; and stoop, kneel, crouch, or crawl. The employee must occasionally lift and/or move up to 10 pounds. Specific vision abilities required by this job include close vision, and ability to adjust focus.
WORK ENVIRONMENT:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
The noise level in the work environment is usually moderate.
Salary Range: $105,000-$115,000
No Sponsorship: Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.
#HybridWork: We follow a Hybrid work schedule. All applicants must be able to work in our Tarrytown office Tues/Wed/Thurs (remote on Mon/Fri).
Work Hours: 40 hours per week.
JOB SUMMARY:
The Sr. IT Compliance Analyst supports Prestige Consumer Healthcare’s information security, IT compliance, vendor risk management, AI governance, and project management activities for key initiatives. This role is responsible for helping maintain effective IT controls, supporting audit readiness, coordinating compliance and governance activities, improving documentation practices, and partnering with IT, business, vendor, and leadership stakeholders to reduce risk and strengthen operational effectiveness across the enterprise.
The role will support the following key areas:
- Risk Mitigation: Maintain information security documentation, support the development of security policies and procedures, and help strengthen governance, tools, and processes that reduce enterprise risk.
- Information Security Policy Management: Support the continued maturity of Prestige’s information security policies, standards, and operating procedures across the organization.
- Process Optimization: Identify opportunities to improve compliance processes, increase efficiency, and strengthen business value through standardized controls and continuous improvement.
- Security Awareness and Training: Manage cybersecurity awareness training, phishing simulations, and related reporting to improve employee awareness and reduce human risk.
- Cross-Functional Collaboration: Work with IT, security, infrastructure, application, and business teams to enhance controls, improve documentation, and support compliance objectives.
- AI Governance and Responsible Use: Support the evaluation, documentation, and governance of artificial intelligence tools to ensure responsible use, data protection, security compliance, and alignment with company policies.
- Project Management: Support planning, execution, and delivery of key initiatives by tracking milestones, deliverables, timelines, budgets, resources, risks, and dependencies.
MAJOR RESPONSIBILITES/ACTIVIES:
- Partner with internal and external auditors to support Sarbanes-Oxley compliance, segregation of duties reviews, control testing, evidence collection, and timely remediation of audit findings.
- Create, maintain, and periodically review global IT policies, standards, standard operating procedures, control documentation, and evidence repositories to support audits, compliance reviews, and operational consistency.
- Support alignment of IT policies, standards, and procedures with the NIST Cybersecurity Framework and other applicable compliance expectations.
- Administer cybersecurity awareness activities, including training assignments, phishing simulations, user communications, reporting, and follow-up actions.
- Develop and deliver clear communications and training materials that help employees understand new or updated security policies, procedures, and compliance requirements.
- Coordinate vendor security and compliance reviews, document assessment results, track remediation activities, and support recommendations that reduce third-party risk.
- Lead the collection, organization, and review of vendor responses and supporting documentation; coordinate meetings, track follow-up items, and ensure assigned actions are completed on time.
- Provide project management support for key IT, compliance, security, vendor risk, and AI governance initiatives, including developing project plans, tracking milestones and deliverables, coordinating cross-functional stakeholders, identifying risks and dependencies, and communicating status updates to leadership.
- Coordinate cloud security and vendor review meetings, facilitate assessment activities, and engage subject matter experts to complete thorough and timely reviews.
- Prepare and present regular compliance, risk, training, vendor, project, and control status reporting for IT leadership and key stakeholders.
- Recommend improvements to enterprise compliance processes, controls, documentation practices, project governance, and risk management procedures.
- Support AI governance activities, including intake reviews, risk assessments, approved use-case documentation, vendor due diligence for AI-enabled tools, and monitoring of responsible AI, privacy, security, and data protection requirements.
QUALIFICATIONS:
- Bachelor’s degree in Information Technology, Information Security, Business, Compliance, or a related field; equivalent professional experience may be considered.
- Minimum of 3-4 years of experience in information security, IT compliance, audit support, governance, risk, or a related discipline.
- Minimum of three years of experience applying project management concepts to business or technology initiatives, including developing project plans, tracking deliverables, coordinating stakeholders, managing timelines, and communicating status, risks, and dependencies.
- Experience supporting Sarbanes-Oxley compliance, audit evidence collection, control testing, and segregation of duties reviews.
- Familiarity with the NIST Cybersecurity Framework and practical experience supporting security policy, control, governance, or compliance programs.
- Knowledge of cloud security, third-party risk management, and vendor compliance requirements.
- Experience developing or maintaining global SOPs, policies, procedures, control evidence, or compliance documentation.
- Experience supporting cybersecurity awareness training, phishing simulations, and user communication programs.
- Strong business process knowledge with the ability to translate compliance requirements into practical, business-aligned procedures.
- Excellent written and verbal communication skills, with the ability to work effectively with technical teams, business stakeholders, vendors, auditors, and leadership.
- Self-starter with strong attention to detail, accountability, sound judgment, and the ability to work independently in a fast-paced environment.
- Working knowledge of responsible AI principles, AI governance concepts, data privacy, security considerations, and vendor risk factors related to AI-enabled solutions is preferred.
Education and Training Requirements:
- Five or more years of experience developing, maintaining, or managing IT policies, procedures, compliance documentation, or control evidence is preferred.
- Enterprise-level experience supporting compliance solutions, process improvement initiatives, and cross-functional governance programs is preferred.
- Professional experience with compliance platforms, security awareness tools, vendor risk management processes, or AI governance workflows is preferred.
Travel: 5% ability to travel via car, plane, rail.
LANGUAGE SKILLS:
Ability to read, analyze, and interpret general business periodicals, professional journals, technical procedures, or governmental regulations. Ability to write reports, business correspondence, and procedure manuals. Ability to effectively present information and respond to questions from groups of managers, clients, customers, and the general public.
MATHEMATICAL SKILLS:
Ability to calculate figures and amounts such as discounts, interest, commissions, proportions, percentages, area, circumference, and volume. Ability to apply concepts of basic algebra and geometry.
REASONING ABILITY:
Ability to apply common sense understanding to carry out instructions furnished in written, oral, or diagram form. Ability to deal with problems involving several concrete variables in standardized situations.
PHYSICAL DEMANDS:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to sit. The employee frequently is required to talk or hear. The employee is occasionally required to stand; walk; use hands to finger, handle, or feel; reach with hands and arms; and stoop, kneel, crouch, or crawl. The employee must occasionally lift and/or move up to 10 pounds. Specific vision abilities required by this job include close vision, and ability to adjust focus.
WORK ENVIRONMENT:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
The noise level in the work environment is usually moderate.
Salary Range: $105,000-$115,000
No Sponsorship: Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.
#HybridWork: We follow a Hybrid work schedule. All applicants must be able to work in our Tarrytown office Tues/Wed/Thurs (remote on Mon/Fri).
Work Hours: 40 hours per week.