Compliance Program Analystst
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Domain|Compliance Services|Compliance Services|Assessment & implementation of Regulatory Standards, Domain|Design & Implementation of Common Control Framework
Domain
Delivery
Interest Group
Infy Chile
Company
IL Chile
Requisition ID
150976BR
Infosys Chile is looking for a Compliance Program Analyst. Your role will be: Be a critical part of the ATE Compliance Program, reporting directly to the Compliance Program Lead. Your focus? Understanding client's compliance standards inside and out — and helping the teams around you apply them correctly. This role centers on validating that controls are designed and operating effectively across ITGC, ISP, and QMS domains. You'll test controls, review evidence, facilitate audits, field inquiries, support escalations, and contribute to control design conversations — making sure the right standards are understood, applied, and met. You'll also support Quality Management System (QMS) testing for both Global and Territory-specific controls, including facilitating audit evidence collection, validation, and delivery throughout the year. You won't work in isolation. You'll partner with IT product teams, security, risk management, QMS resource owners, and internal/external auditors — serving as a knowledgeable, responsive resource who helps teams stay compliant and audit-ready.
Your main activities will be:ITGC control testing and validation (primary focus)
Develop a deep understanding of PwC's Information Security Policy (ISP) and Controls Standard — and help product and technology teams understand and apply the requirements to their environments.
Test and validate that ITGC controls are designed effectively and operating as intended across key domains — Access Controls, System Development and Change Management, Cyber Security and Data Protection, Service Management, and Resilience.
Validate controls across:
Identity and access management — confirm that provisioning and de-provisioning, privileged access reviews, segregation of duties, and authentication mechanisms are in place and functioning as required.
Change management — verify that SDLC controls, change management procedures, emergency change processes, and application development security controls are designed appropriately and operating effectively.
Cyber security operations — validate that incident management, malware protection, vulnerability and patch management, encryption, certificate administration, and logging and monitoring controls meet ISP requirements.
Database and network controls — confirm that database configuration and administration, firewall configuration, and system performance monitoring are compliant and evidenced.
Resilience — validate that business continuity and disaster recovery plans have been tested (at a minimum, annually) and that evidence supports compliance.
Validate that application penetration testing has been performed by independent third parties in accordance with ISP requirements. Review and validate the evidence, ensure it's complete and audit-ready, and provide it in support of audit requests. Escalate any gaps or concerns to the CPL.
Perform compliance checks to assess adherence against PwC's ISP, controls, and relevant standards — reviewing vulnerability scans, security control validations, and other evidence to confirm controls are met.
Evaluate control design and operating effectiveness. Document test results clearly and escalate deficiencies, gaps, or areas of concern to the CPL with practical recommendations.
Support control design conversations with product and technology teams — helping them understand what 'good' looks like and how to meet ISP and ITGC requirements before issues arise.
QMS testing — Global and Territory-specific controls
Support QMS control testing for both Global controls (firm-wide standards) and Territory-specific controls (local and regional regulatory and operational requirements).
Validate that QMS controls are designed effectively and operating as intended across applicable territories — through walkthroughs, sample testing, re-performance, and inspection.
Review and validate QMS evidence for completeness, accuracy, and audit-readiness. Facilitate evidence delivery to auditors and QMS program owners as needed.
Audit facilitation and evidence management
Facilitate internal and external audits — SOC 2, ISO 27001, 7216, and internal control reviews — on behalf of the CPL. That means fielding auditor inquiries, coordinating evidence requests, and ensuring smooth execution throughout the audit lifecycle.
Collect, review, and validate audit evidence to confirm it's complete, accurate, and aligned to the control requirements being tested. If something's missing or insufficient, follow up with control owners to close the gap.
Maint