Looking for a career where you can make a difference?
At Mary Kay we are committed to enriching the lives of women and their families around the world, we offer careers with unlimited opportunities to do something beautiful every day. More than 5,000 employees work in locations around the world. They provide products, marketing and other support to millions of Independent Beauty Consultants (IBCs) who work as independent contractors, selling our products directly to consumers in nearly 40 markets on five continents.
This role is a key contributor to the enterprise cybersecurity governance strategy, responsible for leading initiatives that enhance security awareness, ensure audit preparedness, and strengthen vendor governance. The Senior Compliance Analyst will operate with a high degree of autonomy, influence cross-functional teams, and serve as a subject matter expert on cybersecurity frameworks, risk mitigation practices, and regulatory compliance.
Key Responsibilities
- Compliance Leadership Act as the primary compliance representative at the corporate office, fostering a culture of accountability and proactive risk management through direct engagement with business units.
- Policy Governance Oversee the annual review and enhancement of internal policies in alignment with frameworks such as SCF, PCI DSS, and ISO 27001. Collaborate with stakeholders to ensure policies are current, enforceable, and audit-ready.
- Audit & Vendor Governance Lead coordination of external audit responses and annual vendor risk assessments. Ensure timely and accurate documentation, and drive resolution of compliance gaps across SaaS platforms and third-party engagements.
- Security Awareness Strategy Design and execute enterprise-wide cybersecurity awareness campaigns to elevate participation in Security Awareness Training (SAT). Develop targeted messaging and leverage creative tools and communication strategies to maximize engagement, reinforce secure behaviors, and ensure alignment with organizational risk posture.
- Cross-Functional Collaboration Partner with Legal, Procurement, IT, and business units to ensure compliance messaging is aligned, actionable, and well-integrated into operational workflows.
- Reporting & Metrics Maintain dashboards and executive summaries on training completion, audit status, and vendor compliance. Provide insights and recommendations to leadership for continuous improvement.
Qualifications
Bachelor’s degree in Business, Information Systems, Cybersecurity, or a related field.5+ years of experience in IT governance, risk and compliance, or audit.Demonstrated expertise in regulatory frameworks (PCI DSS, NIST CSF, ISO 27001) and GRC tools (e.g., OneTrust).Strong leadership, communication, and stakeholder management skills.Proven ability to manage complex projects, influence without authority, and drive cross-functional outcomes.Creative thinker with experience in campaign development.