Compliance Analytics Analyst 3
Comcast
- Location
- PA - Philadelphia, 1701 John F Kennedy Blvd
- Work model
- On-Site
- Level
- Senior
- Posted
- 1d ago
Skills
About this role
Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You’ll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.) Job Summary Job Summary We are seeking a highly analytical and technically proficient Compliance Analyst to join our Continuous Compliance Monitor (CCM) team within the Cybersecurity GRC organization. In this role, you will help ensure that our technology environment, data practices, and security controls continuously align with internal policies and industry standards.You will leverage data analytics and automated monitoring tools to assess control effectiveness, proactively identify risks, and support continuous compliance efforts. Additionally, you will partner closely with engineering teams to embed compliance requirements into platform design and development, while delivering actionable insights that strengthen our overall cybersecurity posture.
Job Description
Responsibilities: Compliance Controls Control Requirements Definition: Define, map, and document comprehensive continuous compliance control requirements aligned to the organization’s cybersecurity frameworks, regulatory obligations, and internal policies. Control Validation & Effectiveness: Continuously test and validate the design and operational effectiveness of technical controls, ensuring they mitigate risk as intended and meet compliance standards. Platform Integration & Validation Functional Specification Development: Translate complex regulatory and compliance requirements into clear, actionable functional specifications for engineering and product teams developing internal platforms. Platform & Release Validation: Perform rigorous pre- and post-deployment validation of platforms and system updates to ensure compliance requirements are embedded and operating effectively. Data Analytics & Insights Control Monitoring & Analytics: Utilize data analytics tools to continuously monitor automated controls, analyze system activity, and proactively identify anomalies or control failures. Analytical Support for GRC Initiatives: Conduct deep-dive data analysis, extraction, and manipulation to support internal audits, regulatory inquiries, and broader GRC efforts. Data Storytelling & Reporting: Synthesize complex data into clear, compelling insights through dashboards and presentations. Communicate key trends, risk posture, and actionable recommendations to both technical and executive stakeholders.
Skills & Qualifications
5+ years of experience owning and leading cybersecurity processes or programs, with strong expertise in cybersecurity data analysis, metrics, reporting, and using data-driven insights to improve security and compliance outcomes. 5–7 years of experience in data analysis Experience in cybersecurity, compliance, or GRC environments Proficiency in Excel and SQL for analyzing large datasets Familiarity with (or ability to learn) Snowflake and Databricks environments Experience analyzing data and delivering insights to support compliance reporting, remediation efforts, and risk awareness Strong communication skills with the ability to engage and influence both technical and non-technical stakeholders