Overview:
Live the experience. From professional empowerment to continual learning opportunities. From ongoing investment in new and emerging technologies to a career of self-determination. At Ulta Beauty, our tech team is critical to our scalability—and is recognized that way. We’ve been defined as a “mature start-up.” A place where interdepartmental exposure, open doors, and genuine collaboration is ubiquitous. Where challenges come fast and furious, requiring agility, mental dexterity, and creativity. Where our passion for better solutions drives us and is core to who we are.
We’re engineering for the future of retail, and it’s no-holds-barred. But for those motivated by continual change and ambiguity, by superior leadership, by whip smart colleagues who will press you daily for your very best, you’ll find that virtually nothing’s impossible at Ulta Beauty.
:
THE IMPACT YOU CAN HAVE:
The Associate Analyst, IT Compliance supports the organization's cybersecurity governance, risk management, and compliance programs in a dynamic and fast-paced environment. This role works closely with Information Security, IT, Internal Audit, business stakeholders, and control owners to help maintain compliance with regulatory, industry, and corporate requirements including Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standard (PCI DSS), and third-party risk management activities.
The Associate Analyst assists with the execution of compliance assessments, risk reviews, control monitoring, policy management, and audit support activities. The position develops a foundational understanding of information security frameworks, risk management practices, and regulatory requirements while contributing to the organization's overall cybersecurity and compliance objectives.
YOU'LL ACCOMPLISH THESE GOALS BY:
Compliance Program Support
Assists in the execution and maintenance of IT compliance programs, including SOX, PCI DSS, and other applicable regulatory, industry, and corporate requirements. Supports collection, organization, and validation of compliance evidence and documentation.
Assists with the identification, documentation, and tracking of cybersecurity and technology risks. Supports risk assessment activities and helps maintain risk registers, remediation plans, and related reporting.
Audit & Assessment Support
Supports internal and external audits by gathering requested documentation, coordinating evidence collection activities, tracking requests, and assisting with remediation follow-up activities.
Policy & Standards Management
Supports the maintenance, review, and communication of information security policies, standards, procedures, and guidelines. Assists in ensuring documentation remains current and aligned with organizational and regulatory requirements.
Third-Party Risk Management
Participates in vendor and third-party risk assessment processes by collecting information, reviewing submitted documentation, tracking assessment activities, and escalating identified concerns as appropriate.
Control Monitoring & Validation
Assists with monitoring the effectiveness of IT and cybersecurity controls. Reviews evidence submitted by control owners and supports control testing activities to validate compliance requirements.
Data Analysis & Reporting
Collects, analyzes, and interprets governance, risk, and compliance data. Assists with preparing reports, dashboards, metrics, and presentations that communicate compliance status, risk trends, and remediation activities.
Develops working relationships with business and technology teams to support compliance initiatives, facilitate information gathering, and promote awareness of governance, risk, and compliance requirements.
Identifies opportunities to improve governance, risk, compliance, and audit processes. Supports implementation of process improvements, standardization efforts, and documentation enhancements.
ADDITIONAL RESPONSIBILITIES:
- Coordinate with control owners to collect and validate compliance evidence for audits and assessments.
- Assist with tracking remediation activities for identified control deficiencies, audit findings, and risk treatment plans.
- Support quarterly compliance reviews and periodic control validation activities.
- Maintain governance, risk, and compliance documentation repositories, including policies, standards, risk registers, and control inventories.
- Monitor and document changes to relevant security frameworks, compliance requirements, and industry regulations.
- Assist with cybersecurity awareness and compliance communications across IT and business teams.
- Support development of governance and compliance metrics and reporting for leadership review.
- Participate in special projects and initiatives related to cybersecurity governance, risk management, and regulatory compliance.
:
ESSENTIALS FOR SUCCESS:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Information Systems, Risk Management, or a related field, or equivalent work experience.
- 0-2 years of experience in cybersecurity, IT compliance, IT audit, risk management, governance, information security, or a related technology field.
- Foundational understanding of information security concepts, cybersecurity frameworks, and IT controls.
- Basic knowledge of compliance and risk management frameworks such as SOX, PCI DSS, NIST, ISO 27001, COBIT, or similar standards preferred.
- Strong analytical, organizational, and problem-solving skills with attention to detail.
- Ability to collect, analyze, and interpret data and documentation from multiple sources.
- Excellent verbal and written communication skills with the ability to interact effectively with both technical and non-technical stakeholders.
- Proficiency with Microsoft Office applications, particularly Excel, PowerPoint, and Word.
- Ability to manage multiple priorities and meet deadlines in a fast-paced environment.
- Strong customer service mindset and ability to build collaborative relationships across teams.
- Self-motivated, proactive, and eager to learn new technologies, security concepts, and compliance requirements.
- Relevant coursework, internships, or certifications such as Security+, ISC2 CC, ITIL Foundation, or similar certifications are a plus.
- Flexibility of providing support during odd hours, weekends, and peak seasons.
- Minimal travel required (training/conferences).
#LI -ML1
#LI-HYBRID
: The pay range for this position is $79,900.00 - $85,000.00 / Year with the opportunity for eligible associates to earn additional compensation pursuant to the Company’s bonus plan. Exact pay will be based on factors including, but not limited to relevant education, qualifications, certifications, experience, level, shift, geographic location, and business and organizational needs. Full-time positions are eligible for paid time off, health, dental, vision, life and disability benefits. Part-time positions are eligible for dental, vision, life, and disability benefits. For additional information concerning our benefits, visit our Benefits and Career Development page: https://learn.bswift.com/ulta About:
At Ulta Beauty (NASDAQ: ULTA), the possibilities are beautiful. Ulta Beauty is the largest North American beauty retailer and the premier beauty destination for cosmetics, fragrance, skin care products, hair care products and salon services. We bring possibilities to life through the power of beauty each and every day in our stores and online with more than 25,000 products from approximately 500 well-established and emerging beauty brands across all categories and price points, including Ulta Beauty’s own private label. Ulta Beauty also offers a full-service salon in every store featuring—hair, skin, brow, and make-up services.
We will consider for employment all qualified applicants, including those with arrest records, conviction records, or other criminal histories, in a manner consistent with the requirements of any applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.