Analyst, IT Audit and Compliance
Listed on 2026-07-15
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security
Company Overview
Foundation Building Materials (FBM) is a leading construction materials distribution company serving the commercial and residential construction markets across the United States and Canada. In conjunction with Unified Door & Hardware Group (UDHG), a premier provider of commercial door, frame and hardware solutions, FBM supports a broad range of construction and architectural projects nationwide.
FBM’s 8,000+ team members are committed to operational excellence, innovation, and employee development. By combining scale, specialty expertise, and a customer‑first mindset, we deliver high‑quality products and services to contractors, builders, and project teams across diverse markets. Following our recent acquisition by Lowe’s, we are investing in strong, forward‑thinking talent to support long‑term success.
Position OverviewThe Analyst, IT Audit and Compliance is responsible for handling IT audit, risk assessment, and compliance program work. This role ensures that IT systems, processes, and controls comply with internal policies, industry standards, and regulatory requirements. The analyst will work closely with IT, security, finance, and business teams to strengthen internal controls, mitigate risks, and support strategic initiatives under the leadership of the Manager, IT Audit and Compliance.
Key ResponsibilitiesAudit & Risk Management
- Support the planning and execution of IT audits to evaluate the design and effectiveness of internal controls, security measures, and operational processes.
- Assist with testing and documentation of SOX controls within a publicly traded company environment.
- Participate in risk assessments to identify gaps and vulnerabilities in IT systems and processes.
- Support third‑party risk assessments of vendors in accordance with NIST and other established frameworks.
- Assist in maintaining audit plans and supporting audit activities aligned with business priorities and regulatory changes.
- Track and monitor remediation efforts from audit findings and assist in ensuring timely closure of action items.
Compliance & Governance
- Support compliance activities related to regulatory requirements and frameworks, including SOX, NIST, and PCI.
- Assist with PCI‑DSS 4.0 compliance efforts, including evidence collection and documentation related to scope reduction initiatives such as segmentation, iFrame, and P2PE.
- Maintain IT compliance documentation, policies, procedures, and supporting materials.
- Collaborate with Legal, Finance, IT, and business stakeholders to support compliance initiatives across systems and processes.
- Monitor regulatory updates and communicate relevant changes to the broader team.
Leadership & Collaboration
- Support internal and external audit activities by coordinating requests, gathering documentation, and assisting with audit inquiries.
- Assist with monitoring compliance risks through established internal controls and process improvement initiatives.
- Coordinate with internal stakeholders and external auditors to support audit and compliance activities.
Continuous Improvement
- Participate in initiatives to improve IT audit, risk management, and compliance processes and controls.
- Partner with IT and Security teams to promote best practices in information security and data protection.
- Assist with external audits, assessments, and compliance reviews conducted by auditors, regulators, and third‑party assessors.
- Prepare reports, metrics, and documentation to support management visibility into audit and compliance activities.
Additional Responsibilities
- Perform other duties as assigned to support IT Audit and Compliance objectives.
- Bachelor’s degree in Information Systems, Computer Science, Accounting, Cybersecurity, or a related field.
- CISA, CISM, CISSP, CRISC, or similar certifications preferred but not required.
- 1–3 years of experience in IT audit, compliance, cybersecurity, risk management, or related fields.
- Foundational understanding of IT general controls, cybersecurity frameworks, and regulatory requirements.
- Exposure to SOX, IT audits, compliance testing, or risk assessments through professional experience, internships, or public accounting preferred.
- Strong…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).