Analyst II, Information Risk Management
CarMax
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis. Sponsorship will not be considered for this specific role.
We are looking for an Analyst II, Information Risk Management to maintain and enhance the Information Risk Management posture of an innovative and fast paced company that is leveraging technology to provide innovative methods to improve the car buying experience.
The Analyst II, Information Risk Management is an integral individual contributor role within the CarMax Information Security Organization, focused on planning and executing critical risk and privacy operations and initiatives for the company to ensure continuous privacy operations, modernize control methodologies through automation and artificial intelligence, and streamline privacy assessments to improve the programs efficiency and effectiveness.
This is a unique opportunity to work at a Fortune 200 company and national brand to expand your skills and influence a growing Technology Program. This role will partner across Business and Technology teams to design, implement and manage privacy operations practices ensuring CarMax effectively assesses and mitigates risk to company and customer data. The successful candidate will leverage strengths in privacy operations execution and drive continuous improvement through process optimization, automation and AI for streamlined efficiency.
What you will do Essential Responsibilities
The Analyst II, Information Risk Management Privacy will focus primarily on facilitating and supporting regulatory and privacy operations for the company to ensure an effective and compliant posture for CarMax and our customers. This role serves as the conduit between the business community, Privacy core team, technology, and the application development teams. The Analyst II Privacy manages the intake, analysis and completion of privacy requests and facilitates all operational aspects of the privacy lifecycle, including:
- Privacy Request Support Coordinate with multiple technology teams to capture, assess and process data subject access requests (DSAR) timely and accurately.
- Privacy Operations Management Use service delivery principles to implement, execute and measure the program and related services consistently and effectively. Prepare and deliver regular program updates with KPIs that illustrate volumes, trends and risk areas to stakeholders. Maintain appropriate work management practices and backlogs to meet or exceed SLAs.
- Process Improvement Identify and implement opportunities to simplify and strengthen our privacy risk management processes and capabilities using process analysis, automation and AI where applicable.
- Privacy Technology Administration Utilize standalone and integrated platforms in daily operations and perform system improvements and administration.
- Privacy Impact Assessment Facilitate ongoing data privacy assessments of internal systems to effectively manage data sensitivity risk across in the enterprise.
- Policy Governance Lifecycle Management Own and manage the technology and information security focused guidance to ensure all policies, procedures, standards and job aids remain current, published and available for our associates.
- Knowledge Management Document and maintain clear, effective reference documentation (playbooks, processes, job aids, technical diagrams) as an internal knowledgebase and for ease of customer experience.
- Projects, as defined Participate in related strategic and tactical projects as necessary to mature the privacy operations function.
- As an integral member of the team, exhibiting ownership, follow-through, initiative, awareness and effective communication with peers and management and ability to speak to details of privacy operations.
- Maintain a strong knowledge base and awareness of industry and technological trends, external regulations for new or changed requirements within privacy and technology for core processes (e.g. NiST, PCI, ITIL, data privacy etc.).
Qualifications and Requirements:
- Bachelors degree in business / computer science / information systems (or related)
- 2+ years working experience in privacy, technology compliance, IT Audit, cybersecurity, or related experience.
- One or more of the following privacy-focused certifications such as: CIPP, CIPM, CIPT, CIA, CRSC, CISA.
- Experience / familiarity with relevant U.S. legal frameworks and privacy regulation such as: CCPA, GLBA, PCI, NYDFS, CFPB.
- Detail oriented Possess a keen eye for detail and accuracy in all operations. Leverage defined, repeatable methods for managing work and communicating progress and priority.
- Analytical approach Ability to perform data analysis and trending, problem solve obstacles and find alternative ways to meet and achieve privacy goals,
- Ability to understand and implement information risk and privacy principles across disciplines. Apply a risk-based approach to analysis in a fast-paced, rapidly evolving environment .
- Customer Focus Ability to provide exceptional customer service for our internal partners, with a mindset for understanding their need and consistently finding ways to exceed expectation.
- Communication Excellent verbal and written communication skills, with the ability to structure and deliver clear, accurate messaging. Ability to create and present concepts to various audiences, facilitate discussion with diplomacy while seeking diverse opinions to reach consensus
- Collaboration Strong emphasis on effective relationship building and partnership.
- Demonstrate initiative, ownership, and a service-oriented mindset in all interactions.
Work Location and Arrangement: This role will be based out of the Richmond, VA Technology Innovation Center. Associates based in Richmond work onsite 4 days per week.
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis. Sponsorship will not be considered for this specific role.
- CarMax Business Services in Richmond, VA is seeking an Analyst II, Information Risk Management to enhance the company's privacy operations. This role will manage privacy requests, improve processes using automation, and ensure compliance with U.S. regulations. The ideal...Suggested
- CarMax is seeking an Analyst II for Information Risk Management at the Richmond, VA Technology Innovation Center. The essential duties include coordinating data subject access requests and implementing privacy risk management programs. Ideal candidates will have a relevant...Suggested
- ...and be the subject matter expert in technology governance, risk management, compliance, and audit requirements? Then your job... ...here…. Who we are looking for: A Senior Technology/Information Risk Analyst with experience in the areas highlighted below. This is a...SuggestedFull timeWork experience placementWork at office
- ...career should be! The Income Tax Analyst II/Sr. Analyst will play a critical role... ...report to the Income Tax Compliance Manager and will work closely with the Income Tax... ...orientation, gender identity, genetic information, national origin, protected veteran status...SuggestedFull timeWork at officeLocal areaHome office
- ...etc.). Learns a wide variety of information related to Metering Operations... ...(Metering Field Scheduling Analyst I) or 3+ years of related experience... ...Field Scheduling Analyst II). Ability to continually analyze... ...responsibilities. Ability to manage multiple activities, remote...SuggestedContract workWork at officeRemote workVisa sponsorshipWork visaRelocation packageShift work
- ...in South Carolina is seeking a Clinical Informatics Analyst II to develop and implement clinical information systems. The ideal candidate will have significant... .... Responsibilities include mentoring junior staff, managing projects, and collaborating on healthcare technology...
- ...Analyst II, Credit Bureau Reporting and Software Configuration Play... ...as the configuration and management of our credit decisioning system... ...ARGO system as needed by the Risk team. Partner with dependent... ...ecosystem. Use a data informed approach to problem solving...Full timeWork at officeHome office
- ...Epic Analyst II – Beaker AP Position Title: Epic Analyst II – Beaker AP Department:... ...upgrades, following pre‑defined change management processes to ensure that new features and... ...and accessibility of critical information within the team. Provide training and...Full timeRemote workRelocationShift work
- ...an impact? We’re seeking a Compensation Analyst II to join our dynamic Compensation team. In... ...II, you’ll have the opportunity to manage and execute key compensation processes,... ...compensation guidelines and detailed compensation information to all levels of Associates in a...Temporary workWork experience placementWork at office
- ...ServiceNow Business Analyst II - MUST SIT IN EST We have a 12 month contract to hire for a... ...documentation skills, and the ability to manage competing priorities while meeting SLAs... ...Associate Employment type Contract Job function Information Technology Industries Staffing and...Contract workRemote workShift work
- Analyst II, Sales and Use Tax role at CarMax (posting via TieTalent).... ...taking direction from the Tax Manager to assist on projects related... ...initiatives and reducing tax risks through analysis and audit... ...orientation, gender identity, genetic information, national origin, protected...Full timeCasual workWork at officeLocal areaHome office
- Description The Data Analyst II is a financial and reporting analyst position that is responsible... ...analysis and presentation of financial information at the organizational, product, and... ...support production ETL processes Manage the deployment, monitoring, maintenance,...Work experience placement
- Income Tax Analyst II/Sr. Analyst Location: 8901 - Corp Office West Crk, 12800 Tuckahoe Creek... ...as well as present recommendations to management. Qualifications Bachelor’s Degree in... ...orientation, gender identity, genetic information, national origin, protected veteran...Full timeWork at officeLocal areaHome office
$23.42 - $29.3 per hour
...Carrier Disputes Analyst II Segra is searching for a qualified and experienced Carrier... ...Analyst II is responsible for independently managing moderately complex carrier disputes.... ..., marital status, disability, genetic information, age, membership in an employee...Full timeContract workWork at officeImmediate startRemote workFlexible hours2 days per week- ...3 skills required for this role? Asset Management CMDB Job Description / Responsibilities... ...technology asset lifecycle management, risk management, and regulatory compliance. Key... ...Associate Employment type Contract Job function Information Technology Industries Software...Long term contractContract workRemote work
- ...something special! The Lead Analyst, Risk Reporting will serve as the... ..., the Board and executive management at Markel, and rating agencies... ...: Familiarity with Solvency II, NAIC ORSA, or BMA... ...now or in the future. Pay information: Base salary offered for the...Full timeLocal areaWork from home
$61.68k - $92.52k
Business Analyst II - Wellpoint Federal Location : This role requires associates to be in-office 1-2 days per week, fostering collaboration... ...process improvement or reduce manual work. Additional Information If this job is assigned to any Government Business Division entity...Work experience placementWork at officeLocal area2 days per week1 day per week- Elevance Health is seeking a Business Analyst II to analyze business needs and translate them into application software requirements. This role allows for full-time virtual work with flexibility in scheduling, while ensuring essential in-person training sessions are met...Remote jobFull timeFlexible hours
- ...Job Description The Case Analyst II plays a significant role on a fully remote team supporting... ...maintaining the confidentiality of the information they encounter. A Case Analyst II must... ...skills for research, remediation, case management, and troubleshooting to support...Contract workRemote workFlexible hours
- ...consulting company in the United States is looking for a GRC Analyst II to support governance programs for clients. In this role, you... ...security policies. The ideal candidate will have 2-3 years in information security and excellent communication skills. This position...
- A technology solutions company in Virginia seeks an IT Business Analyst II to support projects by gathering requirements and documenting processes. The ideal candidate has experience in business analysis, strong organizational skills, and proficiency with tools like Visio...3 days per week
$64.7k - $107.9k
...NJ, MD, DE, VA, DC. The BLC Account Management Analyst is responsible for the activities involved in the ongoing monitoring and risk management of commercial clients within... ..., gender, gender identity, age, genetic information, marital status, disability, covered veteran...Full timeTemporary workWork experience placementWork at officeLocal areaWork visaFlexible hours- ...Senior SCRM Analyst PingWind is seeking a Senior SCRM Analyst to support mission-critical supply chain risk management programs for public sector customers. This role is ideal for an... ...mitigation recommendations that directly inform operational and strategic decisions....Temporary workFlexible hours
- ...Washington University in St. Louis is seeking a skilled professional to manage software configurations and resolve application issues. The candidate will participate in developing test plans and execute tests while handling incidents following agreed procedures. The role...
- A leading automotive retailer is seeking a Financial Reporting Analyst II in Richmond, Virginia. This role involves preparing financial statements, analyzing results, and ensuring SEC compliance. The ideal candidate holds a degree in Accounting, is a CPA candidate, and...
- A leading automotive retailer based in Richmond, VA seeks an Analyst II for Sales and Use Tax. Responsibilities include ensuring compliance with sales and use tax laws, tax research, and preparing compliance returns. Candidates must have a Bachelor's degree in Accounting...Casual work
- ...VDH Prog Analyst 4 PL/SQL VENDOR MAXIMUM SUBMITTAL RATE $$$.$$/hr. *local candidates strongly preferred *Mgr will conduct... ...as part of the Virginia Department of Health, Office of Information Management (OIM) team and plan, coordinate, develop, implement the assignments...Contract workWork experience placementWork at officeLocal area
- ...directly contribute to pricing strategies, risk assessment, and overall company... ...in personal lines Passed MAS I and MAS II, or equivalent knowledge Experience with... ...skills and experience working with senior management Why You Should Apply Flexible remote...Work at officeRemote workFlexible hours
$96.5k - $110.1k
...Senior Risk Associate, Enterprise Data Risk Management Do you want to be part of an organization that’s dedicated to helping Capital One manage data... ...listed below, by location. Please note that this salary information is solely for candidates hired to perform work...Full timePart timeLocal area$85k - $145.08k
...Allstate Insurance Company is looking for a P&C Actuary Senior Consultant II to manage projects related to reserving insurance business. This role demands collaboration with analytics management and requires strong actuarial analysis skills. The ideal candidate will...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Analyst II, Information Risk Management. Be the first to apply!
- operational risk consultant Richmond, VA
- it risk analyst Richmond, VA
- operational risk specialist Richmond, VA
- risk analyst Richmond, VA
- third party risk analyst Richmond, VA
- senior quantitative risk analyst Richmond, VA
- risk officer Richmond, VA
- risk consultant Richmond, VA
- risk underwriter Richmond, VA
- risk assurance Richmond, VA

