Analyst II, Cybersecurity- Information Risk Management
CarMax
8901 - Corp Office West Crk - 12800 Tuckahoe Creek Parkway, Richmond, Virginia, 23238
CarMax, the way your career should be!We are looking for an Analyst II, Information Risk Management to maintain and enhance the Information Risk Management posture of an innovative and fast paced company that is leveraging technology to provide innovative methods to improve the car buying experience. The Analyst II, Information Risk Management is an integral individual contributor role within the CarMax Information Security Organization, focused on planning and executing critical risk and privacy operations and initiatives for the company to ensure continuous privacy operations, modernize control methodologies through automation and artificial intelligence, and streamline privacy assessments to improve the program's efficiency and effectiveness. This is a unique opportunity to work at a Fortune 200 company and national brand to expand your skills and influence a growing Technology Program. This role will partner across Business and Technology teams to design, implement and manage privacy operations practices ensuring CarMax effectively assesses and mitigates risk to company and customer data. The successful candidate will leverage strengths in privacy operations execution and drive continuous improvement through process optimization, automation and AI for streamlined efficiency.
What you will do - Essential Responsibilities The Analyst II, Information Risk Management - Privacy will focus primarily on facilitating and supporting regulatory and privacy operations for the company to ensure an effective and compliant posture for CarMax and our customers. This role serves as the conduit between the business community, Privacy core team, technology, and the application development teams. The Analyst II - Privacy manages the intake, analysis and completion of privacy requests and facilitates all operational aspects of the privacy lifecycle, including:
- Privacy Request Support - Coordinate with multiple technology teams to capture, assess and process data subject access requests (DSAR) timely and accurately.
- Privacy Operations Management - Use service delivery principles to implement, execute and measure the program and related services consistently and effectively. Prepare and deliver regular program updates with KPIs that illustrate volumes, trends and risk areas to stakeholders. Maintain appropriate work management practices and backlogs to meet or exceed SLAs.
- Process Improvement - Identify and implement opportunities to simplify and strengthen our privacy risk management processes and capabilities using process analysis, automation and AI where applicable.
- Privacy Technology Administration - Utilize standalone and integrated platforms in daily operations and perform system improvements and administration.
- Privacy Impact Assessment - Facilitate ongoing data privacy assessments of internal systems to effectively manage data sensitivity risk across in the enterprise.
- Policy Governance Lifecycle Management - Own and manage the technology and information security focused guidance to ensure all policies, procedures, standards and job aids remain current, published and available for our associates.
- Knowledge Management - Document and maintain clear, effective reference documentation (playbooks, processes, job aids, technical diagrams) as an internal knowledgebase and for ease of customer experience.
- Projects, as defined - Participate in related strategic and tactical projects as necessary to mature the privacy operations function.
- As an integral member of the team, exhibiting ownership, follow-through, initiative, awareness and effective communication with peers and management and ability to speak to details of privacy operations.
- Maintain a strong knowledge base and awareness of industry and technological trends, external regulations for new or changed requirements within privacy and technology for core processes (e.g. NiST, PCI, ITIL, data privacy etc.).
- Bachelor's degree in business / computer science / information systems (or related)
- 2+ years working experience in privacy, technology compliance, IT Audit, cybersecurity, or related experience.
- One or more of the following privacy-focused certifications such as: CIPP, CIPM, CIPT, CIA, CRSC, CISA.
- Experience / familiarity with relevant U.S. legal frameworks and privacy regulation such as: CCPA, GLBA, PCI, NYDFS, CFPB.
- Detail oriented - Possess a keen eye for detail and accuracy in all operations. Leverage defined, repeatable methods for managing work and communicating progress and priority.
- Analytical approach - Ability to perform data analysis and trending, problem solve obstacles and find alternative ways to meet and achieve privacy goals,
- Ability to understand and implement information risk and privacy principles across disciplines. Apply a risk-based approach to analysis in a fast-paced, rapidly evolving environment .
- Customer Focus - Ability to provide exceptional customer service for our internal partners, with a mindset for understanding their need and consistently finding ways to exceed expectation.
- Communication - Excellent verbal and written communication skills, with the ability to structure and deliver clear, accurate messaging. Ability to create and present concepts to various audiences, facilitate discussion with diplomacy while seeking diverse opinions to reach consensus
- Collaboration - Strong emphasis on effective relationship building and partnership.
- Demonstrate initiative, ownership, and a service-oriented mindset in all interactions.
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis. Sponsorship will not be considered for this specific role. About CarMax CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation's largest retailer of used cars, with over 200 locations nationwide. Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®. Our Commitment to Diversity and Inclusion: CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment. CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, gender expression, genetic information, national origin, protected veteran status, disability status, and any other characteristics protected by law. Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Analyst II, Cybersecurity- Information Risk Management in Henrico, VA vacancy
- CarMax Business Services in Richmond, VA is seeking an Analyst II, Information Risk Management to enhance the company's privacy operations. This role will manage privacy requests, improve processes using automation, and ensure compliance with U.S. regulations. The ideal...Suggested
- CarMax is seeking an Analyst II for Information Risk Management at the Richmond, VA Technology Innovation Center. The essential duties include coordinating data subject access requests and implementing privacy risk management programs. Ideal candidates will have a relevant...Suggested
- ...to play a key role in enhancing the Cybersecurity program for a Fortune 200 company... ...matter expert in technology governance, risk management, compliance, and audit requirements... ...looking for A Senior Technology/Information Risk Analyst with experience in the areas...SuggestedFull timeWork experience placement
- ...an impact? We’re seeking a Compensation Analyst II to join our dynamic Compensation team. In... ...II, you’ll have the opportunity to manage and execute key compensation processes,... ...compensation guidelines and detailed compensation information to all levels of Associates in a...SuggestedTemporary workWork experience placementWork at office
- ...Security Metrics Consultant & Databricks Analyst Drives identity security initiatives... ...~ Executive briefing, stakeholder management, storytelling with data ~ Ability to... ...requirements: A minimum of 3 years' cybersecurity experience. A degree from an accredited...SuggestedPermanent employmentInterim role
- ...Richmond, Virginia, 23238 The Income Tax Analyst II/Sr. Analyst will play a critical role... ...report to the Income Tax Compliance Manager and will work closely with the Income Tax... ...orientation, gender identity, genetic information, national origin, protected veteran status...Full timeWork at officeLocal areaHome office
- Analyst II, Sales and Use Tax role at CarMax (posting via TieTalent).... ...taking direction from the Tax Manager to assist on projects related... ...initiatives and reducing tax risks through analysis and audit... ...orientation, gender identity, genetic information, national origin, protected...Full timeCasual workWork at officeLocal areaHome office
$37.31 - $58.75 per hour
...Intermountain's policies and procedures. Revenue Integrity Analyst II Service Areas: Emergency/Trauma, Transport, Behavioral Health... ...and payer policy review, abstracting of financial and clinical information from various sources. Presents, researches, and follows-up...Hourly payMonday to FridayFlexible hours$61.68k - $92.52k
...05-29 Position Title: Business Analyst II - Wellpoint Federal Job Description:... ...consistent with the law. Job Level: Non-Management Exempt Workshift: 1st Shift (... ...creed, disability, ethnicity, genetic information, gender (including gender identity and...Temporary workWork experience placementWork at officeLocal areaDay shift2 days per week1 day per week- Income Tax Analyst II/Sr. Analyst Location: 8901 - Corp Office West Crk, 12800 Tuckahoe Creek... ...as well as present recommendations to management. Qualifications Bachelor’s Degree in... ...orientation, gender identity, genetic information, national origin, protected veteran...Full timeWork at officeLocal areaHome office
- A reputed HR firm is seeking an IT Security Analyst for a 14-month role in Richmond, VA, with an option... ...analyst will support the Virginia State Police Information Security program, focusing on cybersecurity, risk management, and compliance. Candidates should possess 5...Remote work
- ...Description The P&C Business Analyst II is responsible for executing... .... Essential Responsibilities Manages incoming requests, researching... ...impact, analyzes cost/benefit and risk of change and assists in... ...expression, gender identity, genetic information, marital status, national...Work at officeFlexible hours
- Elevance Health is seeking a Business Analyst II to analyze business needs and translate them into application software requirements. This role allows for full-time virtual work with flexibility in scheduling, while ensuring essential in-person training sessions are met...Remote jobFull timeFlexible hours
$37.31 - $58.75 per hour
Intermountain Health is seeking a Revenue Integrity Analyst II responsible for billing and resolving payment issues. The role involves analyzing data, developing reports, and mentoring other analysts, all while ensuring compliance with healthcare regulations. The ideal...Hourly pay- ...Job Description The Case Analyst II plays a significant role on a fully remote team supporting... ...maintaining the confidentiality of the information they encounter. A Case Analyst II must... ...skills for research, remediation, case management, and troubleshooting to support...Contract workRemote workFlexible hours
- ...something special!The Lead Analyst, Risk Reporting will serve as the... ...regulators, the Board and executive management at Markel, and rating... ...* Familiarity with Solvency II, NAIC ORSA, or BMA regulatory... ...now or in the future.**Pay information:**Base salary offered for the...Full timeLocal areaWork from home
- A technology solutions company in Virginia seeks an IT Business Analyst II to support projects by gathering requirements and documenting processes. The ideal candidate has experience in business analysis, strong organizational skills, and proficiency with tools like Visio...3 days per week
- A technology firm is seeking an IT Business Analyst II to support technology initiatives and facilitate communication between teams. The ideal candidate will have strong analytical, organizational, and communication skills, with experience in requirements gathering and...3 days per week
- ...Business Analyst This is a multi-level posting. Candidates may... ...technical teams, and project managers, translating business requirements... ...the IT PMO Business Analyst II Proficiency with... ...-1, J-1, etc. For additional information around work authorization needs...Permanent employmentWork experience placementInternshipH1bWork at officeLocal area
$61.68k - $92.52k
...Date: 2026-05-29 Position Title: Business Analyst II - Wellpoint Federal Job Description:... ...consistent with the law. Job Level: Non-Management Exempt Workshift: 1st Shift (United... ...creed, disability, ethnicity, genetic information, gender (including gender identity and...Full timeContract workTemporary workWork experience placementWork at officeLocal areaDay shift2 days per week1 day per week- A leading automotive retailer is seeking a Financial Reporting Analyst II in Richmond, Virginia. This role involves preparing financial statements, analyzing results, and ensuring SEC compliance. The ideal candidate holds a degree in Accounting, is a CPA candidate, and...
- A leading automotive retailer based in Richmond, VA seeks an Analyst II for Sales and Use Tax. Responsibilities include ensuring compliance with sales and use tax laws, tax research, and preparing compliance returns. Candidates must have a Bachelor's degree in Accounting...Casual work
$120.8k - $137.9k
...Principal Risk Associate, Enterprise Data Risk Management Do you want to be part of an organization that’s dedicated to helping Capital One manage data... ...below, by location. Please note that this salary information is solely for candidates hired to perform work within...Full timePart timeLocal area$95k - $105k
...governance and compliance program. Works closely with Information Security, Legal, Risk Management, and business stakeholders to help ensure AI... ...governance and technology risk (e.g., NIST AI RMF, NIST Cybersecurity Framework, SOC/SSAE, ISO/IEC 27001 concepts) a plus....Work experience placement$120.8k - $137.9k
...Card Risk Principal Associate (Hybrid) Risk Managers at Capital One are highly motivated Risk Management professionals with excellent organizational and... ...communicating with key stakeholders across all levels to manage, inform, and influence outcomes Supporting, partnering and...Full timePart timeLocal area- ...proprietary data and advanced AI to surface risk, automate compliance, and unlock... ...to the federal government. Analyst, Supply Chain Risk Management (SCRM) - Illuminations... ...enabled tools to gather and analyze information Develop written deliverables, presentations...InternshipVisa sponsorshipFlexible hours
- ...Data Analyst Intern Cognicion LLC, a boutique eDiscovery services and information management provider is actively recruiting a motivated Data Analyst Intern to assist internal teams through day-to-day support of the tools, applications, processes, and requirements...Internship
- A leading cybersecurity firm in Richmond, Virginia is seeking an experienced cybersecurity analyst. The ideal candidate will have 2-5 years in cybersecurity operations and mastery of tools like Splunk and Qualys. Responsibilities include monitoring alerts, investigating...
$111.2k - $126.9k
...Sr. Business Analyst - Anti-Money Laundering As a Senior Business Analyst in the Anti... ...One from fraud and money laundering. Risk management is at the center of what we do at Capital... .... Help build targeted insights to inform the design and development of new customer...Full timeTemporary workPart timeLocal area- ...Business Analyst 4 Location: 102 Governor St., Richmond, VA 23219 ONSITE REQMT: 4... ...applications. Works with business and Information Systems staff to determine needs and produce... ..., data analytics, system automation, cybersecurity, and cloud technology solutions for...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Analyst II, Cybersecurity- Information Risk Management. Be the first to apply!
Related searches
- risk assurance Henrico, VA
- cybersecurity software engineer Henrico, VA
- health information management work from home Henrico, VA
- document management coordinator Henrico, VA
- records management associate Henrico, VA
- records management specialist Henrico, VA
- director of health information management Henrico, VA
- information management coordinator Henrico, VA
- information management specialist Henrico, VA
- director of information management Henrico, VA

