Casey's logo
IT GRC Analyst
full-timeAnkeny$72k - $94k

Summary

Location

Ankeny

Salary

$72k - $94k

Type

full-time

Explore Jobs

About this role

Casey’s is seeking a Governance, Risk & Compliance (GRC) Analyst to help design, implement, and operate our enterprise compliance programs across PCI DSS and SOX IT General Controls. You’ll execute risk assessments, streamline evidence collection, automate recurring compliance tasks, and coordinate third-party risk assurance activities. If you enjoy turning policy requirements into auditable controls, and using automation to reduce manual work, this role is for you.

 

This role may be filled at the Associate GRC Analyst or GRC Analyst level based on experience, skills, and demonstrated capability.

 

What You’ll Do

  • Risk Assessments: Assist with or lead risk assessments discussions (e.g Cyber, Compliance, AI), maintain IT risk register, define treatment plans, and report status, trends, and residual risk.
  • Operate PCI DSS v4.0.1 controls across CDE environments, maintain scope/evidence, and support QSA interviews and artifact packaging for ROC/AOC submissions.
  • Support SOX ITGC readiness across access, change, computer operations by validating control design, coordinating evidence, supporting audit walkthroughs.
  • Automate compliance tasks using either enterprise or custom GRC solution to generate tickets, reminders, evidence collection, and review workflows for key control activities.
  • Manage third party risk (TPRM): conduct vendor onboarding questionnaires, review security documentation (SOC reports, AOCs etc.), track reassessments, and document decisions in TPRM Platform.
  • Maintain policies & SOPs: Update technology policies and standards, manage acknowledgments/exceptions, and ensure ‘policy à control à evidence’ linkage for auditability.
  • Automation, Reporting, and Process Improvement: Improve recurring compliance process workflows through automation, build and maintain dashboards for risk & controls posture, KRIs, remediation SLAs, and trends (e.g., Power BI/Power Automate), and identify control gaps/ process inefficiencies for practical improvements.

This role does not allow for 100% remote work. Qualified candidates must live within a daily commutable distance of Casey's Store Support Center in Ankeny, IA and be willing to work onsite 5 days per week.  

 

Compensation:

Starting pay range:‏‏‎ ‎$72,000 ‎-‏‏‎ ‎$94,500.‏‏‎ ‎ Actual pay may vary based on Casey’s assessment of the candidate's knowledge, skills, abilities (KSAs), related experience, education, and qualifications. Other factors impacting pay include local prevailing wages and internal equity. This position is eligible for an annual cash bonus based on company performance. Our full salary range for this role does extend beyond the hiring range listed, allowing team members the opportunity to continue to grow within the company. 

Qualifications
  • This position requires authorization to work in the U.S. without the need for employment-based immigration sponsorship now or in the future. Casey’s will not provide sponsorship or employer support for applications or petitions for F-1 OPT, F-1 CPT, H-1B, L-1, TN, O-1, E-3, H-1B1, J-1, or any other employment-based visa.
  • Bachelor’s degree in Information Security, Computer Science, MIS/Accounting/Finance, or a related field,  or equivalent experience.
  • Minimum 3 years in IT risk, compliance, audit, IAM, or security operations with hands on security policy, control execution, research, and evidence management.
  • You independently perform GRC tasks with minimal supervision and communicate effectively across IT, Security, Legal, Finance, Operations, and external partners, demonstrating strong collaboration and written and verbal skills.
  • Working knowledge of PCI DSS v4.01 and SOX ITGC; familiarity with risk management and assessment.
  • Support cyber and technology risk assessments by evaluating likelihood, exploitability, and business impact.
  • Experience with GRC/TPRM platforms (e.g. OneTrust, AuditBoard, SAFE TPRM) and automation/reporting tools (e.g., Power BI, Excel, Power Automate).

Nice to Have

  • Multi-site retail, convenience or hospitality industry experience.
  • Scripting exposure (PowerShell, Python, APIs).
  • Identity access governance (AD, Entra, privileged access).
  • Certifications: CISA, CRISC, CISSP, PCIP, Security + (or in progress).

Other facts

Tech stack
Governance,Risk Management,Compliance,PCI DSS,SOX,IT General Controls,Automation,Reporting,Process Improvement,Third Party Risk Management,Evidence Collection,Security Documentation,Collaboration,Communication,GRC Platforms,Power BI

About Casey's

Third largest convenience retailer.
Fifth largest pizza chain.
"Official Pizza & Beer Headquarters"

Casey's, started from humble beginings in 1968, and our purpose - to make life better for communities and guests every day - is at the heart of all we do.

Team size: 10,001+ employees
LinkedIn: Visit
Industry: Food and Beverage Services
Founding Year: 1968

What you'll do

  • The IT GRC Analyst will assist with risk assessments, operate PCI DSS controls, support SOX ITGC readiness, and automate compliance tasks. Additionally, they will manage third-party risk and maintain policies and SOPs.

Ready to join Casey's?

Take the next step in your career journey

Frequently Asked Questions

What does Casey's pay for a IT GRC Analyst?

Casey's offers a competitive compensation package for the IT GRC Analyst role. The salary range is USD 72k - 95k per year. Apply through Clera to learn more about the full compensation details.

What does a IT GRC Analyst do at Casey's?

As a IT GRC Analyst at Casey's, you will: the IT GRC Analyst will assist with risk assessments, operate PCI DSS controls, support SOX ITGC readiness, and automate compliance tasks. Additionally, they will manage third-party risk and maintain policies and SOPs..

Why join Casey's as a IT GRC Analyst?

Casey's is a leading Food and Beverage Services company. The IT GRC Analyst role offers competitive compensation.

Is the IT GRC Analyst position at Casey's remote?

The IT GRC Analyst position at Casey's is based in Ankeny, Iowa, United States. Contact the company through Clera for specific work arrangement details.

How do I apply for the IT GRC Analyst position at Casey's?

You can apply for the IT GRC Analyst position at Casey's directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Casey's on their website.