Employee Records
GRC Regulatory Compliance Senior Analyst
Kura Sushi Corporate Support Center
GRC Regulatory Compliance Senior Analyst
Kura Sushi Corporate Support Center
Full Time
Hybrid remote
Coins Icon $90000 - $105000 / Year
GRC Regulatory Compliance Senior Analyst
Kura Sushi Corporate Support Center

Description

Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC Senior Regulatory Compliance Analyst, who has proficient knowledge in regulatory compliance rules and regulations will be responsible for assisting the Integrated GRC Senior Manager (Juris Doctorate) for ensuring Kura meets all applicable legal, regulatory, and internal regulatory compliance requirements and facilitating centralized monitoring. This includes but not limited to: 

  • Evaluating regulatory laws applicable to Kura business operations.
  • Conducting compliance audits and reviews to ensure execution of compliance standards.
  • Preparing and presenting compliance reports to the VP of ACAS and other applicable executives.
  • Identifying compliance issues requiring follow-up or investigation.
  • Disseminating written policies and procedures related to compliance activities.
    Collaborating with cross-functional departments to foster a culture of compliance.
  • Maintaining documentation of compliance activities.
  • Ongoing professional development and staying abreast with the latest trends and changes in laws and regulations

    Other responsibilities include but not limited to facilitating/moderating annual regulatory compliance risk assessments, reviewing contracts containing PII, system components, MNDA, performing compliance assessments/reviews, monitoring compliance activities /remediation efforts, conducting investigations, and providing guidance and facilitation to cross-functional peers and senior management relating to various regulatory compliance that Kura is subject to such as CCPA/CPRA, PCI, Information Security (Cybersecurity), Artificial Intelligence, Information Technology standards and Frameworks, FDA, ESG, SOX etc.  

In addition, the GRC Regulatory Compliance Senior Analyst will partner with/provide guidance to the GRC Senior Security Analyst and the Head of Information Technology, when applicable, in designing/implementing information services (IT and security) solution components used throughout Kura Sushi’s environment as well as liaising with the Internal Audit team for in-scope SOX systems.   The GRC Regulatory Compliance Senior Analyst will be responsible for assisting the Integrated GRC Senior Manager in facilitating Kura’s vendor relationships with several outsourced service providers as needed in establishing a scalable and compliant environment to support the Company’s compliance landscape to include security and technological components.

The GRC-Regulatory Compliance Senior Analyst require proficient knowledge and understanding of compliance standards and frameworks  to include end-to-end business process, security frameworks (including domains such as access management and data protection), regulatory compliance (e.g., SOX, PCI, CPRA, etc.) and technology standards, procedures, guidelines and; and be able to prepare and communicate compliance issues to the Integrated GRC Senior Manager, VP of ACAS and others as directed by the VP of ACAS.
 
Key Responsibilities

  • Policy & Procedure Development: Draft, review, and update privacy and compliance policies, procedures, and training materials to align with evolving laws and regulations 
  • Regulatory Monitoring: Research and interpret new or revised laws, regulations, and industry standards; track changes and recommend updates to the compliance program 
  • Risk Assessment & Auditing: Conduct risk assessments, compliance audits, and testing of controls to identify gaps and deficiencies; develop and implement gap closure plans 
  • Training & Culture: Lead or assist in compliance training programs for new hires and ongoing staff, promoting a culture of compliance 
  • Cross-Functional Collaboration: Work with legal, finance, operations, and other departments to integrate compliance into business processes (e.g., Privacy by Design “PbD”)
  • Reporting: Prepare clear, concise compliance reports for management and regulatory bodies, highlighting risks, findings, and recommendations 

Regulatory Compliance

1. Ensures the organization complies with all applicable laws, regulations, and internal policies. This includes monitoring business operations and reporting any infractions. 

2. Partners with General Counsel and other management members, as needed

3. Policy Development: Create, modify, and implement company policies and procedures to align with legal requirements and ethical standards. 

4. Risk Management: Develop risk management strategies and conduct regular audits to identify areas of potential non-compliance. 

5. Manage the operational processes for Data Subject Requests (DRS) such as rights to access or delete personal data.

6. Maintain up-to-date Records of Processing Activities (RoPA) across departments.

7. Advise operational personnel on appropriate responses to recurring confidentiality and data disclosure inquiries.

8. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and audits. 

9. Incident Management: Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence

10. Reporting: Provide regular reports to the Integrated GRC Senior Manager, VP of ACAS and other senior management on the status of the compliance program and any issues that arise.

11.  Conducts annual regulatory compliance risk assessments

12.  Reviews and main contracts containing PII and system/AI components to ensure DPAs are issued to 3rd party vendors.

13.  Performs compliance assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting investigations,

Governance, Risk and Compliance (GRC Activities)

1. Provides guidance to the Information Services (Security and Technology) management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.

2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.

3. Perform Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) for new system implementations.

4. Liaise with Internal Audit members to ensure appropriate controls over business and IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness.

5. Evaluate third party vendor contracts, performing privacy and security due diligence on business associates and service providers.

6. Develops reporting metrics, dashboards, and obtains and retains evidence and provides to the Integrated GRC Senior Manager, VP of ACAS or other leadership, as needed for review.

7. Provides guidance to the Security Senior Analyst for building the organization’s cybersecurity strategy to ensure Kura Security team is proactively identifying/addressing relevant security gaps, compliant with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.

8. Collaborates with cross-functional business, security and the information technology team to ensure security strategies and initiatives align with business objectives and regulatory compliance requirements.

9. Provides guidance to the Security Manager in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations.

10. Collaborates with the Integrated GRC Senior Analyst, GRC-Senior Security Analysts, Internal Audit and other key members who will at a minimum, facilitate and monitor compliance enterprise wide.

11. Facilitation and the coordination, development and implementation of security awareness compliance programs and education while partnering with the Security Manager.

12. Facilitates, guides coordinates, and partners with the Security Manager during the systems development life cycle activities and new processes to ensure they are properly implemented in conjunction with guidance from the Internal Audit team.

13. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the IT/Security team on remediation plan.

14. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and regulatory requirements.

15. Presents issues of IT non-compliance to the Integrated GRC Senior Manager and VP of ACAS

16. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.

17. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and VP of ACAS

18. Perform other projects assigned by the Integrated GRC Senior Manager and VP of ACAS

SKILLS AND QUALIFICATIONS: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:

1. Bachelor’s degree in business, Finance, Law, Accounting, or related field; MBA, Juris Doctorate, Information Technology or advanced degree preferred

2. Prefer Juris Doctorate degree with compliance certifications such as: Certified Information Privacy Professional (CIPP/US), Certified Regulatory Compliance Manager (CRCM), Certified Compliance & Ethics Professional (CCEP); desirable to possess CIA/CISA/CPA certifications.

3. 5 years of experience in regulatory compliance with legal, compliance and/internal audit role and prefer multi-location restaurant and/or retail businesses background.

4. Big 4 consulting experience

5. Proficiency with Office 365 (O365), particularly: PowerPoint, Outlook, Excel, and Word

6. Proficient with regulatory requirements related to CCPA/CPRA, PCI, ESG, Information Security (Cybersecurity), Information Technology, SOX, ADA, FDA etc.

7. Proficient with Optro (formerly Audit Board)-Cross Comply, Risk Oversight, BigID, Contract Management Systems, NAVEX

8. Strong regulatory compliance background.

9. Excellent leadership and people management skills.

10. Skills in documenting risk, and regulatory compliance activities

11. Familiar with dashboard creation

12. Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with different ACAS functional areas, e.g., Security, GRC and Internal Audit to ensure appropriate compliance controls. Demonstrates ability to articulate business cases for identified technology solutions.
13. Demonstrates ability to articulate regulatory compliance and information services activities to the Audit Committee or the Board, at the request of the VP of ACAS, if needed.
14. Excellent analytical and troubleshooting skills.
15. Ability to work under pressure.

Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC Senior Regulatory Compliance Analyst, who has proficient knowledge in regulatory compliance rules and regulations will be responsible for assisting the Integrated GRC Senior Manager (Juris Doctorate) for ensuring Kura meets all applicable legal, regulatory, and internal regulatory compliance requirements and facilitating centralized monitoring. This includes but not limited to: 

  • Evaluating regulatory laws applicable to Kura business operations.
  • Conducting compliance audits and reviews to ensure execution of compliance standards.
  • Preparing and presenting compliance reports to the VP of ACAS and other applicable executives.
  • Identifying compliance issues requiring follow-up or investigation.
  • Disseminating written policies and procedures related to compliance activities.
    Collaborating with cross-functional departments to foster a culture of compliance.
  • Maintaining documentation of compliance activities.
  • Ongoing professional development and staying abreast with the latest trends and changes in laws and regulations

    Other responsibilities include but not limited to facilitating/moderating annual regulatory compliance risk assessments, reviewing contracts containing PII, system components, MNDA, performing compliance assessments/reviews, monitoring compliance activities /remediation efforts, conducting investigations, and providing guidance and facilitation to cross-functional peers and senior management relating to various regulatory compliance that Kura is subject to such as CCPA/CPRA, PCI, Information Security (Cybersecurity), Artificial Intelligence, Information Technology standards and Frameworks, FDA, ESG, SOX etc.  

In addition, the GRC Regulatory Compliance Senior Analyst will partner with/provide guidance to the GRC Senior Security Analyst and the Head of Information Technology, when applicable, in designing/implementing information services (IT and security) solution components used throughout Kura Sushi’s environment as well as liaising with the Internal Audit team for in-scope SOX systems.   The GRC Regulatory Compliance Senior Analyst will be responsible for assisting the Integrated GRC Senior Manager in facilitating Kura’s vendor relationships with several outsourced service providers as needed in establishing a scalable and compliant environment to support the Company’s compliance landscape to include security and technological components.

The GRC-Regulatory Compliance Senior Analyst require proficient knowledge and understanding of compliance standards and frameworks  to include end-to-end business process, security frameworks (including domains such as access management and data protection), regulatory compliance (e.g., SOX, PCI, CPRA, etc.) and technology standards, procedures, guidelines and; and be able to prepare and communicate compliance issues to the Integrated GRC Senior Manager, VP of ACAS and others as directed by the VP of ACAS.
 
Key Responsibilities

  • Policy & Procedure Development: Draft, review, and update privacy and compliance policies, procedures, and training materials to align with evolving laws and regulations 
  • Regulatory Monitoring: Research and interpret new or revised laws, regulations, and industry standards; track changes and recommend updates to the compliance program 
  • Risk Assessment & Auditing: Conduct risk assessments, compliance audits, and testing of controls to identify gaps and deficiencies; develop and implement gap closure plans 
  • Training & Culture: Lead or assist in compliance training programs for new hires and ongoing staff, promoting a culture of compliance 
  • Cross-Functional Collaboration: Work with legal, finance, operations, and other departments to integrate compliance into business processes (e.g., Privacy by Design “PbD”)
  • Reporting: Prepare clear, concise compliance reports for management and regulatory bodies, highlighting risks, findings, and recommendations 

Regulatory Compliance

1. Ensures the organization complies with all applicable laws, regulations, and internal policies. This includes monitoring business operations and reporting any infractions. 

2. Partners with General Counsel and other management members, as needed

3. Policy Development: Create, modify, and implement company policies and procedures to align with legal requirements and ethical standards. 

4. Risk Management: Develop risk management strategies and conduct regular audits to identify areas of potential non-compliance. 

5. Manage the operational processes for Data Subject Requests (DRS) such as rights to access or delete personal data.

6. Maintain up-to-date Records of Processing Activities (RoPA) across departments.

7. Advise operational personnel on appropriate responses to recurring confidentiality and data disclosure inquiries.

8. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and audits. 

9. Incident Management: Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence

10. Reporting: Provide regular reports to the Integrated GRC Senior Manager, VP of ACAS and other senior management on the status of the compliance program and any issues that arise.

11.  Conducts annual regulatory compliance risk assessments

12.  Reviews and main contracts containing PII and system/AI components to ensure DPAs are issued to 3rd party vendors.

13.  Performs compliance assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting investigations,

Governance, Risk and Compliance (GRC Activities)

1. Provides guidance to the Information Services (Security and Technology) management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.

2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.

3. Perform Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) for new system implementations.

4. Liaise with Internal Audit members to ensure appropriate controls over business and IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness.

5. Evaluate third party vendor contracts, performing privacy and security due diligence on business associates and service providers.

6. Develops reporting metrics, dashboards, and obtains and retains evidence and provides to the Integrated GRC Senior Manager, VP of ACAS or other leadership, as needed for review.

7. Provides guidance to the Security Senior Analyst for building the organization’s cybersecurity strategy to ensure Kura Security team is proactively identifying/addressing relevant security gaps, compliant with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.

8. Collaborates with cross-functional business, security and the information technology team to ensure security strategies and initiatives align with business objectives and regulatory compliance requirements.

9. Provides guidance to the Security Manager in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations.

10. Collaborates with the Integrated GRC Senior Analyst, GRC-Senior Security Analysts, Internal Audit and other key members who will at a minimum, facilitate and monitor compliance enterprise wide.

11. Facilitation and the coordination, development and implementation of security awareness compliance programs and education while partnering with the Security Manager.

12. Facilitates, guides coordinates, and partners with the Security Manager during the systems development life cycle activities and new processes to ensure they are properly implemented in conjunction with guidance from the Internal Audit team.

13. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the IT/Security team on remediation plan.

14. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and regulatory requirements.

15. Presents issues of IT non-compliance to the Integrated GRC Senior Manager and VP of ACAS

16. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.

17. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and VP of ACAS

18. Perform other projects assigned by the Integrated GRC Senior Manager and VP of ACAS

SKILLS AND QUALIFICATIONS: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:

1. Bachelor’s degree in business, Finance, Law, Accounting, or related field; MBA, Juris Doctorate, Information Technology or advanced degree preferred

2. Prefer Juris Doctorate degree with compliance certifications such as: Certified Information Privacy Professional (CIPP/US), Certified Regulatory Compliance Manager (CRCM), Certified Compliance & Ethics Professional (CCEP); desirable to possess CIA/CISA/CPA certifications.

3. 5 years of experience in regulatory compliance with legal, compliance and/internal audit role and prefer multi-location restaurant and/or retail businesses background.

4. Big 4 consulting experience

5. Proficiency with Office 365 (O365), particularly: PowerPoint, Outlook, Excel, and Word

6. Proficient with regulatory requirements related to CCPA/CPRA, PCI, ESG, Information Security (Cybersecurity), Information Technology, SOX, ADA, FDA etc.

7. Proficient with Optro (formerly Audit Board)-Cross Comply, Risk Oversight, BigID, Contract Management Systems, NAVEX

8. Strong regulatory compliance background.

9. Excellent leadership and people management skills.

10. Skills in documenting risk, and regulatory compliance activities

11. Familiar with dashboard creation

12. Communicates confidently with executive management, corporate support personnel, cross-functional peers, and product/services providers at appropriate technical levels for each and liaises with different ACAS functional areas, e.g., Security, GRC and Internal Audit to ensure appropriate compliance controls. Demonstrates ability to articulate business cases for identified technology solutions.
13. Demonstrates ability to articulate regulatory compliance and information services activities to the Audit Committee or the Board, at the request of the VP of ACAS, if needed.
14. Excellent analytical and troubleshooting skills.
15. Ability to work under pressure.

{{ backgroundCheckDisclosureText }}