Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC Senior Regulatory Compliance
Analyst, who has proficient knowledge in regulatory compliance rules
and regulations will be responsible for assisting the Integrated GRC Senior Manager (Juris
Doctorate) for ensuring Kura meets all applicable legal, regulatory,
and internal regulatory compliance requirements and facilitating centralized
monitoring. This includes but not limited to:
In addition, the GRC Regulatory
Compliance Senior Analyst will partner with/provide guidance to the GRC Senior
Security Analyst and the Head of Information Technology, when applicable, in
designing/implementing information services (IT and security) solution
components used throughout Kura Sushi’s environment as well as liaising with
the Internal Audit team for in-scope SOX systems.
The GRC Regulatory Compliance Senior
Analyst will be responsible for assisting the Integrated GRC Senior Manager in facilitating
Kura’s vendor relationships with several outsourced service providers as needed in establishing a scalable and compliant environment to support the Company’s
compliance landscape to include security and technological components.
The GRC-Regulatory
Compliance Senior Analyst require proficient knowledge and understanding of compliance
standards and frameworks to include end-to-end
business process, security frameworks (including domains such as access
management and data protection), regulatory compliance (e.g., SOX, PCI, CPRA, etc.)
and technology standards, procedures, guidelines and; and be able to prepare
and communicate compliance issues to the Integrated GRC Senior Manager, VP of ACAS
and others as directed by the VP of ACAS.
Key Responsibilities
Regulatory Compliance:
1. Ensures the organization complies with all applicable laws, regulations, and internal policies. This includes monitoring business operations and reporting any infractions.
2. Partners with General Counsel and other management members, as needed
3. Policy Development: Create, modify, and implement company policies and procedures to align with legal requirements and ethical standards.
4. Risk Management: Develop risk management strategies and conduct regular audits to identify areas of potential non-compliance.
5. Manage the operational processes for Data Subject Requests (DRS) such as rights to access or delete personal data.
6. Maintain up-to-date Records of Processing Activities (RoPA) across departments.
7. Advise operational personnel on appropriate responses to recurring confidentiality and data disclosure inquiries.
8. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and audits.
9. Incident Management: Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence
10. Reporting: Provide regular reports to the Integrated GRC Senior Manager, VP of ACAS and other senior management on the status of the compliance program and any issues that arise.
11. Conducts annual regulatory compliance risk assessments
12. Reviews and main contracts containing PII and system/AI components to ensure DPAs are issued to 3rd party vendors.
13. Performs compliance assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting investigations,
Governance, Risk and Compliance (GRC Activities)
1. Provides guidance to the Information Services (Security and Technology) management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.
2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.
3. Perform Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) for new system implementations.
4. Liaise with Internal Audit members to ensure appropriate controls over business and IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness.
5. Evaluate third party vendor contracts, performing privacy and security due diligence on business associates and service providers.
6. Develops reporting metrics, dashboards, and obtains and retains evidence and provides to the Integrated GRC Senior Manager, VP of ACAS or other leadership, as needed for review.
7. Provides guidance to the Security Senior Analyst for building the organization’s cybersecurity strategy to ensure Kura Security team is proactively identifying/addressing relevant security gaps, compliant with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.
8. Collaborates with cross-functional business, security and the information technology team to ensure security strategies and initiatives align with business objectives and regulatory compliance requirements.
9. Provides guidance to the Security Manager in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations.
10. Collaborates with the Integrated
GRC Senior Analyst, GRC-Senior Security Analysts, Internal Audit and other key
members who will at a minimum, facilitate and monitor compliance enterprise
wide.
11. Facilitation and the coordination, development and
implementation of security awareness compliance programs and education
while partnering with the Security Manager.
12. Facilitates, guides coordinates, and partners with the Security Manager during the systems development life cycle activities and new processes to ensure they are properly implemented in conjunction with guidance from the Internal Audit team.
13. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the IT/Security team on remediation plan.
14. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and regulatory requirements.
15. Presents issues of IT non-compliance to the Integrated GRC Senior Manager and VP of ACAS
16. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.
17. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and VP of ACAS
18. Perform other projects
assigned by the Integrated GRC Senior Manager and VP of ACAS
SKILLS AND
QUALIFICATIONS: To perform this job successfully, an individual
must be able to perform each essential duty satisfactorily.
The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable
accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:
1. Bachelor’s degree in business, Finance, Law, Accounting, or related field; MBA, Juris Doctorate, Information Technology or advanced degree preferred
2. Prefer Juris Doctorate degree with compliance certifications such as: Certified Information Privacy Professional (CIPP/US), Certified Regulatory Compliance Manager (CRCM), Certified Compliance & Ethics Professional (CCEP); desirable to possess CIA/CISA/CPA certifications.
3. 5 years of experience in regulatory compliance with legal, compliance and/internal audit role and prefer multi-location restaurant and/or retail businesses background.
4. Big 4 consulting experience
5. Proficiency with Office 365 (O365), particularly: PowerPoint, Outlook, Excel, and Word
6. Proficient with regulatory requirements related to CCPA/CPRA, PCI, ESG, Information Security (Cybersecurity), Information Technology, SOX, ADA, FDA etc.
7. Proficient with Optro (formerly Audit Board)-Cross Comply, Risk Oversight, BigID, Contract Management Systems, NAVEX
8. Strong regulatory compliance background.
9. Excellent leadership and people management skills.
10. Skills in documenting risk, and regulatory compliance activities
11. Familiar with dashboard creation
12. Communicates
confidently with executive management, corporate support personnel,
cross-functional peers, and product/services providers at appropriate technical
levels for each and liaises with different ACAS functional areas, e.g.,
Security, GRC and Internal Audit to ensure appropriate compliance controls. Demonstrates
ability to articulate business cases for identified technology solutions.
13. Demonstrates ability to
articulate regulatory compliance and information services activities to the
Audit Committee or the Board, at the request of the VP of ACAS, if needed.
14. Excellent analytical
and troubleshooting skills.
15. Ability to work under
pressure.
Kura Sushi USA is a publicly traded U.S. company established in 2008 as a subsidiary of Kura Sushi, Inc. We are an innovative and tech interactive Japanese restaurant chain serving up the ultimate eater-tainment dining experience with a combination of premium ingredients, advanced technology, and affordable prices to create a one-of-a-kind revolving sushi dining experience.
Come join the Kura Krew! This role is a hybrid role. The selected candidate must be able to come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC Senior Regulatory Compliance
Analyst, who has proficient knowledge in regulatory compliance rules
and regulations will be responsible for assisting the Integrated GRC Senior Manager (Juris
Doctorate) for ensuring Kura meets all applicable legal, regulatory,
and internal regulatory compliance requirements and facilitating centralized
monitoring. This includes but not limited to:
In addition, the GRC Regulatory
Compliance Senior Analyst will partner with/provide guidance to the GRC Senior
Security Analyst and the Head of Information Technology, when applicable, in
designing/implementing information services (IT and security) solution
components used throughout Kura Sushi’s environment as well as liaising with
the Internal Audit team for in-scope SOX systems.
The GRC Regulatory Compliance Senior
Analyst will be responsible for assisting the Integrated GRC Senior Manager in facilitating
Kura’s vendor relationships with several outsourced service providers as needed in establishing a scalable and compliant environment to support the Company’s
compliance landscape to include security and technological components.
The GRC-Regulatory
Compliance Senior Analyst require proficient knowledge and understanding of compliance
standards and frameworks to include end-to-end
business process, security frameworks (including domains such as access
management and data protection), regulatory compliance (e.g., SOX, PCI, CPRA, etc.)
and technology standards, procedures, guidelines and; and be able to prepare
and communicate compliance issues to the Integrated GRC Senior Manager, VP of ACAS
and others as directed by the VP of ACAS.
Key Responsibilities
Regulatory Compliance:
1. Ensures the organization complies with all applicable laws, regulations, and internal policies. This includes monitoring business operations and reporting any infractions.
2. Partners with General Counsel and other management members, as needed
3. Policy Development: Create, modify, and implement company policies and procedures to align with legal requirements and ethical standards.
4. Risk Management: Develop risk management strategies and conduct regular audits to identify areas of potential non-compliance.
5. Manage the operational processes for Data Subject Requests (DRS) such as rights to access or delete personal data.
6. Maintain up-to-date Records of Processing Activities (RoPA) across departments.
7. Advise operational personnel on appropriate responses to recurring confidentiality and data disclosure inquiries.
8. Liaison with Regulatory Bodies: Act as the point of contact between the organization and regulatory agencies, handling inspections and audits.
9. Incident Management: Investigate compliance breaches, conduct root cause analysis, and implement corrective actions to prevent recurrence
10. Reporting: Provide regular reports to the Integrated GRC Senior Manager, VP of ACAS and other senior management on the status of the compliance program and any issues that arise.
11. Conducts annual regulatory compliance risk assessments
12. Reviews and main contracts containing PII and system/AI components to ensure DPAs are issued to 3rd party vendors.
13. Performs compliance assessments/reviews, monitors compliance deficiencies/remediation efforts, conducting investigations,
Governance, Risk and Compliance (GRC Activities)
1. Provides guidance to the Information Services (Security and Technology) management in building a strong IT/Security compliant environment including guiding and mentoring direct and indirect team members.
2. Providing guidance and facilitating coordination with cross-functional members in implementing processes such as Security and IT governance, risk, and compliance activities to automate and facilitate continuous monitoring of information security controls, exceptions, risks, and testing.
3. Perform Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) for new system implementations.
4. Liaise with Internal Audit members to ensure appropriate controls over business and IT/Security design while working with the IT management and cross-functional members to facilitate operational efficiencies and effectiveness.
5. Evaluate third party vendor contracts, performing privacy and security due diligence on business associates and service providers.
6. Develops reporting metrics, dashboards, and obtains and retains evidence and provides to the Integrated GRC Senior Manager, VP of ACAS or other leadership, as needed for review.
7. Provides guidance to the Security Senior Analyst for building the organization’s cybersecurity strategy to ensure Kura Security team is proactively identifying/addressing relevant security gaps, compliant with internal policies and external regulatory requirements, and improving Kura’s overall security posture and program.
8. Collaborates with cross-functional business, security and the information technology team to ensure security strategies and initiatives align with business objectives and regulatory compliance requirements.
9. Provides guidance to the Security Manager in developing the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations.
10. Collaborates with the Integrated
GRC Senior Analyst, GRC-Senior Security Analysts, Internal Audit and other key
members who will at a minimum, facilitate and monitor compliance enterprise
wide.
11. Facilitation and the coordination, development and
implementation of security awareness compliance programs and education
while partnering with the Security Manager.
12. Facilitates, guides coordinates, and partners with the Security Manager during the systems development life cycle activities and new processes to ensure they are properly implemented in conjunction with guidance from the Internal Audit team.
13. Evaluates IT control/process deficiencies issued by the Internal Audit team and provides remediation plans to the Internal Audit Team for recommended design improvements while partnering with the IT/Security team on remediation plan.
14. Facilitates and provides guidance to the IT HOD in the development of IT policies and procedures and ensures alignment with company goals and regulatory requirements.
15. Presents issues of IT non-compliance to the Integrated GRC Senior Manager and VP of ACAS
16. Attends continuing professional education to keep abreast of security and technology regulations, emerging risks and strategies.
17. Presents progress and initiatives on a monthly basis based on annual plan to the Integrated GRC Senior Manager and VP of ACAS
18. Perform other projects
assigned by the Integrated GRC Senior Manager and VP of ACAS
SKILLS AND
QUALIFICATIONS: To perform this job successfully, an individual
must be able to perform each essential duty satisfactorily.
The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable
accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education/Experience:
1. Bachelor’s degree in business, Finance, Law, Accounting, or related field; MBA, Juris Doctorate, Information Technology or advanced degree preferred
2. Prefer Juris Doctorate degree with compliance certifications such as: Certified Information Privacy Professional (CIPP/US), Certified Regulatory Compliance Manager (CRCM), Certified Compliance & Ethics Professional (CCEP); desirable to possess CIA/CISA/CPA certifications.
3. 5 years of experience in regulatory compliance with legal, compliance and/internal audit role and prefer multi-location restaurant and/or retail businesses background.
4. Big 4 consulting experience
5. Proficiency with Office 365 (O365), particularly: PowerPoint, Outlook, Excel, and Word
6. Proficient with regulatory requirements related to CCPA/CPRA, PCI, ESG, Information Security (Cybersecurity), Information Technology, SOX, ADA, FDA etc.
7. Proficient with Optro (formerly Audit Board)-Cross Comply, Risk Oversight, BigID, Contract Management Systems, NAVEX
8. Strong regulatory compliance background.
9. Excellent leadership and people management skills.
10. Skills in documenting risk, and regulatory compliance activities
11. Familiar with dashboard creation
12. Communicates
confidently with executive management, corporate support personnel,
cross-functional peers, and product/services providers at appropriate technical
levels for each and liaises with different ACAS functional areas, e.g.,
Security, GRC and Internal Audit to ensure appropriate compliance controls. Demonstrates
ability to articulate business cases for identified technology solutions.
13. Demonstrates ability to
articulate regulatory compliance and information services activities to the
Audit Committee or the Board, at the request of the VP of ACAS, if needed.
14. Excellent analytical
and troubleshooting skills.
15. Ability to work under
pressure.