Lead Security Governance, Risk & Compliance Analyst (Payments)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Hybrid in Scottsdale, Phoenix, Chicago, New York, or San Francisco; candidates must independently possess eligibility to work in the United States. Visa sponsorship is not available.
Salary: $116,000–$145,000 per year in Phoenix or Chicago; $139,000–$174,000 per year in New York or San Francisco, plus discretionary incentive eligibility and benefits.
Company
provides payment and financial technology solutions, including Zelle and Paze, for financial institutions, consumers, and small businesses.
What you will do
- Establish repeatable processes for security audits, assessments, evidence collection, customer requests, regulatory activities, and control reviews.
- Manage compliance intake, ownership, evidence, escalation, remediation tracking, and closure practices.
- Identify workflow automation and process improvements across GRC, reporting, collaboration, and evidence-management activities.
- Develop evidence packages, control narratives, evidence maps, templates, playbooks, checklists, and operating guidance.
- Analyze compliance and audit data, identify recurring issues and root causes, and coordinate sustainable remediation.
- Prepare metrics, reporting, and narratives for Security leadership, governance forums, auditors, regulators, customers, and other stakeholders.
Requirements
- Bachelor's degree or equivalent practical experience.
- Approximately 7 years of experience in security governance, risk and compliance, information security, technology risk, IT audit, control testing, regulatory readiness, or a comparable discipline.
- Understanding of control environments, evidence requirements, audit and assessment processes, issue management, and remediation tracking.
- Experience translating security or compliance requirements into practical processes, procedures, or guidance.
- Program, project, or workstream management experience with cross-functional stakeholders and competing priorities.
- Experience with GRC, workflow, reporting, collaboration, or comparable enterprise systems, together with strong analytical and communication skills.
Nice to have
- Experience in financial services, payments, banking, or another regulated environment.
- Familiarity with NIST, CRI, ISO 27001/27002, SOC 2, PCI DSS, FFIEC, or comparable frameworks.
- Experience with customer audits, regulatory examinations, internal audits, external assessments, or security attestations.
- Experience with Jira, ServiceNow, Confluence, SharePoint, Excel, or GRC platforms.
- CISA, CRISC, CISSP, CISM, PMP, or equivalent demonstrated experience.
Culture & Benefits
- Hybrid work model supporting collaboration in designated locations.
- Medical, dental, and vision coverage, with HSA and FSA options.
- 401(k) plan with a 100% company safe-harbor match on the first 6% of deferrals.
- Flexible time off or generous PTO, 11 paid company holidays, and a paid volunteer day.
- 12 weeks of paid parental leave and family-planning support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →