Назад
Company hidden
9 дней назад

Information Security Assurance Analyst I (Fintech)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Assurance Analyst I (Fintech): Performing security control assessments, assurance reviews, compliance validation, and remediation tracking across information security and technology environments with an accent on control effectiveness, risk analysis, and automation. Focus on designing repeatable evidence-collection workflows, building dashboards and reports with Power Automate and Power BI, and supporting continuous monitoring and certification activities.

Location: Alpharetta, Georgia, United States

Company

hirify.global provides payment technology and software solutions for credit, debit, prepaid, and merchant services.

What you will do

  • Collaborate with Information Security, Technology, Risk, Audit, and business stakeholders on First Line Assurance activities.
  • Perform targeted control assessments, operational assurance reviews, post-deployment security validations, and certification activities.
  • Evaluate control implementation and effectiveness, identify vulnerabilities and compliance gaps, and provide remediation recommendations.
  • Automate control audits, evidence collection, control testing, reporting, remediation tracking, certification, and continuous monitoring.
  • Develop repeatable workflows, dashboards, metrics, and assessment reports using automation and reporting tools.
  • Review control exceptions and business requests, assess risk, and communicate policy variances and remediation paths to management.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related information technology field, or equivalent relevant experience.
  • At least 7 years of relevant experience in information security, security assurance, audit, risk, compliance, security architecture, security engineering, or related technology functions.
  • Knowledge of security and compliance frameworks including PCI, FFIEC, FISMA, SOX, GLBA, HIPAA, ISO 27001, NIST 800-53, NIST CSF, or NIST RMF.
  • Ability to collect and evaluate evidence, document findings, identify risk, and communicate practical remediation options to stakeholders at multiple levels.
  • Must be authorized to work in the United States without employment-based visa sponsorship now or in the future.

Nice to have

  • Certifications such as CRISC, CGRC, CISM, CISSP, CISA, or CySA+.
  • Experience with on-premises, cloud, and hybrid environments, including GCP, AWS, or Azure.
  • Experience with automated security control validation, continuous monitoring, evidence collection, remediation tracking, Power Automate, Power BI, ServiceNow, Optro, Archer, or similar GRC tools.
  • Experience developing dashboards, metrics, assessment reports, and recurring assurance reporting from multiple data sources.

Culture & Benefits

  • Inclusive and global working environment focused on collaboration and professional growth.
  • Culture centered on client focus, ownership, teamwork, curiosity, innovation, and empowered decision-making.
  • Opportunities to work with Information Security, Technology, Risk, Audit, and business stakeholders on complex initiatives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →