Назад
Company hidden
16 часов назад

Senior Security Analyst, GRC (Fintech)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Analyst, GRC (Fintech): Supporting enterprise security governance for a regulated financial services organization with an accent on security policies, risk oversight, regulatory compliance, and control effectiveness. Focus on independently assessing second-line controls, managing risk remediation, supporting audits and regulatory exams, and building executive security reporting.

Location: Remote for candidates residing in Arizona, Florida, Georgia, Iowa, Kansas, Michigan, Missouri, Nebraska, South Dakota, Tennessee, Texas, or Wisconsin

Company

hirify.global Financial Services provides equipment financing to businesses across the United States.

What you will do

  • Support and maintain the enterprise information security governance framework, including policies, standards, exceptions, and control documentation.
  • Coordinate information security risk assessments, manage the security risk register, and validate remediation of risks and control gaps.
  • Independently assess first-line security engineering and IT operations controls, including design, ownership, evidence sufficiency, and operating effectiveness.
  • Act as a security governance liaison for regulators and auditors, supporting examinations, audit reviews, findings, and external customer requests.
  • Develop dashboards and executive reporting covering risk posture, policy compliance, control effectiveness, and incident trends.
  • Maintain alignment with NIST CSF, NIST RMF, CIS, and ITGC frameworks and improve governance processes and tooling.

Requirements

  • Bachelor’s degree or equivalent preferred.
  • At least 5 years of experience in information security, risk, security governance, or audit.
  • Strong knowledge of information security governance, risk management, regulatory compliance, and control frameworks, preferably in banking or regulated financial services.
  • Working knowledge of banking regulatory expectations and FFIEC guidance.
  • Experience supporting regulatory exams, audit reviews, issue management, remediation tracking, and external customer requests.
  • Must be authorized to work for any employer in the United States; visa sponsorship is not available.

Nice to have

  • CISA, CRISC, CGRC, CISSP, or CISM certification.

Culture & Benefits

  • Full-time employee position with competitive compensation and monthly bonuses for eligible employees.
  • 401(k) with company match and annual profit sharing.
  • Paid vacation, sick days, holidays, parental leave, and paid life insurance.
  • Health, dental, vision, disability, FSA, HSA, and employee assistance benefits.
  • Tuition assistance, networking opportunities, and leadership development.
  • Hybrid work arrangements, gym reimbursement, and paid parking.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →