16 часов назад
Senior Security Analyst, GRC (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Analyst, GRC (Fintech): Supporting enterprise security governance for a regulated financial services organization with an accent on security policies, risk oversight, regulatory compliance, and control effectiveness. Focus on independently assessing second-line controls, managing risk remediation, supporting audits and regulatory exams, and building executive security reporting.
Location: Remote for candidates residing in Arizona, Florida, Georgia, Iowa, Kansas, Michigan, Missouri, Nebraska, South Dakota, Tennessee, Texas, or Wisconsin
Company
Financial Services provides equipment financing to businesses across the United States.
What you will do
- Support and maintain the enterprise information security governance framework, including policies, standards, exceptions, and control documentation.
- Coordinate information security risk assessments, manage the security risk register, and validate remediation of risks and control gaps.
- Independently assess first-line security engineering and IT operations controls, including design, ownership, evidence sufficiency, and operating effectiveness.
- Act as a security governance liaison for regulators and auditors, supporting examinations, audit reviews, findings, and external customer requests.
- Develop dashboards and executive reporting covering risk posture, policy compliance, control effectiveness, and incident trends.
- Maintain alignment with NIST CSF, NIST RMF, CIS, and ITGC frameworks and improve governance processes and tooling.
Requirements
- Bachelor’s degree or equivalent preferred.
- At least 5 years of experience in information security, risk, security governance, or audit.
- Strong knowledge of information security governance, risk management, regulatory compliance, and control frameworks, preferably in banking or regulated financial services.
- Working knowledge of banking regulatory expectations and FFIEC guidance.
- Experience supporting regulatory exams, audit reviews, issue management, remediation tracking, and external customer requests.
- Must be authorized to work for any employer in the United States; visa sponsorship is not available.
Nice to have
- CISA, CRISC, CGRC, CISSP, or CISM certification.
Culture & Benefits
- Full-time employee position with competitive compensation and monthly bonuses for eligible employees.
- 401(k) with company match and annual profit sharing.
- Paid vacation, sick days, holidays, parental leave, and paid life insurance.
- Health, dental, vision, disability, FSA, HSA, and employee assistance benefits.
- Tuition assistance, networking opportunities, and leadership development.
- Hybrid work arrangements, gym reimbursement, and paid parking.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Director, GRC (Cybersecurity)
5 часов назад
IT Risk & Compliance Analyst (Cybersecurity)
84 000 - 94 000$
1 день назад
Senior GRC Manager (Cybersecurity)
6 дней назад
Sr Manager, InfoSec Governance Risk and Compliance (GRC)
112 000 - 208 000$
4 дня назад
Cybersecurity Analyst
6 дней назад
Senior Analyst, IT Risk & GRC (Cybersecurity)
90 500 - 143 000$