Назад
Company hidden
2 дня назад

Senior GRC Analyst (FinTech)

114 000 - 163 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Analyst (FinTech): Owning PCI DSS Level 1, SOC 2 Type II, IT general controls, NIST CSF 2.0, and third-party risk programs with an accent on audit readiness, evidence management, and governance maturity. Focus on coordinating QSA and auditor examinations, testing control effectiveness, administering GRC workflows, and establishing governance for AI adoption.

Location: 5-day onsite role in Pittsburgh, Pennsylvania, United States

Salary: $114,000–$163,000 per year

Company

hirify.global is a Pittsburgh-based FinTech and e-commerce company operating consumer gifting, payments, and personalized gift-card brands, with AI being integrated across its products and internal operations.

What you will do

  • Own PCI DSS v4.0.1 Level 1 service provider assessments and SOC 2 Type II examinations from scope validation through evidence collection, auditor coordination, and remediation tracking.
  • Maintain IT general control readiness across change management, logical access, SDLC, backup, and job scheduling.
  • Manage issues from intake and risk rating through remediation, closure evidence, and reporting to leadership and the Audit Committee.
  • Conduct third-party risk assessments, including vendor security questionnaire reviews, contract security and PCI terms, and ongoing monitoring.
  • Administer the GRC platform, including control libraries, cross-framework mappings, automated evidence collection, workflows, and dashboards.
  • Support governance controls and review processes for AI adoption across the company.

Requirements

  • 7+ years of experience in GRC, IT audit, or information security compliance, including at least 3 years supporting PCI DSS in a Level 1 service provider or equivalent payment-card environment.
  • Experience preparing for and supporting SOC 2 Type II examinations and designing, documenting, and testing IT general controls.
  • Strong knowledge of IT governance and the ability to translate control requirements into audit-ready evidence.
  • Hands-on experience administering a GRC platform such as Vanta, Drata, Secureframe, ServiceNow IRM, AuditBoard, or a similar system.
  • Experience running third-party risk assessments and reviewing security and compliance terms in vendor contracts.
  • Experience in regulated financial services and producing deliverables for external parties, executives, and boards.

Nice to have

  • CISA, CRISC, CISSP, PCIP, or ISA certification.

Culture & Benefits

  • Medical, prescription, vision, and dental insurance for employees and dependents, with hirify.global paying 80% of premiums.
  • Short-term disability insurance fully paid by hirify.global, plus optional long-term disability, life, critical illness, accident, and hospital indemnity coverage.
  • Paid vacation and sick time, corporate and floating holidays, and a 401(k) plan.
  • Restricted stock units, profit share, tuition reimbursement, internal training, and information sessions.
  • Employee recognition, referral bonuses, charitable donations, and company outings.

Hiring process

  • Resume review, team interview, culture interview, and final interview.
  • Offer, start, and background check.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →