
IT Security Compliance Analyst
Posted Jun 5

Posted Jun 5
This is a fully remote position, open to applicants in United States.
• The IT Security Compliance Analyst supports IT Compliance Programs by researching risks, identifying issues, developing solutions, and generating related reports, training, and other responsibilities.
• The incumbent will oversee and gather information regarding ongoing activities within Velera, including the creation and development of information security metrics for senior leadership.
• The individual will report on key departmental and corporate compliance priorities and will be responsible for executing processes to meet these stated priorities.
• This role also involves collaborating with functional ITS and business leaders to promote IT compliance practices and their adoption.
• Conduct audits of user and system security configurations to ensure compliance with both internal and external requirements.
• Perform audits and follow up on corrective actions; participate in internal audit activities conducted for compliance verification.
• Interact and coordinate with relevant business unit resources for audit participation.
• Provide management with insights regarding the negative business impact of breaches in confidentiality, integrity, or availability of information and information systems.
• Comprehend the application of security concepts across a wide range of information technology areas, including data communications, network design, operations, database structures, operating systems, application development, security risk assessments, and disaster recovery.
• Offer continuous guidance and support to foster a progressive and sustainable compliance culture within the organization.
• Prepare and present updates for monthly internal and external compliance reports.
• Document and maintain risk-based compliance policies and procedures; develop various materials for use on ITS's compliance intranet site.
• Coordinate the creation of training materials and the monitoring of records, as well as the distribution of regulatory information to the appropriate personnel.
• Implement and manage operational plans for key control activities to ensure compliance with regulatory, legal, and corporate or functional policies and procedures.
• Respond to internal and external inquiries and requests for information to clarify regulatory requirements.
• Assist in developing processes to identify, quantify, analyze, and report on Velera Technology Risk and Compliance status.
• Act as a liaison between business units with compliance responsibilities to gather, report, and retain compliance documentation and reports.
• Identify ongoing process improvements, operational gaps, and potential remediation steps; assist and/or lead process redesign and coordination of remediation efforts and reporting on their status.
• Stay informed of legislative and regulatory changes related to the financial industry; possess an understanding of applicable finance industry security and privacy regulations, procedures, and issues, and assist in leading internal efforts to ensure organizational compliance with such laws and regulations.
• Lead and/or participate in special project teams that support general business initiatives outside of the primary security function.
• Perform other duties as assigned.
• A Bachelor’s degree in computer science or a related discipline, or an equivalent combination of education and experience is required.
• A risk management, governance, or security certification (CRISC, CGEIT, CISSP, CISM, CISA) is required.
• Project Management certification (PMP) is preferred.
• A minimum of five (5) years of relevant work experience is required, including at least three (3) years in Internal IT Systems Auditing and three (3) years in internal control projects within the financial industry.
• Working knowledge of SSAE 16 and PCI requirements is necessary.
• Familiarity with the ISO27000 series of standards, PCI, COBIT, ITIL, and Sarbanes Oxley regulations related to IT is essential.
• Working knowledge of NACHA is required.
• Understanding of OFAC, BSA, GLBA, the Patriot Act, and other Federal or State laws impacting National Security requirements or privacy is important.
• Competitive wages
• Medical with telemedicine
• Dental and Vision
• Basic and Optional Life Insurance
• Paid Time Off (PTO)
• Maternity, Parental, Family Care
• Community Volunteer Time Off
• 12 Paid Holidays
• Company Paid Disability Insurance
• 401k (with employer match)
• Health Savings Accounts (HSA) with company provided contributions
• Flexible Spending Accounts (FSA)
• Supplemental Insurance
• Mental Health and Well-being: Employee Assistance Program (EAP)
• Tuition Reimbursement
• Wellness program
Julesetmoi
National University
MeridianLink
Woolpert
Get handpicked remote jobs straight to your inbox weekly.