
Junior Information Security – Compliance Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Utah.
• Oversee security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana; triage, document outcomes, and escalate according to established runbooks.
• Conduct regular vulnerability scans on cloud, endpoint, and application surfaces; track remediation and ensure findings are resolved within SLAs.
• Assess employee-reported phishing incidents and security inquiries, escalating confirmed issues as necessary.
• Assist in incident response as the initial responder and note-taker; document timelines, preserve evidence, maintain ticket integrity, and prepare post-incident reports.
• Ensure coverage of security tools including MFA enrollment, endpoint agents, logging agents, and email security.
• Manage user access provisioning, role modifications, and deprovisioning processes for onboarding and offboarding.
• Conduct quarterly reviews of user access and document exceptions and completed evidence.
• Uphold least-privilege and role-based access policies; maintain records of privileged, service, and third-party access.
• Gather and preserve audit evidence for SOC 2 and PCI DSS compliance.
• Assist in SOC 2 and PCI DSS audit processes and communications with auditors.
• Maintain the library of policies and procedures, review schedules, approval documentation, and employee attestations.
• Facilitate vendor risk assessments and manage the vendor inventory.
• Carry out assigned internal control testing and document findings.
• Prepare responses for customer and carrier security questionnaires for review.
• Maintain the asset inventory and oversee the security awareness training program.
• Develop and uphold security and compliance metrics reporting.
• Create and maintain runbooks, standard operating procedures (SOPs), and checklists.
• Collaborate with IT, Engineering, Compliance, Legal, and Service teams.
• Identify repetitive tasks that can be automated or improved and suggest enhancements.
• Perform additional duties as requested, directed, or assigned.
• 0–2 years of relevant professional experience; internships, IT helpdesk or support, systems administration, or audit and compliance support are included.
• Bachelor’s degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or relevant certification in place of a degree.
• Working knowledge of at least one major cloud or productivity platform: AWS, Microsoft 365/Azure, or Google Workspace, including user management, permissions, and logs.
• Capability to independently manage recurring, detail-oriented tasks to completion without reminders.
• Proficient with spreadsheets, ticketing systems such as Jira, and documentation tools.
• Exceptional verbal and written communication abilities.
• Good judgment and discretion when handling sensitive, regulated, and confidential information, including customer PII and NPI.
• Openness to coaching and a genuine curiosity about security.
• Ability to remain composed under pressure during audits, incidents, and tight deadlines.
• Health, dental, and vision insurance plans.
• 4 weeks of Paid Time Off.
• 10 Paid Company Holidays plus 2 floating holidays.
• 401K Programs with employer matching.
• Personal assistance programs to support a healthy work and personal life.
• Opportunity to engage in innovative projects that are transforming the insurance industry.
• Collaborate with a team of dedicated, like-minded professionals.
• Experience a culture that emphasizes growth and development.
Positivo S+
ShorePoint Inc
General Dynamics Information Technology
Gifthealth
Get handpicked remote jobs straight to your inbox weekly.