Remotery

Senior Security Analyst, GRC

Posted Aug 11

This is a fully remote position, open to applicants in United States.

📋 Description

• Assist in the creation and upkeep of the bank’s information security governance framework.

• Monitor the lifecycle of security policies and standards, reporting non-compliance to policy owners.

• Ensure compliance with FFIEC and banking regulator guidelines.

• Maintain governance artifacts, procedures for policy exceptions, and control documentation.

• Conduct independent reviews of first-line procedures to ensure alignment with approved policies and standards.

• Oversee information security risk assessments and manage the security risk register.

• Track and independently validate the remediation of identified risks and control deficiencies.

• Evaluate first-line controls and formally question control design, ownership, and evidence adequacy.

• Act as the primary liaison for security governance with regulators and auditors.

• Assist with regulatory examinations, audit reviews, and responses to findings and customer requests.

• Create security governance reports and executive dashboards that detail risk posture, policy compliance, control effectiveness, and incident trends.

• Aid in quarterly updates for risk committees and senior management.

• Ensure alignment with NIST CSF, NIST RMF, CIS, and ITGC frameworks.

• Propose and facilitate enhancements to governance processes and Optro/Auditboard tools.

• Collaborate with legal, compliance, risk, technology, security, audit, and business functions.


⛳️ Requirements

• Bachelor’s degree or equivalent preferred.

• At least 5 years of experience in information security, risk management, security governance, or audit.

• In-depth knowledge of information security governance, risk management, regulatory compliance, and control frameworks, ideally within banking or regulated financial services.

• Familiarity with banking regulatory expectations, FFIEC guidance, NIST CSF, NIST RMF, CIS, and ITGC.

• Experience in supporting regulatory examinations, audit reviews, external customer inquiries, findings, issue management, and tracking remediation efforts.

• Capability to maintain security policies, standards, governance artifacts, risk registers, control documentation, and processes for policy exceptions.

• Ability to independently evaluate control design, ownership, evidence adequacy, remediation status, and operational effectiveness within a second-line risk oversight framework.

• Strong analytical and reporting capabilities, including the development of dashboards and communication regarding risk posture, policy compliance, control effectiveness, and incident trends.

• Proficient in collaborating across security, technology, risk, compliance, audit, legal, and business teams while maintaining independence and the ability to challenge.

• Excellent written and verbal communication skills.

• Strong organizational, project coordination, follow-through, and judgment abilities.

• ISACA CISA certification preferred.

• ISACA CRISC certification preferred.

• ISC2 CGRC certification preferred.

• ISC2 CISSP certification preferred.

• ISACA CISM certification preferred.

• Must be authorized to work for any employer in the U.S.; employment visa sponsorship is not available.


🏝️ Benefits

• Competitive Compensation.

• Monthly Bonuses for Eligible Employees.

• 401(k) with Company Match.

• Annual Profit Sharing.

• Paid Vacation - starting at 80 hours annually for employees in their first year of service.

• Paid Sick Days - Ten (10) per year with an option to convert unused time.

• Ten (10) Paid Holidays each year.

• Gym Reimbursement.

• Health Insurance.

• Dental Insurance.

• Vision Insurance.

• Short-Term and Long-Term Disability.

• Company-Paid Life Insurance.

• Flexible Spending Accounts (FSA).

• Health Savings Accounts (HSA).

• Employee Assistance Program.

• Parental Leave.

• Tuition Assistance.

• Networking Opportunities.

• Leadership Development Opportunities.

• Paid Parking.

• Service Awards.

• Hybrid work arrangements.

• Business casual environment.

People also viewed

The Home Depot9 hours ago

Cybersecurity Analyst – PCI

US flagTexas OnlyFull-timeSecurity Analyst$80k – $120k/year
ApplyView job
Lennar13 hours ago

Senior Workday Analyst – Security Administration, Job Architecture

US flagFlorida OnlyFull-timeSecurity Analyst
ApplyView job
Golden 1 Credit Union1 day ago

Senior Information Security Analyst

US flagCalifornia OnlyFull-timeSecurity Analyst$112.2k – $120k/year
ApplyView job
NuHarbor Security1 day ago

Security Analyst

US flagHawaii OnlyFull-timeSecurity Analyst$90k – $120k/year
ApplyView job
Lennar1 day ago

Workday Analyst – Security Administration, Job Architecture

US flagFlorida OnlyFull-timeSecurity Analyst
ApplyView job
Kocho1 day ago

Security Analyst – Tier 2

ZA flagSouth Africa OnlyFull-timeSecurity Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers