Security Analyst managing security and compliance programs for fintech startup. Ensuring policies and evidence stay organized and collaborate with Head of Security for execution.
Responsibilities
Triage and manage incoming security requests from entire company.
Own and manage the full vendor security assessment lifecycle (new vendors and annual reviews).
Own and build device management and provisioning process.
Troubleshoot and enhance in-office IT, wifi and physical security.
Partner with product/engineering teams to clarify which controls apply to new features, systems, or architectural changes.
Read python code to understand vulnerabilities and help validate fixes and make small bug fixes or configuration updates when appropriate.
Maintain organized, audit-ready repositories of policies, SOC reports, and control documentation.
Assist with security questionnaires from enterprise customers.
Coordinate evidence collection and organize materials for quarterly/annual audits.
Update and refine security policies to reflect current controls and organizational practices.
Track remediation of security findings from vulnerability scans, pentests, and audits.
Requirements
1-4 years of experience in GRC, security compliance, IT audit or security operations.
Familiarity with SOC 2, PCI DSS, ISO 27001, or similar security frameworks.
Ability to read and understand python code to validate security fixes.
Strong organizational and documentation skills.
Ability to own and prioritize multiple tasks open at once.
Experience with vendor assessments, access reviews, evidence collection, or audit support.
Comfort working with technical teams, asking clarifying questions, and escalating when need.
Nice to have: Payments experience.
Nice to have: Knowledge of penetration testing workflows.
Nice to have: ability to read node.
Benefits
100% of Medical, Dental and Vision premium coverage for yourself and dependents.
Enjoy regular team lunches at our San Francisco office, fostering collaboration and connection over great food.
A fun and caring environment that prioritizes transparency, growth, and ownership.
A talented, diverse, high-achieving, and humble team with diverse backgrounds and viewpoints.
Professional N2 in Information Security executing projects and providing technical support at NetSecurity. Collaborating with São Paulo technical team to enhance cybersecurity processes.
Cyber Security Analyst at Equitable Bank responsible for cyber risk governance. Working in a hybrid environment in Toronto focusing on compliance and risk management.
Cybersecurity Analyst role at Sip providing secure development support for financial services. Involvement in offensive security activities and design software solutions.
Experienced Information Security Analyst investigating incidents and mentoring junior analysts in a collaborative environment. Position with a mission - centered organization to support information security operations.
Network Security Analyst leading response efforts during major security incidents while ensuring robust security operations at Comcast. Engaging in investigations and providing strategic recommendations for improvements.
Cyber Security Co - op at RBC analyzing data to detect threats and improve security measures. Collaborating in a dynamic team environment to build solutions for potential cyber threats.
Security Analyst at Digio responsible for Security by Design, identifying and managing risks in projects. Focus on secure architecture, threat modeling, and risk evaluation.
Information Security Analyst developing and managing security awareness training programs for global function. Reducing human - based risks through education and compliance adherence.
Join is seeking a Senior Cybersecurity Analyst for a hybrid quality - focused squad. Responsible for incident response and digital forensics in cybersecurity.