Senior Security Analyst

Posted 19hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Analyst strengthening GRC, compliance, and cloud security. Protecting mortgage-finance systems and data at AI-native operating system company Valon.

Responsibilities:

  • Implement and maintain compliance with SOC 2, NIST CSF, CIS, NYDFS, GLBA Safeguards, CCPA, and related regulatory requirements
  • Support internal and external security audits and exams, including evidence gathering and remediation tracking
  • Build AI-assisted GRC workflows to scale GRC and security functions
  • Maintain and manage the security risk register, risk assessments, and remediation processes
  • Manage security governance and compliance projects and assist with other project management efforts
  • Manage security metrics, KPIs, and reporting
  • Support customer security due diligence processes
  • Review, manage, and monitor security policies for compliance
  • Facilitate remediation of security and compliance issues across stakeholders
  • Manage vendor security risk assessments
  • Support on-call and operational security activities, including security monitoring, incident management, general security reviews, security awareness and training, and other tasks
  • Collaborate with the Head of Security GRC, Security team, Product, Engineering, and cross-functional stakeholders to protect systems, cloud infrastructure, products, and data

Requirements:

  • Minimum of 5+ years as a security analyst or security program manager with relevant responsibilities and background
  • Bachelor's degree in Computer Science, Information Security, Technology, or a related field
  • Relevant security certifications based on career experience (CompTIA Security+, CC, SSCP or related), or seasoned career level (CISSP, CISM, CRISC or related)
  • Experience with security compliance frameworks and risk assessments
  • Experience with operational activities including issue management, security reviews, control monitoring, incident management, and reporting
  • Hands-on experience with AI tooling and assisted workflows
  • Experience with security and compliance frameworks and requirements, including OWASP, SOC 2, NIST CSF / 800-53, ISO 27001/2, CIS, NYDFS, and CCPA
  • Basic knowledge of cloud security and public cloud environments
  • Experience developing, automating, and scaling security and GRC processes leveraging AI tools / agentic capabilities
  • Experience maintaining a security risk register and issue management processes
  • Strong organization and project management skills
  • Excellent communication and collaboration skills, with ability to explain security concepts to technical and non-technical stakeholders
  • Ability to work autonomously, be agile, and balance multiple projects and operational efforts

Benefits:

  • Competitive salary with a meaningful stake in the company via equity
  • 401k plan
  • Comprehensive medical, dental, & vision benefits
  • Pre-tax commuter benefits for public transportation, rideshare services, and parking expenses
  • Company-wide orientation and learning & development opportunities
  • Regular review cycles featuring 360 degree feedback
  • Quarterly budgets for team and company outings
  • Flexible paid time off
  • Sick days
  • 11 company holidays
  • 12 weeks fully paid baby bonding time for birthing and non-birthing parents