Senior Information Security GRC Analyst
$155k - $165kBranch
Senior Information Security GRC Analyst
Remote, US
Branch is on a mission to empower workers with financial freedom. We do this by helping companies accelerate payments and providing working Americans with accessible, free financial services. We're committed to building and delivering more inclusive, transparent, and frictionless financial products.
Our goal of empowerment extends to our own employees, too. Have a great idea? Share it today and it might just get implemented tomorrow. As a member of our team, your voice and creativity matter—and they can directly impact our products, company, and culture.
We not only focus on attracting great talent from across the country, but also on building teams that help that talent thrive. That means valuing a diversity of opinions and working styles, while creating a shared belief in innovation, initiative, and winning together.
Come join our team as we develop new ways to improve the lives of working Americans.
About the Role
Branch is seeking an experienced Security Governance, Risk, and Compliance (GRC) professional to join our team. This position will work in all aspects of GRC, so broad knowledge is preferred across multiple frameworks and related policy and procedure lifecycle management. The ideal candidate will have a background in managing relationships with internal stakeholders (C Suite, Risk, and Legal), external partners (3rd party vendors, auditors, sub-processors), and working closely with members of the Security team.
Responsibilities include, but are not limited to:
- Manage and maintain the Branch Information Security Program, security function programs and processes. Own internal Branch controls. Maintain an accurate security program and all the associated processes across all corporate functions.
- Ambassador and champion of the Branch Information Security Program and security awareness.
- Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA).
- Conduct comprehensive gap analysis to identify deficiencies and areas for improvement in existing controls.
- Experience implementing new frameworks and integrating into existing audit cycles.
- Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with the frameworks (SOC 2, ISO 27001, PCI, NIST, CCPA) implemented by Branch.
- Manage Branch's Drata GRC platform:
- Ensure information is up to date and automated collections are working appropriately.
- Ensure that Audit evidence is collected and validated.
- Manage access to and keep information up to date for Branch's Security Trust Center.
- Manage and maintain frameworks, policies, control content and control mapping.
- Inform the proper stakeholders of important concerns, hazards, and risk to the organization.
- Collaborate with stakeholders (Security, Engineering, Cloud Operations, Procurement, and Legal) to ensure security practices are integrated into daily operations, and are aligned with our GRC objectives.
- Maintain up-to-date knowledge of procedures and methods that serve to broaden team knowledge and industry expertise.
- Write and manage security standards, policies, and practices on an ongoing basis to make sure they meet corporate demands.
- Assist the department in responding to inquiries from the business units about ongoing operational compliance.
- Be proactive in seeking out areas for improvement and offer insightful advice and value-added guidance and/or automation for process and control enhancements.
- Manage the end-to-end third-party vendor management lifecycle, including onboarding, due diligence, and ongoing monitoring of vendor risk, performance, and operational changes through established governance processes.
- Partner with the Risk and Legal teams to share information and seek out areas for improvement, streamline processes and to reduce risk throughout the company.
- Manage the security training and awareness program, responsible for promoting and enhancing our organization's security culture through effective awareness programs and initiatives.
- Support the planning of penetration tests and the coordination of remediation efforts.
Qualifications
- 5-7 years of experience in a similar role
- 3+ years of expertise conducting audits (SOC 2, PCI or ISO 27001), as well as handling audit responses
- Excellent communication skills
- Oral and written communication to an audience of employees as well as to the leadership team is necessary
- Create and maintain clear, concise, and accurate documentation that supports our GRC initiatives
- Knowledge of GRC tool techniques and best practices (Drata, HyperProof, AuditBoard, OneTrust)
- Solid ethics and core values - Situations sometimes require discretion and may be of a confidential or sensitive nature
- Excellent organizational, process improvement, and project management skills
- Familiarity with security and compliance requirements for SOC 2, PCI, NIST CSF, ISO 27001, CCPA
- CISA, CISM or are working toward certification
Compensation
The base salary range for this role is $155-165k. The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc.
Location
This position is classified as REMOTE within the United States of America.
We are unable to hire candidates located outside of the domestic U.S.
Benefits
- Market-leading medical, dental, and vision insurance
- Stock options
- Free Premium-Tier Origin Financial Wellness subscription
- Monthly home-office stipend
- 401k (TransAmerica)
- 12-weeks paid parental leave for birthing and non-birthing parents
- Flexible time off + sick and safe time
- 11 paid company holidays
- View email address on click.appcast.io Same Day Pay Option
Branch is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Must be currently authorized to work in the USA without sponsorship or transfer.
No third-parties, please.
View how Branch collects your personal data here.
- ...To support the organization's security initiatives, the remote Senior Security GRC Analyst will manage the Information Security Program, conduct compliance audits, and collaborate with various stakeholders to enhance security practices and policies. Key responsibilities...SeniorRemote work
$90k - $135k
...Our team members are empowered to take ownership, make informed decisions, and make a meaningful impact as the bank continues... ...your best. Together we win! THE OPPORTUNITY The Senior GRC Information Security Analyst role will be part of the Information Security...SeniorLocal areaImmediate startFlexible hours$115k - $125k
...Overview: Sr. Information Security GRC Analyst Location: Tire Rack South Bend, IN (On-Site) Department: Information Security Employment Type... ...000 annually About the Role Tire Rack is seeking a Senior Information Security GRC Analyst to support and advance...SeniorFull timeMonday to Friday$99k - $136.5k
...business objectives. Transforms complex information and documentation into simple concepts... ...risks and enhance loanDepot's overall security posture. Stays informed about the latest... ...' experience working in Cybersecurity GRC, policy development, risk management, or...SeniorLocal area- Axon is seeking a Senior Security Program Analyst to lead core corporate security programs focusing on Governance, Risk, and Compliance (GRC). In this role, you will have significant autonomy to coordinate activities that ensure security initiatives are executed effectively...Senior
- PTR Global is looking for a Senior Information Security Analyst to support governance work focusing on data-at-rest protection and enterprise information... ..., with strong analytical skills and experience in GRC. The position is a contract for 18-24 months based in Chandler...SeniorContract work
- ...This role sits within theInformation Security Governance, Risk and Compliance (GRC) team, which reports directly into... ...control framework that governs information security across Chatham. This team... ...The Information Security GRC Analyst with a Risk and Policy focusis responsible...Contract workImmediate start
- ...Title: Information Security GRC Analyst Location: Remote, EST Time Duration: 7+ Months JOB DESCRIPTION Responsibilities: Support the development and implementation of an enterprise-wide business continuity program. Execute tasks associated...Remote work
- A leading company is seeking a senior-level GRC Security Analyst for their Policy, Risk, and Third-Party Security team in Houston, TX. The role involves conducting risk assessments, developing compliance strategies, and supporting cross-functional projects to enhance IT...Senior
- ...Senior Security Analyst, Information Security Location: O'Fallon, MO Rate: DOE $/hr. on w2 only Position Type: contract Interview Process: Phone followed by F2F US Citizen, Green Card and GC EAD, Job Description: Skills: • Identity/Access Management...SeniorContract work
- ...Position Summary Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for Purpose Financials information security program. This role is the operational backbone of our compliance posture owing to SOC 2 Type II readiness...Contract workCasual workWork at office
- ...The Sr. Information Security Analyst is responsible for assessing information risk and facilitates remediation of identified vulnerabilities for IT security and IT risk across the enterprise. Assesses information risk and facilitates remediation of identified vulnerabilities...SeniorRemote work
$94.1k - $164.8k
...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk management policies, procedures and limits. Essential...Temporary workWork experience placementWork at office$60 - $65 per hour
...Information Security GRC Analyst Job Type: Contract Contract Length: 6 months Pay Range: $60-$65/hr Start Date: ASAP Location: Remote (EST) About the Opportunity Our client, a leader in the Cloud Infastructure industry, is looking for a skilled Information Security GRC...Contract workFor contractorsImmediate startRemote work- ...Access Management Information Security Analyst We believe that, when done right, investing liberates people to create their own destiny. We are driven by our purpose to champion every client’s goals with passion and integrity. We respect and appreciate the diversity...Senior
- ...Job Summary The Senior IT Security Analyst is responsible for engineering and administration of IT Security systems as well as monitoring... ...operational implementation requirements ensuring compliance with information security policy, standards, guidelines. Reports any...Senior
- ...Insight Global are seeking a Senior IT Security & Compliance Analyst to support and strengthen global security and compliance initiatives... ...Haves: Strong experience in IT Compliance, Information Security, IT Audit, or GRC Strong experience working with SOX, PCI, or...SeniorContract workWork at office
- ...IT Security Risk And Audit Program Lead The management, assessment, and mitigation... ...risks are fundamental components of our information assurance and cyber security program.... ...PCI DSS) and IT best practices. GRC Risk Analyst Skills & Requirements: ~7-10 years...Work experience placement
- ...Job Title Under general direction of the Sr Security Analysis Manager, works closely with the other members of the team to develop and implement a comprehensive information security program. This includes coordinating implementation, optimization, and operation of...SeniorWork at office
- ...Central About the Job: Full Time Job Function The Senior IT Security Analyst is responsible for safeguarding enterprise systems,... ...organization. Basic Qualifications ~ Bachelor’s degree in Information Security, Computer Science, Engineering, or equivalent...SeniorFull timeTemporary workFor contractorsWork experience placementLocal area
- ...some of the most cutting edge software/security solutions platforms in the world.... ...Job Details: As a Consulting Senior SOC Security Analyst, you will be at the forefront of our... ...team that ensures the security of our information systems against threats, attacks, and...SeniorLocal area
- ...Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority... ...into executive-level insights that inform prioritization, investment and... ...and Governance, Risk and Compliance (GRC) platforms (e.g. ServiceNow GRC, X-Analytics...SeniorWork experience placement
- ...A company is looking for a Sr. Information Security Analyst. Key Responsibilities Provide operational support for IAM related administration tools Analyze access requirements and implement improvements to data quality and role decisions Enhance IAM posture and assist...SeniorRemote work
- ...Job Title: Info Security Analyst-Senior Job location :Irving Texas Duration:12 month Job Description: In support... ...Experience: ~5 to 10 years Certificates: ~ ITIL, Information security industry certification on any one of CISSP, CISA,...Senior
- ...motivated candidate to join our talented Team. Job Title : IT Security Analyst Senior. Location : Atlanta, GA. About the Role: We... ...Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or...SeniorFor contractorsWork experience placementRemote work
- ...Senior Security Analyst – GRC The Senior Security Analyst – GRC (Governance, Risk and Compliance) is a member of the IT Security team and works... ...and automation of core functions supporting the Information Security program. This person will work to support the continued...Senior
$43.46 per hour
...candidates with their reasonable salary requests.*** 25% Perm Placement Fee The primary responsibility of the Senior Information Systems Security position is to ensure the confidentiality, availability and integrity of Parkland's data, computer systems and...SeniorHourly payPermanent employmentLocal areaFlexible hours- ...candidate to join our talented Team. Job Title: Senior Security Vulnerability Analyst Location: Washington, DC Responsibilities:... ...the discovered gaps. Certification Certified Information Systems Security Professional (CISSP) GIAC Enterprise...Senior
- ...Information Security Analyst Location: Fully Remote Duration: 4-12+ months Contract Must Haves: CyberArk is the must have skill set. Communication 10/10, they need to be able to communicate clearly as well as document everything clearly. The other key skill...SeniorContract workRemote workWeekend work
- ...Senior Technical Security Analyst Location: Sterling, VA Position Type: Full Time Salary: $100k-... ...with a Risk Management Framework and GRC tool to perform risk assessments of... ...maintain a knowledge base regarding information security risks, issues, solutions and...SeniorFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Information Security GRC Analyst. Be the first to apply!
- business intelligence data analyst United States
- data analyst United States
- data center analyst United States
- data analyst full time United States
- data analyst manager United States
- research data analyst United States
- data analyst bank United States
- remote data analyst intern United States
- data analyst - r python sql United States
- data solutions analyst United States


