Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Information Security GRC Analyst

$155k - $165k

Branch

Senior Information Security GRC Analyst

Remote, US

Branch is on a mission to empower workers with financial freedom. We do this by helping companies accelerate payments and providing working Americans with accessible, free financial services. We're committed to building and delivering more inclusive, transparent, and frictionless financial products.

Our goal of empowerment extends to our own employees, too. Have a great idea? Share it today and it might just get implemented tomorrow. As a member of our team, your voice and creativity matter—and they can directly impact our products, company, and culture.

We not only focus on attracting great talent from across the country, but also on building teams that help that talent thrive. That means valuing a diversity of opinions and working styles, while creating a shared belief in innovation, initiative, and winning together.

Come join our team as we develop new ways to improve the lives of working Americans.

About the Role

Branch is seeking an experienced Security Governance, Risk, and Compliance (GRC) professional to join our team. This position will work in all aspects of GRC, so broad knowledge is preferred across multiple frameworks and related policy and procedure lifecycle management. The ideal candidate will have a background in managing relationships with internal stakeholders (C Suite, Risk, and Legal), external partners (3rd party vendors, auditors, sub-processors), and working closely with members of the Security team.

Responsibilities include, but are not limited to:

  • Manage and maintain the Branch Information Security Program, security function programs and processes. Own internal Branch controls. Maintain an accurate security program and all the associated processes across all corporate functions.
  • Ambassador and champion of the Branch Information Security Program and security awareness.
  • Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA).
  • Conduct comprehensive gap analysis to identify deficiencies and areas for improvement in existing controls.
  • Experience implementing new frameworks and integrating into existing audit cycles.
  • Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with the frameworks (SOC 2, ISO 27001, PCI, NIST, CCPA) implemented by Branch.
  • Manage Branch's Drata GRC platform:
    • Ensure information is up to date and automated collections are working appropriately.
    • Ensure that Audit evidence is collected and validated.
    • Manage access to and keep information up to date for Branch's Security Trust Center.
    • Manage and maintain frameworks, policies, control content and control mapping.
  • Inform the proper stakeholders of important concerns, hazards, and risk to the organization.
  • Collaborate with stakeholders (Security, Engineering, Cloud Operations, Procurement, and Legal) to ensure security practices are integrated into daily operations, and are aligned with our GRC objectives.
  • Maintain up-to-date knowledge of procedures and methods that serve to broaden team knowledge and industry expertise.
  • Write and manage security standards, policies, and practices on an ongoing basis to make sure they meet corporate demands.
  • Assist the department in responding to inquiries from the business units about ongoing operational compliance.
  • Be proactive in seeking out areas for improvement and offer insightful advice and value-added guidance and/or automation for process and control enhancements.
  • Manage the end-to-end third-party vendor management lifecycle, including onboarding, due diligence, and ongoing monitoring of vendor risk, performance, and operational changes through established governance processes.
  • Partner with the Risk and Legal teams to share information and seek out areas for improvement, streamline processes and to reduce risk throughout the company.
  • Manage the security training and awareness program, responsible for promoting and enhancing our organization's security culture through effective awareness programs and initiatives.
  • Support the planning of penetration tests and the coordination of remediation efforts.
Qualifications
  • 5-7 years of experience in a similar role
  • 3+ years of expertise conducting audits (SOC 2, PCI or ISO 27001), as well as handling audit responses
  • Excellent communication skills
    • Oral and written communication to an audience of employees as well as to the leadership team is necessary
  • Create and maintain clear, concise, and accurate documentation that supports our GRC initiatives
  • Knowledge of GRC tool techniques and best practices (Drata, HyperProof, AuditBoard, OneTrust)
  • Solid ethics and core values - Situations sometimes require discretion and may be of a confidential or sensitive nature
  • Excellent organizational, process improvement, and project management skills
  • Familiarity with security and compliance requirements for SOC 2, PCI, NIST CSF, ISO 27001, CCPA
  • CISA, CISM or are working toward certification
Compensation

The base salary range for this role is $155-165k. The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc.

Location

This position is classified as REMOTE within the United States of America.

We are unable to hire candidates located outside of the domestic U.S.

Benefits
  • Market-leading medical, dental, and vision insurance
  • Stock options
  • Free Premium-Tier Origin Financial Wellness subscription
  • Monthly home-office stipend
  • 401k (TransAmerica)
  • 12-weeks paid parental leave for birthing and non-birthing parents
  • Flexible time off + sick and safe time
  • 11 paid company holidays
  • View email address on click.appcast.io Same Day Pay Option

Branch is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Must be currently authorized to work in the USA without sponsorship or transfer.

No third-parties, please.

View how Branch collects your personal data here.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Information Security GRC Analyst in United States vacancy
  •  ...To support the organization's security initiatives, the remote Senior Security GRC Analyst will manage the Information Security Program, conduct compliance audits, and collaborate with various stakeholders to enhance security practices and policies. Key responsibilities... 
    Senior
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  • $90k - $135k

     ...Our team members are empowered to take ownership, make informed decisions, and make a meaningful impact as the bank continues...  ...your best. Together we win! THE OPPORTUNITY The Senior GRC Information Security Analyst role will be part of the Information Security... 
    Senior
    Local area
    Immediate start
    Flexible hours

    Banc of California

    Santa Ana, CA
    1 day ago
  • $115k - $125k

     ...Overview: Sr. Information Security GRC Analyst Location: Tire Rack South Bend, IN (On-Site) Department: Information Security Employment Type...  ...000 annually About the Role Tire Rack is seeking a Senior Information Security GRC Analyst to support and advance... 
    Senior
    Full time
    Monday to Friday

    Discount Tire

    Indiana
    3 days ago
  • $99k - $136.5k

     ...business objectives. Transforms complex information and documentation into simple concepts...  ...risks and enhance loanDepot's overall security posture. Stays informed about the latest...  ...' experience working in Cybersecurity GRC, policy development, risk management, or... 
    Senior
    Local area

    loanDepot

    Plano, TX
    4 days ago
  • Axon is seeking a Senior Security Program Analyst to lead core corporate security programs focusing on Governance, Risk, and Compliance (GRC). In this role, you will have significant autonomy to coordinate activities that ensure security initiatives are executed effectively... 
    Senior

    Axon

    Scottsdale, AZ
    4 days ago
  • PTR Global is looking for a Senior Information Security Analyst to support governance work focusing on data-at-rest protection and enterprise information...  ..., with strong analytical skills and experience in GRC. The position is a contract for 18-24 months based in Chandler... 
    Senior
    Contract work

    PTR Global

    Chandler, AZ
    3 days ago
  •  ...This role sits within theInformation Security Governance, Risk and Compliance (GRC) team, which reports directly into...  ...control framework that governs information security across Chatham. This team...  ...The Information Security GRC Analyst with a Risk and Policy focusis responsible... 
    Contract work
    Immediate start

    Chatham Financial

    Kennett Square, PA
    1 day ago
  •  ...Title: Information Security GRC Analyst Location: Remote, EST Time Duration: 7+ Months JOB DESCRIPTION Responsibilities: Support the development and implementation of an enterprise-wide business continuity program. Execute tasks associated... 
    Remote work

    Trilyon, Inc.

    United States
    4 days ago
  • A leading company is seeking a senior-level GRC Security Analyst for their Policy, Risk, and Third-Party Security team in Houston, TX. The role involves conducting risk assessments, developing compliance strategies, and supporting cross-functional projects to enhance IT... 
    Senior

    Compunnel, Inc.

    Houston, TX
    2 days ago
  •  ...Senior Security Analyst, Information Security Location: O'Fallon, MO Rate: DOE $/hr. on w2 only Position Type: contract Interview Process: Phone followed by F2F US Citizen, Green Card and GC EAD, Job Description: Skills: • Identity/Access Management... 
    Senior
    Contract work

    Staffing the Universe

    O Fallon, MO
    1 day ago
  •  ...Position Summary Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for Purpose Financials information security program. This role is the operational backbone of our compliance posture owing to SOC 2 Type II readiness... 
    Contract work
    Casual work
    Work at office

    Purpose Financial

    Greenville, SC
    5 days ago
  •  ...The Sr. Information Security Analyst is responsible for assessing information risk and facilitates remediation of identified vulnerabilities for IT security and IT risk across the enterprise. Assesses information risk and facilitates remediation of identified vulnerabilities... 
    Senior
    Remote work

    TridentCare

    United States
    3 days ago
  • $94.1k - $164.8k

     ...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk management policies, procedures and limits. Essential... 
    Temporary work
    Work experience placement
    Work at office

    CareSource

    Dayton, OH
    3 days ago
  • $60 - $65 per hour

     ...Information Security GRC Analyst Job Type: Contract Contract Length: 6 months Pay Range: $60-$65/hr Start Date: ASAP Location: Remote (EST) About the Opportunity Our client, a leader in the Cloud Infastructure industry, is looking for a skilled Information Security GRC... 
    Contract work
    For contractors
    Immediate start
    Remote work

    DeWinter Group

    San Jose, CA
    4 days ago
  •  ...Access Management Information Security Analyst We believe that, when done right, investing liberates people to create their own destiny. We are driven by our purpose to champion every client’s goals with passion and integrity. We respect and appreciate the diversity... 
    Senior

    Samprasoft

    Austin, TX
    2 days ago
  •  ...Job Summary The Senior IT Security Analyst is responsible for engineering and administration of IT Security systems as well as monitoring...  ...operational implementation requirements ensuring compliance with information security policy, standards, guidelines. Reports any... 
    Senior

    Continental Resources

    Oklahoma City, OK
    3 days ago
  •  ...Insight Global are seeking a Senior IT Security & Compliance Analyst to support and strengthen global security and compliance initiatives...  ...Haves: Strong experience in IT Compliance, Information Security, IT Audit, or GRC Strong experience working with SOX, PCI, or... 
    Senior
    Contract work
    Work at office

    Insight Global

    Miami, FL
    4 days ago
  •  ...IT Security Risk And Audit Program Lead The management, assessment, and mitigation...  ...risks are fundamental components of our information assurance and cyber security program....  ...PCI DSS) and IT best practices. GRC Risk Analyst Skills & Requirements: ~7-10 years... 
    Work experience placement

    Samprasoft

    Boca Raton, FL
    2 days ago
  •  ...Job Title Under general direction of the Sr Security Analysis Manager, works closely with the other members of the team to develop and implement a comprehensive information security program. This includes coordinating implementation, optimization, and operation of... 
    Senior
    Work at office

    Dallas Fort Worth International Airport

    Dallas, TX
    1 day ago
  •  ...Central About the Job: Full Time Job Function The Senior IT Security Analyst is responsible for safeguarding enterprise systems,...  ...organization. Basic Qualifications ~ Bachelor’s degree in Information Security, Computer Science, Engineering, or equivalent... 
    Senior
    Full time
    Temporary work
    For contractors
    Work experience placement
    Local area

    Foxconn Industrial Internet

    Houston, TX
    6 days ago
  •  ...some of the most cutting edge software/security solutions platforms in the world....  ...Job Details: As a Consulting Senior SOC Security Analyst, you will be at the forefront of our...  ...team that ensures the security of our information systems against threats, attacks, and... 
    Senior
    Local area

    Jobot

    Irvine, CA
    2 days ago
  •  ...Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority...  ...into executive-level insights that inform prioritization, investment and...  ...and Governance, Risk and Compliance (GRC) platforms (e.g. ServiceNow GRC, X-Analytics... 
    Senior
    Work experience placement

    Institute of Nuclear Power Operations

    Atlanta, GA
    3 days ago
  •  ...A company is looking for a Sr. Information Security Analyst. Key Responsibilities Provide operational support for IAM related administration tools Analyze access requirements and implement improvements to data quality and role decisions Enhance IAM posture and assist... 
    Senior
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  •  ...Job Title: Info Security Analyst-Senior Job location :Irving Texas Duration:12 month Job Description: In support...  ...Experience: ~5 to 10 years Certificates: ~ ITIL, Information security industry certification on any one of CISSP, CISA,... 
    Senior

    TriOptus LLC

    Irving, TX
    1 day ago
  •  ...motivated candidate to join our talented Team. Job Title : IT Security Analyst Senior. Location : Atlanta, GA. About the Role: We...  ...Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or... 
    Senior
    For contractors
    Work experience placement
    Remote work

    Ampcus

    Atlanta, GA
    10 days ago
  •  ...Senior Security Analyst – GRC The Senior Security Analyst – GRC (Governance, Risk and Compliance) is a member of the IT Security team and works...  ...and automation of core functions supporting the Information Security program. This person will work to support the continued... 
    Senior

    1872 Consulting

    Chicago, IL
    1 day ago
  • $43.46 per hour

     ...candidates with their reasonable salary requests.*** 25% Perm Placement Fee The primary responsibility of the Senior Information Systems Security position is to ensure the confidentiality, availability and integrity of Parkland's data, computer systems and... 
    Senior
    Hourly pay
    Permanent employment
    Local area
    Flexible hours

    Reliant Staffing Solutions

    Dallas, TX
    3 days ago
  •  ...candidate to join our talented Team. Job Title: Senior Security Vulnerability Analyst Location: Washington, DC Responsibilities:...  ...the discovered gaps. Certification Certified Information Systems Security Professional (CISSP) GIAC Enterprise... 
    Senior

    Ampcus

    Washington DC
    2 days ago
  •  ...Information Security Analyst Location: Fully Remote Duration: 4-12+ months Contract Must Haves: CyberArk is the must have skill set. Communication 10/10, they need to be able to communicate clearly as well as document everything clearly. The other key skill... 
    Senior
    Contract work
    Remote work
    Weekend work

    Samprasoft

    United States
    2 days ago
  •  ...Senior Technical Security Analyst Location: Sterling, VA Position Type: Full Time Salary: $100k-...  ...with a Risk Management Framework and GRC tool to perform risk assessments of...  ...maintain a knowledge base regarding information security risks, issues, solutions and... 
    Senior
    Full time

    Georgia IT Inc

    Sterling, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Information Security GRC Analyst. Be the first to apply!