GRC SECURITY ANALYST

1 month, 2 weeks ago
Full-time
Senior
Cybersecurity
ClearCapital.com,

ClearCapital.com,

Clear Capital is a real estate valuation technology company that provides valuation services, data and analytics tools, and a full suite of appraisal services. They offer intelligent valuation solutions for properties nationwide, serving the mortgage a...

Real Estate
1-10

Description

  • Monitor and enforce compliance with security frameworks and industry regulations, including NIST CSF, NIST RMF, ISO 27001/27002, SOC 2, ISO 42001, GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments to identify security vulnerabilities, evaluate control effectiveness, and resolve complex compliance issues.
  • Develop, maintain, and update security policies, procedures, and guidelines aligned with best practices, client requirements, and regulatory standards.
  • Lead preparation for and participation in internal and external security audits, including defining audit scope and addressing audit findings.
  • Serve as an organizational representative for information security compliance and communicate with internal and external stakeholders.
  • Partner with cross-functional teams to develop and implement remediation plans for security gaps and weaknesses.
  • Evaluate the security posture and contractual compliance of third-party vendors handling sensitive financial and property data.
  • Maintain accurate records of compliance activities, findings, and remediation efforts, and prepare reports for management, clients, and regulators.
  • Define metrics to measure security program performance and provide regular reporting to security and business leadership.
  • Stay current on emerging security threats, technologies, and regulatory changes relevant to financial services and real estate tech.

Requirements

  • Minimum of 5 years of related experience in GRC, security compliance, or risk management, with a bachelor’s degree; or 3 years of experience with a master’s degree; or equivalent work experience.
  • Complete knowledge and understanding of relevant security frameworks and standards, including NIST CSF, SOC 2, ISO 27001, and ISO 42001.
  • Knowledge of data privacy regulations such as GLBA, GDPR, and CCPA.
  • Relevant industry certification such as CISSP, CISM, CISA, CRISC, AIGP, or equivalent.
  • Strong analytical and problem-solving skills for assessing unusual and complex security issues independently.
  • Strong communication and interpersonal skills, including the ability to influence differing audiences and advise senior stakeholders.
  • Familiarity with GRC technologies such as Vanta, Drata, and OneTrust, as well as risk assessment tools.
  • Working knowledge of cloud computing, DevOps, and application security.
  • Advanced proficiency with spreadsheets for data analysis, audit metric tracking, and compliance reporting.
  • Detail-oriented with a high standard for accuracy, confidentiality, integrity, and professionalism.
  • Ability to understand both legacy and modern technology controls and related risks.

Benefits

  • Base salary range of $114,000 to $139,000 annually, depending on location, experience, and qualifications.
  • Company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Comprehensive medical, dental, and company-paid vision insurance.
  • 401(k) retirement plan with employer match.
  • Paid time off and paid holidays.
  • Employee assistance and wellness programs, including company-paid access to Galileo for virtual primary care and Rula for virtual mental health support.
  • Company-paid short-term disability coverage and contributions to health savings funds for eligible participants.
  • Career and skill development resources to support professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Director, Compliance Product Advisory

Upgrade 251-1K Banks

Upgrade is seeking a Director of Compliance Advisory to support the launch and enhancement of consumer financial products by partnering with Product and Legal on compliance and risk matters.

2 hours, 55 minutes ago

Surety & Insurance Risk Manager

Giga Energy 11-50 Industrial Conglomerates

Giga Energy is hiring a Surety & Insurance Risk Manager to manage bonding and insurance operations for its rapidly scaling AI data center business.

3 hours, 25 minutes ago

Compliance Analyst II

Affirm 1K-5K Diversified Financial Services

Affirm is hiring a Compliance Analyst II in its Compliance Shared Services team to support centralized compliance training and governance programs for a remote role based in Poland.

Git
1 day, 2 hours ago

Compliance Advisory Manager - Investments, Pensions & Financial Promotions

Monzo 1K-5K Banks

Monzo is hiring a Compliance Advisory Manager to provide day-to-day compliance guidance across its Wealth, Growth & Marketing, and MonzOS teams within the UK second line of defence.

1 day, 3 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers