GRC SECURITY ANALYST

2 months, 1 week ago
Full-time
Senior
Cybersecurity
ClearCapital.com,

ClearCapital.com,

Clear Capital is a real estate valuation technology company that provides valuation services, data and analytics tools, and a full suite of appraisal services. They offer intelligent valuation solutions for properties nationwide, serving the mortgage a...

Real Estate
1-10

Description

  • Monitor and enforce compliance with security frameworks and industry regulations, including NIST CSF, NIST RMF, ISO 27001/27002, SOC 2, ISO 42001, GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments to identify security vulnerabilities, evaluate control effectiveness, and resolve complex compliance issues.
  • Develop, maintain, and update security policies, procedures, and guidelines aligned with best practices, client requirements, and regulatory standards.
  • Lead preparation for and participation in internal and external security audits, including defining audit scope and addressing audit findings.
  • Serve as an organizational representative for information security compliance and communicate with internal and external stakeholders.
  • Partner with cross-functional teams to develop and implement remediation plans for security gaps and weaknesses.
  • Evaluate the security posture and contractual compliance of third-party vendors handling sensitive financial and property data.
  • Maintain accurate records of compliance activities, findings, and remediation efforts, and prepare reports for management, clients, and regulators.
  • Define metrics to measure security program performance and provide regular reporting to security and business leadership.
  • Stay current on emerging security threats, technologies, and regulatory changes relevant to financial services and real estate tech.

Requirements

  • Minimum of 5 years of related experience in GRC, security compliance, or risk management, with a bachelor’s degree; or 3 years of experience with a master’s degree; or equivalent work experience.
  • Complete knowledge and understanding of relevant security frameworks and standards, including NIST CSF, SOC 2, ISO 27001, and ISO 42001.
  • Knowledge of data privacy regulations such as GLBA, GDPR, and CCPA.
  • Relevant industry certification such as CISSP, CISM, CISA, CRISC, AIGP, or equivalent.
  • Strong analytical and problem-solving skills for assessing unusual and complex security issues independently.
  • Strong communication and interpersonal skills, including the ability to influence differing audiences and advise senior stakeholders.
  • Familiarity with GRC technologies such as Vanta, Drata, and OneTrust, as well as risk assessment tools.
  • Working knowledge of cloud computing, DevOps, and application security.
  • Advanced proficiency with spreadsheets for data analysis, audit metric tracking, and compliance reporting.
  • Detail-oriented with a high standard for accuracy, confidentiality, integrity, and professionalism.
  • Ability to understand both legacy and modern technology controls and related risks.

Benefits

  • Base salary range of $114,000 to $139,000 annually, depending on location, experience, and qualifications.
  • Company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Comprehensive medical, dental, and company-paid vision insurance.
  • 401(k) retirement plan with employer match.
  • Paid time off and paid holidays.
  • Employee assistance and wellness programs, including company-paid access to Galileo for virtual primary care and Rula for virtual mental health support.
  • Company-paid short-term disability coverage and contributions to health savings funds for eligible participants.
  • Career and skill development resources to support professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Director, International Regulatory Affairs #4809

GRAIL 1K-5K Health Care Providers & Services

GRAIL is seeking a Director of International Regulatory Affairs to lead global regulatory strategy and commercialization of its early cancer detection products across major international markets.

HIPAA
10 hours, 31 minutes ago

Financial Intelligence Analyst

Wealthfront 51-250 Capital Markets

Wealthfront is hiring an Anti-Money Laundering Compliance professional for its Financial Intelligence Unit to investigate suspicious activity, file regulatory reports, and strengthen AML and fraud-monitoring programs.

10 hours, 46 minutes ago

Anti-Money Laundering Monitoring Analyst

Wealthfront 51-250 Capital Markets

Wealthfront is hiring an AML Compliance professional for its AML Monitoring team to triage potentially suspicious activity referrals and support the firm’s transaction monitoring and reporting programs.

10 hours, 46 minutes ago

Global Immigration Manager

DoorDash 10K-50K Air Freight & Logistics

DoorDash is seeking a Global Immigration Manager to lead its worldwide immigration program, overseeing strategy, operations, vendors, and compliance while enabling workforce mobility across 40+ countries.

11 hours, 1 minute ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers