GRC SECURITY ANALYST

14 hours, 59 minutes ago
Full-time
Senior
Cybersecurity
ClearCapital.com,

ClearCapital.com,

Clear Capital is a real estate valuation technology company that provides valuation services, data and analytics tools, and a full suite of appraisal services. They offer intelligent valuation solutions for properties nationwide, serving the mortgage a...

Real Estate
1-10

Description

  • Monitor and enforce compliance with security frameworks and industry regulations, including NIST CSF, NIST RMF, ISO 27001/27002, SOC 2, ISO 42001, GLBA, CCPA, and GDPR.
  • Conduct comprehensive risk assessments to identify security vulnerabilities, evaluate control effectiveness, and resolve complex compliance issues.
  • Develop, maintain, and update security policies, procedures, and guidelines aligned with best practices, client requirements, and regulatory standards.
  • Lead preparation for and participation in internal and external security audits, including defining audit scope and addressing audit findings.
  • Serve as an organizational representative for information security compliance and communicate with internal and external stakeholders.
  • Partner with cross-functional teams to develop and implement remediation plans for security gaps and weaknesses.
  • Evaluate the security posture and contractual compliance of third-party vendors handling sensitive financial and property data.
  • Maintain accurate records of compliance activities, findings, and remediation efforts, and prepare reports for management, clients, and regulators.
  • Define metrics to measure security program performance and provide regular reporting to security and business leadership.
  • Stay current on emerging security threats, technologies, and regulatory changes relevant to financial services and real estate tech.

Requirements

  • Minimum of 5 years of related experience in GRC, security compliance, or risk management, with a bachelor’s degree; or 3 years of experience with a master’s degree; or equivalent work experience.
  • Complete knowledge and understanding of relevant security frameworks and standards, including NIST CSF, SOC 2, ISO 27001, and ISO 42001.
  • Knowledge of data privacy regulations such as GLBA, GDPR, and CCPA.
  • Relevant industry certification such as CISSP, CISM, CISA, CRISC, AIGP, or equivalent.
  • Strong analytical and problem-solving skills for assessing unusual and complex security issues independently.
  • Strong communication and interpersonal skills, including the ability to influence differing audiences and advise senior stakeholders.
  • Familiarity with GRC technologies such as Vanta, Drata, and OneTrust, as well as risk assessment tools.
  • Working knowledge of cloud computing, DevOps, and application security.
  • Advanced proficiency with spreadsheets for data analysis, audit metric tracking, and compliance reporting.
  • Detail-oriented with a high standard for accuracy, confidentiality, integrity, and professionalism.
  • Ability to understand both legacy and modern technology controls and related risks.

Benefits

  • Base salary range of $114,000 to $139,000 annually, depending on location, experience, and qualifications.
  • Company profit-sharing bonus program, communication stipends, and referral bonuses.
  • Comprehensive medical, dental, and company-paid vision insurance.
  • 401(k) retirement plan with employer match.
  • Paid time off and paid holidays.
  • Employee assistance and wellness programs, including company-paid access to Galileo for virtual primary care and Rula for virtual mental health support.
  • Company-paid short-term disability coverage and contributions to health savings funds for eligible participants.
  • Career and skill development resources to support professional growth.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Risk & Audit Specialist

RemoteWoman 1-10 Internet Software & Services

Upsun is hiring a Senior Risk & Audit Specialist to help keep its global security, risk, audit, and compliance program on track across a remote, cross-functional organization.

HIPAA
14 hours, 44 minutes ago

Privacy and Compliance Analyst (Remote)

BIS Safety Software Internet Software & Services

BIS Safety Software is hiring a remote Privacy and Compliance Analyst to support its risk, privacy, and compliance operations for a SaaS platform serving organizations that manage safety, learning, and compliance.

Cybersecurity
14 hours, 59 minutes ago

PCI Compliance Consultant

Avertium 251-1K IT Services

Avertium is seeking a Remote PCI Compliance Consultant to lead PCI audit engagements and advise clients in the Risk & Compliance practice on secure, compliant solutions.

Cybersecurity Network Security
14 hours, 59 minutes ago

Senior Compliance Consultant

Planet Technologies 251-1K Internet Software & Services

Planet Technologies is hiring a Senior Compliance Consultant to support remote security and compliance projects for public sector, defense industrial base, and commercial customers, with a focus on developing and delivering compliance solutions and strategies.

Azure HIPAA
14 hours, 59 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers