Velera

Formerly PSCU/Co-op Solutions

Security Compliance Analyst

Security AnalystSecurity AnalystFull TimeRemoteTeam 1,001-5,000H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

Not specified

PCI DSSNIST CSFCISACRISCCGEITIT AuditingGovernanceRisk ManagementSOXCOBITITILCOSOWindows ADAzureUnixOracleSQL

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

This position provides support for technology compliance programs, executing functions that may include:

  • Performing segregation of duties reviews and user attestations
  • Identifying/remediating technology compliance issues
  • Enforcing information security policies and standards to maintain company certifications (PCI DSS, NIST CSF)
  • Documenting, updating, and facilitating technology compliance deliverables
  • Participating on large-scale projects
  • Documenting and testing general computer and application controls
  • Supporting technology components of onsite and virtual audits/assessments, NCUA examinations, and client due diligence reviews

The individual will execute assigned duties to meet stated priorities within SLAs and plays a critical role in driving technology control and compliance practices and adoption across the company.

Qualifications

  • Bachelor’s degree in computer science, information systems, cybersecurity, or related field, or equivalent combination of education and experience required
  • Cybersecurity risk management, governance, and control professional certification required (CISA, CRISC, CGEIT)
  • Other relevant professional certifications preferred (e.g., CISSP, Security +, PCI Internal Security Assessor (ISA), PCI Qualified Security Assessor (QSA), Certificate of Cloud Security Knowledge (CCSK))
  • Five (5) years of relevant work experience in public accounting firm, IT controls consulting/testing, PCI/NIST CSF assessments, IT internal/external auditing, and technology risk management required
  • Experience in identification, validation, design, and testing operating effectiveness of general computer and application controls required
  • Experience in financial services required
  • Experience assessing Cloud security and controls preferred
  • Background in PCI DSS, NIST CSF, NIST AI Risk Mgt Framework, FFIEC, NACHA, CMM, COBIT, ITIL, COSO
  • Working knowledge of independent audit and assessment reports per job function (e.g., SOC1/2, PCI DSS AOC/ROC)
  • Ability to work with cross-functional technology and business teams
  • Ability to apply understanding of IT security/controls risk vs. business impact in decision making
  • Understanding and ability to apply security concepts across a broad scope of information technology areas
  • Working knowledge of and experience with various operating system and database platforms (e.g. Windows AD, Azure, Unix, Oracle, SQL)

Requirements

  • Execute technology compliance and governance duties as assigned to meet company information security & technology compliance standards, industry requirements, and applicable laws and regulations
  • Review, test, and validate user account and system security configurations for compliance
  • Execute segregation of duties (SOD) reviews and user attestations of internal/business partner systems
  • Document, maintain, and facilitate technology compliance deliverables
  • Support technology components of internal/external audits and assessments
  • Support vendor risk governance program, RFPs, and client due diligence responses
  • Identify, communicate, and escalate technology compliance issues and information security policy violations
  • Function as a liaison between technology and business units
  • Identify ongoing process improvements, operational gaps, and potential remediation steps
  • Participate on strategic business and client commercialization projects
  • Perform other duties as assigned

Benefits

  • Competitive wages
  • Medical with telemedicine
  • Dental and Vision
  • Basic and Optional Life Insurance
  • Paid Time Off (PTO)
  • Maternity, Parental, Family Care
  • Community Volunteer Time Off
  • 12 Paid Holidays
  • Company Paid Disability Insurance
  • 401k (with employer match)
  • Health Savings Accounts (HSA) with company provided contributions
  • Flexible Spending Accounts (FSA)
  • Supplemental Insurance
  • Mental Health and Well-being: Employee Assistance Program (EAP)
  • Tuition Reimbursement
  • Wellness program

Job Requirements

  • Bachelor’s degree in computer science, information systems, cybersecurity, or related field, or equivalent combination of education and experience required
  • Cybersecurity risk management, governance, and control professional certification required (CISA, CRISC, CGEIT)
  • Other relevant professional certifications preferred (e.g., CISSP, Security +, PCI Internal Security Assessor (ISA), PCI Qualified Security Assessor (QSA), Certificate of Cloud Security Knowledge (CCSK))
  • Five (5) years of relevant work experience in public accounting firm, IT controls consulting/testing, PCI/NIST CSF assessments, IT internal/external auditing, and technology risk management required
  • Experience in identification, validation, design, and testing operating effectiveness of general computer and application controls required
  • Experience in financial services required
  • Experience assessing Cloud security and controls preferred
  • Background in PCI DSS, NIST CSF, NIST AI Risk Mgt Framework, FFIEC, NACHA, CMM, COBIT, ITIL, COSO
  • Working knowledge of independent audit and assessment reports per job function (e.g., SOC1/2, PCI DSS AOC/ROC)
  • Ability to work with cross-functional technology and business teams
  • Ability to apply understanding of IT security/controls risk vs. business impact in decision making
  • Understanding and ability to apply security concepts across a broad scope of information technology areas
  • Working knowledge of and experience with various operating system and database platforms (e.g. Windows AD, Azure, Unix, Oracle, SQL)
  • Execute technology compliance and governance duties as assigned to meet company information security & technology compliance standards, industry requirements, and applicable laws and regulations
  • Review, test, and validate user account and system security configurations for compliance
  • Execute segregation of duties (SOD) reviews and user attestations of internal/business partner systems
  • Document, maintain, and facilitate technology compliance deliverables
  • Support technology components of internal/external audits and assessments
  • Support vendor risk governance program, RFPs, and client due diligence responses
  • Identify, communicate, and escalate technology compliance issues and information security policy violations
  • Function as a liaison between technology and business units
  • Identify ongoing process improvements, operational gaps, and potential remediation steps
  • Participate on strategic business and client commercialization projects
  • Perform other duties as assigned

Benefits

  • Competitive wages
  • Medical with telemedicine
  • Dental and Vision
  • Basic and Optional Life Insurance
  • Paid Time Off (PTO)
  • Maternity, Parental, Family Care
  • Community Volunteer Time Off
  • 12 Paid Holidays
  • Company Paid Disability Insurance
  • 401k (with employer match)
  • Health Savings Accounts (HSA) with company provided contributions
  • Flexible Spending Accounts (FSA)
  • Supplemental Insurance
  • Mental Health and Well-being: Employee Assistance Program (EAP)
  • Tuition Reimbursement
  • Wellness program

Related Job Pages

More Security Analyst Jobs

SAP Security Specialist

CACI International

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Security Analyst3 days ago
Full TimeRemoteTeam 10,001

The specialist will translate functional specifications into SAP role designs, manage technical roles, user authorizations, and handle Segregation of Duties conflict remediation projects. They will also provide subject matter expertise and technical direction to clients while ensuring system reliability through day-to-day sustainment support.

SAP SecuritySAP GRCSegregation of DutiesSODSAP AuthorizationBW4HANAS4HANAR3 ECC
United States
$90.3K - $189K / year

Security Analyst II

Garner Health

A better way to get your employees to high-quality doctors.

Security Analyst3 days ago
Full TimeRemoteTeam 51-200Since 2019H1B No Sponsor

Security Analyst II maintaining data integrity for Garner's healthcare technology

New York
$117K - $130K / year
Full TimeRemoteTeam 312Since 2010

This role involves conducting tactical threat monitoring and detection activities using internal tools to assess and communicate risks to customers through tactical-level reports. Analysts will produce high-quality tactical assessments, manage customer alerting profiles, and synthesize data to identify information credibility and relevance.

Threat IntelligenceData AnalysisPattern RecognitionCybersecurityRisk AssessmentTactical Monitoring
United States
Security Analyst3 days ago
Full TimeRemoteTeam 51-200Since 2021H1B No Sponsor

AGE Solutions is looking for a Security Control Assessor, Mid to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD in...

STIGRMFNIST 800-37NIST 800-53CNSSI 1253eMASSSTIG ViewerNessusACASSCAPHBSSWindowsUNIXCloudDatabasesPOA&M
United States