Velera

Velera

Senior IT Security Compliance Analyst - REMOTE

Remote-USA · Senior

No sponsorship$96k-$125kDetected 2 days ago
SQLAzureLinuxCybersecurityComplianceProject ManagementAccountingExcelAuditingProcess ImprovementCustomer SuccessCommunicationCollaborationProblem SolvingCritical ThinkingTime ManagementMentoringCertified ScrumMaster

About the role

  • The individual will execute assigned duties to meet stated priorities and SLAs.
  • The individual plays a critical role in driving technology control and compliance practices and adoption across the company.
  • Identify and report on technology control status and metrics; Assist with Audit Committee and Board reporting.

Responsibilities

  • Participate on strategic business and client commercialization projects (e.g., consulting, documenting, validating, and testing Blueprint controls); Review, test, and validate user account and security configurations for compliance with information security and technology policies/standards; Collect and maintain appropriate evidence and supporting documentation.
  • Execute segregation of duties (SOD) reviews and user attestations of internal/business partner systems and client online banking platforms.
  • Document, maintain, and facilitate technology compliance deliverables (e.g., PCI Scope Validation, Targeted Risk Assessments, Compensating Control Worksheets, Shared Responsibility Matrices, process flows, department procedures).
  • Perform QA reviews of technology compliance work products (e.g., user attestation packages) and client assistance documentation prior to delivering to internal and external auditors, clients, and business partners.
  • Support vendor risk governance program, RFPs, and client due diligence responses (e.g., SIG questionnaires, cybersecurity risk assessments).
  • Perform other duties as assigned.
  • Project management skills including ability to manage multiple projects and work effectively with technology and business resources to drive internal control, process improvement, and remediation efforts
  • Ability to travel as needed to successfully perform position responsibilities, less than 25%
  • Ability to maintain confidentiality of materials handled

Requirements

  • Cybersecurity risk management, governance, and control professional certification required (e.g., CISA, CRISC, CGEIT).
  • Eight (8) years of relevant work experience in public accounting firm, IT controls consulting/testing, PCI/NIST CSF assessments, IT internal/external auditing, and technology risk management required.
  • Experience assessing cloud security and controls required.
  • Experience in financial services required.
  • Solid knowledge of independent audit and assessment reports per job function (e.g., SOC1/2, PCI DSS AOC/ROC
  • Ability to work with cross-functional technology and business teams
  • Ability to apply understanding of IT security/controls risk vs. business impact in decision making
  • Ability to influence without authority
  • Ability to multi-task and juggle competing tasks under strict deadlines
  • Ability to take ownership, seeing tasks and projects through to satisfaction and completion
  • Bachelor's degree in computer science, information systems, cybersecurity, or related field, or equivalent combination of education and experience required. Cybersecurity risk management, governance, and control professional certification required (e.g., CISA, CRISC, CGEIT).
  • Other relevant professional certifications preferred (e.g., PCI Internal Security Assessor (ISA), PCI Qualified Security Assessor (QSA), Certificate of Cloud Security Knowledge (CCSK), Project Management Professional (PMP), Certified ScrumMaster (CSM)).
  • Eight (8) years of relevant work experience in public accounting firm, IT controls consulting/testing, PCI/NIST CSF assessments, IT internal/external auditing, and technology risk management required. Experience in identification, validation, design, and testing operating effectiveness of general computer and application controls. Experience assessing cloud security and controls required. Experience in financial services required.
  • Demonstrate behaviors based on Velera values: Dedication, Collaboration, Belonging, Curiousity, & Integrity
  • Theoretical knowledge and practical application of major risk and IT control frameworks, IT industry standards, and financial services regulations surrounding IT (e.g., PCI, NIST CSF, NIST AI Risk Management, FFIEC, NACHA, CMM, COBIT, ITIL, COSO)
  • Ability to be flexible and work under high pressure in a complex environment with frequently shifting priorities
  • Strong organizational and time management skills
  • Self-starter with minimal management supervision

Compensation

  • However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have

Company info

  • Join the People Helping People
  • Velera is the nation's premier payments credit union service organization (CUSO) and an integrated fintech solutions provider.
  • The company serves more than 4,000 financial institutions throughout North America, operating with velocity to help our clients keep pace with the rapid momentum of change and fuel growth in the new era of financial services.

Visa & Work Authorization

  • This role is currently not eligible for sponsorship.

This listing is sourced directly from Velera's careers page and normalized into a canonical job model.