Swbc
Senior Security Assurance Analyst
San Antonio, TX · Senior
Sponsorship not specifiedDetected 1 day ago
Cloud PlatformsCybersecurityPenetration TestingProcurementLeadershipCritical ThinkingCISSP
About the role
- SWBC is seeking a talented individual who will protect the organization, its clients, and its business operations through risk-based security assessments, third-party security reviews, control validation, and assurance activities.
- If you enjoy solving complex problems, conducting investigative analysis, working with a wide variety of stakeholders, and translating technical risks into practical business guidance, this role may be a great fit for you.
- Why you'll love this role: In this role, your work will directly influence business decisions, technology investments, third-party partnerships, and enterprise risk management efforts across the organization.
Responsibilities
- This role serves as a trusted advisor to technology, business, compliance, procurement, and security stakeholders, helping them understand and manage cybersecurity risk while supporting regulatory, contractual, and business requirements.
- As a key member of the Security team, you will perform in-depth security assessments, evaluate vendor security programs, review security controls, analyze evidence, and develop clear, actionable recommendations that strengthen the organization's security posture.
Requirements
- Bachelor's degree in Cybersecurity, Information Security, Information Systems, Risk Management, Audit, Computer Science, or a related field, or equivalent experience.
- Minimum of five (5) years of experience in cybersecurity, IT risk, IT audit, compliance, third-party risk management, security assessments, or related discipline.
- Experience conducting independent security assessments and documenting risk-based findings.
- Experience reviewing security controls, vendor documentation, SOC reports, audit artifacts, remediation plans, and compliance evidence.
- Experience working with enterprise technology environments, cloud platforms, and third-party service providers.
- Experience performing vendor risk assessments or third-party security reviews.
- Experience supporting audits, examinations, or client assurance activities.
- Familiarity with cloud security, application security, identity and access management, or data protection controls.
- Experience using GRC, workflow, ticketing, or evidence management platforms.
Nice to have
- At least one of the following certifications is required, others are strongly preferred: CISSP, CISA, CRISC, GIAC certifications
Skills
- Evaluate security controls and identify potential risks, control gaps, and improvement opportunities.
- Review vendor security questionnaires, SOC reports, certifications, penetration testing reports, and supporting security documentation.
- Assess the security capabilities of prospective and existing third-party service providers.
- Assist with internal audits, external audits, client assurance requests, and regulatory examinations.
- Review evidence supporting security controls and evaluate control effectiveness.
- Help ensure documentation remains accurate, complete, traceable, and audit-ready.
- Produce executive-ready assessment summaries, risk narratives, and remediation recommendations.
- Present findings to technical and non-technical audiences.
- Work closely with Security, Technology, Compliance, Legal, Procurement, and business stakeholders.
- Help teams understand security requirements, control expectations, and business risks.
- Contribute to the ongoing enhancement of security assessment processes, templates, standards, and reporting practices.
Compensation
- Competitive overall compensation package
This listing is sourced directly from Swbc's careers page and normalized into a canonical job model.