Swbc

Swbc

Senior Security Assurance Analyst

San Antonio, TX · Senior

Sponsorship not specifiedDetected 1 day ago
Cloud PlatformsCybersecurityPenetration TestingProcurementLeadershipCritical ThinkingCISSP

About the role

  • SWBC is seeking a talented individual who will protect the organization, its clients, and its business operations through risk-based security assessments, third-party security reviews, control validation, and assurance activities.
  • If you enjoy solving complex problems, conducting investigative analysis, working with a wide variety of stakeholders, and translating technical risks into practical business guidance, this role may be a great fit for you.
  • Why you'll love this role: In this role, your work will directly influence business decisions, technology investments, third-party partnerships, and enterprise risk management efforts across the organization.

Responsibilities

  • This role serves as a trusted advisor to technology, business, compliance, procurement, and security stakeholders, helping them understand and manage cybersecurity risk while supporting regulatory, contractual, and business requirements.
  • As a key member of the Security team, you will perform in-depth security assessments, evaluate vendor security programs, review security controls, analyze evidence, and develop clear, actionable recommendations that strengthen the organization's security posture.

Requirements

  • Bachelor's degree in Cybersecurity, Information Security, Information Systems, Risk Management, Audit, Computer Science, or a related field, or equivalent experience.
  • Minimum of five (5) years of experience in cybersecurity, IT risk, IT audit, compliance, third-party risk management, security assessments, or related discipline.
  • Experience conducting independent security assessments and documenting risk-based findings.
  • Experience reviewing security controls, vendor documentation, SOC reports, audit artifacts, remediation plans, and compliance evidence.
  • Experience working with enterprise technology environments, cloud platforms, and third-party service providers.
  • Experience performing vendor risk assessments or third-party security reviews.
  • Experience supporting audits, examinations, or client assurance activities.
  • Familiarity with cloud security, application security, identity and access management, or data protection controls.
  • Experience using GRC, workflow, ticketing, or evidence management platforms.

Nice to have

  • At least one of the following certifications is required, others are strongly preferred: CISSP, CISA, CRISC, GIAC certifications

Skills

  • Evaluate security controls and identify potential risks, control gaps, and improvement opportunities.
  • Review vendor security questionnaires, SOC reports, certifications, penetration testing reports, and supporting security documentation.
  • Assess the security capabilities of prospective and existing third-party service providers.
  • Assist with internal audits, external audits, client assurance requests, and regulatory examinations.
  • Review evidence supporting security controls and evaluate control effectiveness.
  • Help ensure documentation remains accurate, complete, traceable, and audit-ready.
  • Produce executive-ready assessment summaries, risk narratives, and remediation recommendations.
  • Present findings to technical and non-technical audiences.
  • Work closely with Security, Technology, Compliance, Legal, Procurement, and business stakeholders.
  • Help teams understand security requirements, control expectations, and business risks.
  • Contribute to the ongoing enhancement of security assessment processes, templates, standards, and reporting practices.

Compensation

  • Competitive overall compensation package

This listing is sourced directly from Swbc's careers page and normalized into a canonical job model.