Information Security Analyst

Betterment Betterment · Fintech · New York, NY · Risk

Information Security Analyst role focused on governance, risk, and compliance (GRC) activities within a financial services company. Responsibilities include performing risk assessments, monitoring vulnerability remediation, and supporting audits. The role will leverage AI and automation tools to enhance efficiency.

What you'd actually do

  1. Operates assigned risk management processes such as vulnerability monitoring, due diligence questionnaire completion, audit or examination evidence gathering. A number of AI and automation tools will be available to facilitate increasing efficiency and scale in this work over time. The role will have some flexibility for specialization among the team.
  2. Perform application-level risk assessments by interviewing and documenting the key business processes and risks related to an application, and providing guidance regarding strong logical access controls to reduce risk. When appropriate, document issues and foster management attention related to remediation for control deficiencies.
  3. Perform due diligence or ongoing monitoring activities to evaluate security risks introduced through third-party relationships or applications or tools used by employees.
  4. Contribute to security awareness training or phishing simulation activities for training of employees and contractors.
  5. Gather data and ensure management attention towards key risk indicator (KRI) metrics for security.

Skills

Required

  • 2+ years experience in technology operations, technology audit, or GRC
  • operated security controls in an IT operations role, or served as a Staff or Senior-level auditor (in public accounting or internal audit), or previously worked in a security role successfully
  • knowledge and familiarity with the principles of security risk management, including the CIA triad, design and operation of controls, and one or more control governance frameworks
  • familiarity with security controls applicable to cloud computing and third-party SaaS applications, including logical access management processes, third-party due diligence and monitoring
  • experience learning new skills, including through research and the use of AI and automation

What the JD emphasized

  • managing information security risk is critical to the trust that we foster with our clients, investors, and regulators.