Sr. Analyst, IT Security, Risk & Compliance

Prosum

  • Irvine, CA
  • 6 days ago

    Highlights

    The company is actively building its security/GRC framework , giving you the opportunity to help establish how the program operates, take ownership of the controls and processes, and play a meaningful role in its continued maturity. The security/GRC framework is being built today, so you’ll have the opportunity to come in during the implementation phase and help turn the framework into a practical, operational security program.

    Numbers & Facts

    LocationIrvine, CA

    Description

    Sr. Analyst, IT Security, Risk & Compliance
    Irvine, CA | Hybrid – 2 days/week onsite | $125K–$145K + 10% bonus

    We’re looking for a hands-on IT Security, Risk & Compliance professional to join a fast-growing, consumer-focused company that is actively building and maturing its security program.

    This is a great opportunity for someone who wants real ownership and impact. The security/GRC framework is being built today, so you’ll have the opportunity to come in during the implementation phase and help turn the framework into a practical, operational security program.
    What You’ll Do
    • Own the day-to-day operation and execution of the IT security and GRC program.
    • Operate and maintain the company’s ISMS, security controls, risk register, compliance activities and control calendar.
    • Coordinate and execute control testing, access reviews, assessments and audit-readiness activities.
    • Gather and validate audit evidence, maintain documentation and drive findings through remediation and closure.
    • Investigate and coordinate the response to security incidents, vulnerabilities, access issues and security findings.
    • Work closely with internal stakeholders, third-party security partners, vendors and the company’s global parent organization.
    • Develop and maintain security policies, SOPs, playbooks, control narratives and other security documentation.
    • Track security awareness, phishing education, compliance activities, remediation and overall security program health.
    • Identify opportunities to improve and mature the security program over time.
    What They’re Looking For
    • 5+ years of experience in IT Security, GRC, Information Security, Security Compliance or a related area.
    • Hands-on experience with security controls, audits, risk assessments, compliance, remediation and control testing.
    • Experience with one or more frameworks such as ISO 27001, NIST, SOC 2 or SOX ITGC.
    • Strong understanding of Microsoft 365, Entra ID/Azure AD, endpoint management, IAM, cloud security and security operations.
    • Experience investigating or coordinating security incidents and vulnerability remediation.
    • Strong documentation, organization, communication and follow-through skills.
    • Someone who can work independently, navigate ambiguity and figure things out without needing constant direction.
    Why This Opportunity?
    This isn't a role where you'll simply maintain someone else's mature security program.

    The company is actively building its security/GRC framework, giving you the opportunity to help establish how the program operates, take ownership of the controls and processes, and play a meaningful role in its continued maturity.

    You'll also work in a highly cloud-based, technology-driven environment with significant exposure to third-party technology and security partners and a global parent organization.

    If you're a security/GRC professional who enjoys ownership, problem-solving and building something rather than simply maintaining it, this could be an excellent opportunity.

     

    Similar Jobs