Sr. Analyst, IT Security, Risk & Compliance
Irvine, CA | Hybrid 2 days/week onsite | $125K$145K + 10% bonusWere looking for a
hands-on IT Security, Risk & Compliance professional to join a fast-growing, consumer-focused company that is actively building and maturing its security program.
This is a great opportunity for someone who wants
real ownership and impact. The security/GRC framework is being built today, so youll have the opportunity to come in during the implementation phase and help turn the framework into a practical, operational security program.
What Youll Do
- Own the day-to-day operation and execution of the IT security and GRC program.
- Operate and maintain the companys ISMS, security controls, risk register, compliance activities and control calendar.
- Coordinate and execute control testing, access reviews, assessments and audit-readiness activities.
- Gather and validate audit evidence, maintain documentation and drive findings through remediation and closure.
- Investigate and coordinate the response to security incidents, vulnerabilities, access issues and security findings.
- Work closely with internal stakeholders, third-party security partners, vendors and the companys global parent organization.
- Develop and maintain security policies, SOPs, playbooks, control narratives and other security documentation.
- Track security awareness, phishing education, compliance activities, remediation and overall security program health.
- Identify opportunities to improve and mature the security program over time.
What Theyre Looking For
- 5+ years of experience in IT Security, GRC, Information Security, Security Compliance or a related area.
- Hands-on experience with security controls, audits, risk assessments, compliance, remediation and control testing.
- Experience with one or more frameworks such as ISO 27001, NIST, SOC 2 or SOX ITGC.
- Strong understanding of Microsoft 365, Entra ID/Azure AD, endpoint management, IAM, cloud security and security operations.
- Experience investigating or coordinating security incidents and vulnerability remediation.
- Strong documentation, organization, communication and follow-through skills.
- Someone who can work independently, navigate ambiguity and figure things out without needing constant direction.
Why This Opportunity?
This isn't a role where you'll simply maintain someone else's mature security program.
The company is
actively building its security/GRC framework, giving you the opportunity to help establish how the program operates, take ownership of the controls and processes, and play a meaningful role in its continued maturity.
You'll also work in a
highly cloud-based, technology-driven environment with significant exposure to third-party technology and security partners and a global parent organization.
If you're a security/GRC professional who enjoys
ownership, problem-solving and building something rather than simply maintaining it, this could be an excellent opportunity.