yandex
E
epay-policy
Страна
США
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

Information Security Compliance Analyst

Оценка ИИ

Отличная позиция в стабильном финтехе с высокой культурой (97% удержание клиентов) и прямым влиянием на процессы. Предлагается гибридный график, неограниченный отпуск и работа в быстрорастущей компании, что дает отличные возможности для карьерного роста.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует глубоких знаний в области комплаенса (PCI DSS, NACHA) и умения проводить детальный технический аудит вендоров вручную, а не просто через GRC-платформы. Высокий уровень ответственности и необходимость взаимодействия с юридическими и финансовыми отделами усложняют позицию.

Анализ зарплаты

Медиана115 000 $
Рынок95 000 $ – 135 000 $
Оценка ИИ

Зарплата в объявлении не указана, но для Остина (Техас) рыночный диапазон для специалистов с опытом 3-5 лет в GRC составляет $95,000–$130,000. ePayPolicy позиционирует себя как конкурентоспособный работодатель, поэтому можно ожидать предложения в этих пределах.

Сопроводительное письмо

I am writing to express my strong interest in the Information Security Compliance Analyst position at ePayPolicy. With over 4 years of experience in IT audit and third-party risk management, I have developed a keen ability to bridge the gap between technical security requirements and business operations. My background in conducting deep-dive technical assessments and managing SOC report reviews aligns perfectly with your need for a professional who can own the TPRM lifecycle.

In my previous roles, I have successfully navigated complex procurement processes, ensuring that security standards were not just met, but integrated as a business enabler. I am particularly drawn to ePayPolicy's growth trajectory and the opportunity to report directly to the Head of InfoSec & Infra to help scale the security posture. My familiarity with PCI-DSS and NACHA frameworks, combined with a 'figure-it-out' mindset, makes me well-equipped to contribute to your team's success from day one.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в epay-policy уже сейчас

Присоединяйтесь к ePayPolicy и станьте ключевым экспертом по безопасности в быстрорастущем финтех-лидере!

Описание вакансии

Every day, ePayPolicy helps over 10,000 insurance companies speed up incoming and outgoing payments. By helping them move from manual, outdated forms of payment collection to modern payment tools, we help their companies work faster and more efficiently. (Check out our almost 5-star customer reviews.)

How do we do it? With powerful payment tools that just work. Our secure, online ACH and credit card payment page is the core product for many of our companies. But we also provide an integrated suite of helpful features for insurance companies of all sizes, including point-of-sale financing, payables network tools, and check reconciliation, all within a single dashboard.

Our expert, live support team helps deliver exceptional care every day, with an industry-leading 97% customer retention rate. Our customers love us. We love them.

Founded in 2014, our growing team is based in Austin, TX, and has clients in all 50 US states. We’ve grown over 300% in the last three years - with big plans for the future.

Position Summary

The Information Security Compliance Analyst is a high-impact role designed for a professional who thrives at the intersection of technical security, risk management, and business operations. This position is the primary engine for our Third-Party Risk Management (TPRM) lifecycle and a key contributor to our broader GRC (Governance, Risk, and Compliance) program, privacy initiatives, and audit readiness.

The ideal candidate is a self-starting "problem-solver" who can navigate complex technical environments and manage multiple high-priority workstreams in parallel. You are expected to act as a strategic partner to the business, applying expert-level stakeholder engagement and a keen eye for process optimization to ensure security compliance serves as a seamless business enabler.

Key Responsibilities

1. Strategic Procurement Partnership & Project Management

  • End-to-End Ownership: Act as a dedicated "Procurement Partner" for internal requestors, managing the workflow from initial intake through final vendor approval and onboarding handoff.
  • Tiered Risk Assessment: Conduct initial technical security assessments. You will be responsible for defining the scope and risk profile of new vendors, strategically engaging senior technical leads when specific high-risk architectures or complex integrations warrant specialized review.
  • Contractual Navigation: Facilitate the legal and contractual review process by translating security requirements into actionable contract language and liaising between Legal, Security, and external vendors.
  • Cross-Functional Onboarding: Orchestrate the final onboarding steps by coordinating with Finance, People Ops, and IT Ops to ensure all operational requirements are met before communicating final approval to the organization.

2. Annual Vendor Lifecycle & Risk Decisioning

  • Portfolio Management: Proactively manage the recurring annual assessment calendar for our existing vendor ecosystem. This requires exceptional time management to ensure deep-dive reviews are completed in parallel with active procurement projects.
  • Critical Risk Analysis: Perform sophisticated analysis of vendor documentation (e.g., SOC reports, SIGs, penetration test summaries). You are expected to synthesize this data to make informed recommendations on risk acceptance, identifying where internal controls can mitigate vendor gaps.

3. GRC, Audit Readiness & Privacy

  • Compliance Response: Serve as the "source of truth" for external parties, managing responses to inbound requests for compliance proof (Audit Reports, W9s, COIs, etc.).
  • Audit Coordination: Support the evidence collection and control-testing phases for annual audits, including PCI DSS and ACH/NACHA.
  • Privacy Operations: Support the Privacy Team as a first-line responder for data subject requests (DSRs) and foundational privacy inquiries.

4. Continuous Improvement & Automation

  • Process Engineering: Continuously evaluate the TPRM and GRC lifecycle for bottlenecks; propose and implement workflows that increase efficiency.
  • Automation Strategy: Partner with the Infrastructure team to automate manual evidence collection and vendor intake processes.

Required Skills & Qualifications

Technical Foundations

  • Systemic Understanding: A strong grasp of system architecture and data flows. You must understand how interconnected systems affect the scope of security and compliance boundaries.
  • Technical Literacy: Ability to interpret network diagrams, encryption standards, and vulnerability reports without requiring basic technical instruction.
  • Compliance Expertise: Foundational knowledge of PCI-DSS, NACHA operating rules, and core GRC principles.

Professional Attributes

  • Autonomous Execution: Proven ability to take a high-level objective and drive it to completion with minimal supervision.
  • Audience Awareness: Exceptional communication skills with the ability to tailor complex technical risks into clear, actionable insights for non-technical stakeholders.
  • Resourcefulness: A "figure-it-out" mindset—leveraging all available documentation, internal tools, and historical data to resolve ambiguity.
  • Analytical Rigor: A natural tendency toward detail; you catch the discrepancies in complex reports that others typically miss.

Experience Requirements

  • 3–5 years of experience in Information Security, IT Audit, or Third-Party Risk Management.
  • Technical Depth: Demonstrated experience performing manual security reviews and control assessments (independent of automated GRC "check-the-box" platforms).
  • Certifications: CISA, CRISC, or Security+ are preferred but not required.
  • Experience in fast-paced, growth-oriented environments where building processes is as important as following them.

Why Join Us?

This role offers a unique level of visibility and ownership. You will report directly to the Head of InfoSec & Infra, serving as a key voice in how we scale our security posture. If you are a high-judgment professional who takes pride in being the "expert in the room" for compliance, this is the role for you.

Why ePayPolicy

  • Competitive salary
  • Comprehensive benefits package with employer-paid basic life and disability premiums
  • 401K
  • Unlimited PTO
  • Company-sponsored quarterly “ePayItForward” initiatives
  • Supportive and inclusive company culture with a focus on work/life balance
  • Fully-stocked kitchen
  • Lunch stipend when working onsite
  • Open communication (We won’t box you in! If you have a cool idea for a product improvement or a suggestion on how to improve the customer experience, let’s talk about it. We value everyone’s ideas and opinions.)
  • Huge opportunity for growth

We operate on a hybrid schedule for in-office employees. Standard schedules are three days per week in the office, however, the cadence and days are determined by each team and manager.

We value diversity here at ePayPolicy and understand the importance of creating a safe and comfortable work environment, encouraging individualism and authenticity in every member of our team. We strive to create an accessible and inclusive experience for all candidates. If you need an accommodation during the application or recruiting process, please submit a request to our team via this Interview Accommodation form: https://forms.gle/xKppyKTSqfTUi7hz5

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Risk Management
  • PCI DSS
  • CISA
  • Information Security
  • IT Audit
  • Security
  • GRC
  • NACHA
  • Third-Party Risk Management
  • CRISC
  • SOC Reports

Возможные вопросы на собеседовании

Проверка практического опыта анализа рисков сторонних организаций.

Опишите ваш процесс анализа отчета SOC 2 Type II: на какие разделы и исключения вы обращаете внимание в первую очередь?

Оценка понимания специфики финтеха и платежных систем.

С какими основными сложностями вы сталкивались при обеспечении соответствия стандарту PCI DSS в облачных средах?

Проверка навыков коммуникации и разрешения конфликтов.

Как вы поступите, если бизнес-подразделение настаивает на работе с критически важным вендором, который не прошел вашу проверку безопасности?

Оценка способности к оптимизации процессов.

Какие метрики вы бы использовали для оценки эффективности программы управления рисками третьих сторон (TPRM)?

Проверка технической грамотности.

Как вы оцениваете риски безопасности при анализе сетевой диаграммы нового SaaS-решения?

Похожие вакансии

AG
Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
S
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
OZ
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
250 000 ₽ – 450 000 ₽

Эксперт по защите периметра (WAF)

УдалённоРоссия
WAF · Wallarm · Positive Technologies Application Firewall · NGFW · IPS · Vulnerability Assessment · Network Security
+7 навыков
К
Квазар
до 350 000 ₽

DevOps-инженер/ИБ (devops engineer, information security)

УдалённоРоссия
TCP/IP · DNS · DHCP · HTTPS · SMTP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · ELK · Wazuh · Grafana · Bash · PowerShell · Python · VMware · Proxmox · Hyper-V · KVM · SoC
+24 навыков
I
Innostaff
Не указана

Сеньор AppSecOps-инженер

SeniorУдалённоБеларусь
AppSecOps · DevSecOps · SAST · DAST · SCA · CI/CD · Cybersecurity · Kubernetes · Docker
+9 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

E
epay-policy
Страна
США