← Back to results

Information Security Compliance Analyst

Join Vestwell as an Information Security Compliance Analyst to manage compliance systems in a rapidly scaling fintech company.

Location
New York, NY, United States
Compensation
$90k–$105k/yr
Level
mid
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 2 hours ago

Last verified on the company career page 2 hours ago

Apply at Vestwell → Save job Scanned from vestwell.com

What you'll build

  • Manage cybersecurity risk processes
  • Manage cybersecurity compliance obligations
  • Coordinate cybersecurity audits and assessments
  • Support customer cybersecurity risk management

Must have

  • Experience with SOC, ISO, and other audits
  • Experience responding to RFPs
  • Experience working cross-teams to implement new compliance processes

Nice to have

  • Vendor management experience
  • Led an audit response

Not disclosed in this posting: years of experience, visa sponsorship.

Benefits

401k Match Unlimited PTO Equity/Stock Options Remote Work Health Insurance

Joblaze summary

The Information Security Compliance Analyst at Vestwell is tasked with overseeing compliance systems, ensuring adherence to cybersecurity standards, and managing risk processes. Key skills include experience with SOC and ISO audits, as well as the ability to respond to RFPs and collaborate across teams to enhance compliance practices. This role is well-suited for candidates with a strong analytical background and familiarity with vendor management. Vestwell's hybrid work model supports collaboration while accommodating flexibility.

Joblaze insights

Quick facts

Is the Information Security Compliance Analyst role remote?
It's hybrid — Vestwell expects some on-site time in New York, NY, United States.
What's the salary range?
Vestwell lists $90,000–$105,000 for this role.
Where is the role based?
Vestwell is hiring for this position in New York, NY, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: CrowdStrike, ISO, NIST, Responsive, SoC, Vanta.
What seniority level is this role?
Vestwell targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Information Security Compliance Analyst role at Vestwell.

From the original posting

Vestwell is the financial technology company powering the new savings economy. Our platform redefines how people save for the critical aspects of life across retirement, education, and healthcare savings needs.

Today, Vestwell enables over 350,000 businesses and over 2M active savers, with over $50B in assets saved across all 50 states.

Vestwell's platform serves a diverse clientele, including financial advisers, employers, third-party administrators, financial institutions, payroll providers, government agencies, and individual savers. To learn more, visit vestwell.com

Who Are We Looking For?

The Vestwell Corporate Information Technology team is looking for an experienced, meticulous and detail-oriented Information Security compliance analyst to be responsible for monitoring the compliance systems in our rapidly scaling organization. The compliance analyst's responsibilities include reviewing our SOC controls and comparing them to actions today, coming up with new automations to confirm compliance, responding to RFPs, and building a library of knowledge to speed up the RFP response program.

You will work cross-functionally with teams such as Security and Engineering to identify and correct any flaws in our Compliance systems as well as Legal and Compliance to advise on best practices and policies

You should have a sound working knowledge of compliance, including audits and RFPs. You should be detail oriented with strong analytical skills and have good communication, interpersonal, and leadership skills.

What Will You Be Doing?

  • Manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance within the Vestwell Governance, Risk and Compliance (GRC) solution.
  • Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIST, ISO and SOC 1&2, and other applicable cybersecurity standards and frameworks.
  • Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, IT, and business leaders.
  • Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.

Requirements

The Necessities

  • Experience with SOC, ISO, and other audits
  • Experience responding to RFPs
  • Experience working crossteams to implement new compliance processes
  • Vendor management, review experience

The Extras

  • Familiarity with software such as:
    • Crowdstrike
    • Vanta
    • Responsive
  • Led an audit response


This role will be based in our New York City or Austin office, and will be part of Vestwell's hybrid in-office operation.

The expected base salary range for this position is $90K - $105K base. This position is eligible to participate in the Company Bonus Pool and is eligible to receive new hire equity in the Company. Please note that salary bands are based on NY and other similar metro areas and may differ based on where the role is ultimately hired.

Employee Benefits
We’re an innovative, high-growth company with an exciting future ahead. At Vestwell, we prioritize employee wellbeing through comprehensive health benefits, generous time off, and a dedicated Employee Wellbeing Committee. Our hybrid work model offers flexibility while providing access to our collaborative offices in Midtown Manhattan, Austin, King of Prussia, and Scottsdale. And, of course, as a company focused on helping people save for the future, we offer a competitive 401(k) plan.

Interview Process
Our interview process starts the same for every candidate with 1-2 introductory conversations to learn more about your background, interests, and what you're looking for, while also giving you the opportunity to learn more about Vestwell and the team. From there, the process varies by role but typically includes a skills or experience-based assessment, such as a coding interview, portfolio review, or deeper discussion of your relevant experience. Successful candidates then move on to a virtual or in-person interview panel. Before extending an offer, we complete a reference check with a current or former manager and a peer. Throughout the process, we prioritize transparency, clear communication, and minimizing surprises.

For your awareness you will only receive correspondence from recruiting@vestwell.com any other domain not ending in vestwell.com is not our Recruitment team.

Vestwell’s Privacy Policy. Attention California residents: In the course of conducting our business and complying with federal, state, and local government regulations governing such matters as employment, tax, insurance, etc., we must collect Personal Information from you. Should you accept employment with Vestwell you may view our California Privacy Rights Act here: Vestwell’s California Privacy Rights Policy.

Similar positions

Vestwell
Senior Associate, Employer Services
Vestwell · New York, NY | Austin, TX | King of Prussia, PA | Scottsdale, AZ
Vestwell
Associate, Retirement Plan Services
Vestwell · New York, NY, United States
Vestwell
Vestwell
Senior Associate, Retirement Plan Services
Vestwell · New York, NY, United States
Vestwell
Senior Associate, Implementations
Vestwell · New York, NY | Austin, TX | King of Prussia, PA | Scottsdale, AZ