As a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations, and policies within the highly regulated mortgage lending and appraisal industry. You will play a critical role in maintaining our Governance, Risk, and Compliance (GRC) posture. Working independently with review at critical points, you will assess unusual circumstances, identify root causes using sophisticated analytical techniques, and devise creative solutions to complex compliance issues. You will help to coordinate internal and external security audits, define audit scopes, act as an organizational representative for information security compliance, and effectively adapt your communication style to influence and advise internal and external partners.
What you will work on
- Monitoring and enforcing compliance with critical security frameworks (such as NIST CSF, NIST RMF, ISO 27001/27002, SOC 2, ISO 42001) and industry-specific regulations (such as GLBA, CCPA, GDPR) pertinent to the financial services and real estate valuation sectors.
- Conducting comprehensive risk assessments of diverse scope to identify security vulnerabilities, evaluating the effectiveness of existing controls, and resolving a wide range of issues using judgment and interpretation.
- Developing, maintaining, and adapting security policies, procedures, and guidelines in alignment with industry best practices, client contractual requirements, and mortgage lending regulatory standards.
- Leading preparation and participation for internal and external security audits, adapting existing approaches to resolve audit findings based on limited information and precedent.
- Enhancing relationships with cross-functional teams to develop and implement remediation plans for identified security gaps and weaknesses.
- Evaluating the security posture of third-party vendors and assessing their compliance with contractual security requirements to protect sensitive financial and property data.
- Maintaining accurate records of compliance activities, findings, and remediation efforts, creating comprehensive reports for management, clients, and regulatory authorities as needed.
- Defining qualitative and quantitative metrics to assess the success of the security program and provide regular reports to security and business leadership.
- Staying abreast of emerging security threats, technologies, and regulatory changes in the financial and real estate tech space.
- Other relevant duties as assigned.
Who we are looking for
- A minimum of 5 years of related experience in GRC, security compliance, or risk management roles with a Bachelor’s degree; or 3 years and a Master’s degree; or equivalent work experience.
- Complete knowledge and full understanding of relevant security frameworks