Vestwell

Information Security Compliance Analyst

Vestwell$90K — $105K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in information security compliance or audit roles
  • Proven track record in responding to RFPs effectively
  • Strong cross-functional collaboration skills, particularly with compliance and IT teams
  • Experience with vendor management and security expectations
  • Familiarity with cybersecurity frameworks like NIST, ISO, and SOC 1&2

Responsibilities

  • Manage cybersecurity risk processes including risk registers and remediation plans
  • Oversee compliance with regulatory, contractual, and customer cybersecurity obligations
  • Coordinate audits and assessments with various teams to ensure compliance
  • Support risk management for customers and vendors through communication and documentation
  • Develop automation processes to enhance compliance monitoring

Benefits

  • Comprehensive health benefits
  • Generous time off policies
  • Access to multiple collaborative office locations
  • Flexible hybrid work model
  • Competitive 401(k) plan
Full Job Description
The Vestwell Corporate Information Technology team is looking for an experienced, meticulous and detail-oriented Information Security compliance analyst to be responsible for monitoring the compliance systems in our rapidly scaling organization. The compliance analyst's responsibilities include reviewing our SOC controls and comparing them to actions today, coming up with new automations to confirm compliance, responding to RFPs, and building a library of knowledge to speed up the RFP response program.

You will work cross-functionally with teams such as Security and Engineering to identify and correct any flaws in our Compliance systems as well as Legal and Compliance to advise on best practices and policies

You should have a sound working knowledge of compliance, including audits and RFPs. You should be detail oriented with strong analytical skills and have good communication, interpersonal, and leadership skills.

What Will You Be Doing?
  • Manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance within the Vestwell Governance, Risk and Compliance (GRC) solution.
  • Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIST, ISO and SOC 1&2, and other applicable cybersecurity standards and frameworks.
  • Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, IT, and business leaders.
  • Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, security expectations, and customer-facing services.


Requirements

The Necessities
  • Experience with SOC, ISO, and other audits
  • Experience responding to RFPs
  • Experience working crossteams to implement new compliance processes
  • Vendor management, review experience

The Extras
  • Familiarity with software such as:
    • Crowdstrike
    • Vanta
    • Responsive
  • Led an audit response


This role will be based in our New York City or Austin office, and will be part of Vestwell's hybrid in-office operation.

The expected base salary range for this position is $90K - $105K base. This position is eligible to participate in the Company Bonus Pool and is eligible to receive new hire equity in the Company. Please note that salary bands are based on NY and other similar metro areas and may differ based on where the role is ultimately hired.

Employee BenefitsWe're an innovative, high-growth company with an exciting future ahead. At Vestwell, we prioritize employee wellbeing through comprehensive health benefits, generous time off, and a dedicated Employee Wellbeing Committee. Our hybrid work model offers flexibility while providing access to our collaborative offices in Midtown Manhattan, Austin, King of Prussia, and Scottsdale. And, of course, as a company focused on helping people save for the future, we offer a competitive 401(k) plan.

Interview Process
Our interview process starts the same for every candidate with 1-2 introductory conversations to learn more about your background, interests, and what you're looking for, while also giving you the opportunity to learn more about Vestwell and the team. From there, the process varies by role but typically includes a skills or experience-based assessment, such as a coding interview, portfolio review, or deeper discussion of your relevant experience. Successful candidates then move on to a virtual or in-person interview panel. Before extending an offer, we complete a reference check with a current or former manager and a peer. Throughout the process, we prioritize transparency, clear communication, and minimizing surprises.

For your awareness you will only receive correspondence from [redacted] any other domain not ending in vestwell.com is not our Recruitment team.

About Vestwell

Vestwell is a financial technology company that provides retirement planning and investment services to employers and employees. The company's platform allows employers to offer retirement plans to their employees, and employees to manage their retirement savings and investments. Vestwell was founded in 2016 and is headquartered in New York City.
Learn more about Vestwell
Size
50 employees
Industry
Founded
2016

Similar Jobs

More Jobs at Vestwell

More Information Technology Jobs

Find similar Information Security Compliance Analyst jobs: