Branch

Senior Information Security GRC Analyst

Branch$155K — $165K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in a similar role
  • 3+ years of expertise conducting audits (SOC 2, PCI or ISO 27001)
  • Excellent communication skills for all organizational levels
  • Ability to create clear documentation for GRC initiatives
  • Knowledge of GRC tools like Drata, HyperProof, AuditBoard, OneTrust
  • Solid ethics and discretion for handling sensitive information
  • Strong organizational, process improvement, and project management skills

Responsibilities

  • Manage and maintain the Branch Information Security Program and processes
  • Serve as an ambassador for the Information Security Program
  • Perform control mapping for regulatory and compliance alignment
  • Conduct gap analyses to improve existing controls
  • Implement new frameworks and integrate them into audit cycles
  • Manage risk assessments, compliance reviews, and audits
  • Oversee the Drata GRC platform, ensuring information accuracy

Benefits

  • Market-leading medical, dental, and vision insurance
  • Stock options
  • Free Premium-Tier Origin Financial Wellness subscription
  • Monthly home-office stipend
  • 401k (TransAmerica)
  • 12-weeks paid parental leave for birthing and non-birthing parents
  • Flexible time off + sick and safe time
  • 11 paid company holidays
Full Job Description
About the role:

Branch is seeking an experienced Security Governance, Risk, and Compliance (GRC) professional to join our team. This position will work in all aspects of GRC, so broad knowledge is preferred across multiple frameworks and related policy and procedure lifecycle management. The ideal candidate will have a background in managing relationships with internal stakeholders (C Suite, Risk, and Legal), external partners (3rd party vendors, auditors, sub-processors), and working closely with members of the Security team.

Responsibilities include, but are not limited to:
  • Manage and maintain the Branch Information Security Program, security function programs and processes. Own internal Branch controls. Maintain an accurate security program and all the associated processes across all corporate functions.
  • Ambassador and champion of the Branch Information Security Program and security awareness.
  • Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA).
  • Conduct comprehensive gap analysis to identify deficiencies and areas for improvement in existing controls.
  • Experience implementing new frameworks and integrating into existing audit cycles.
  • Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with the frameworks (SOC 2, ISO 27001, PCI, NIST, CCPA) implemented by Branch.
  • Manage Branch's Drata GRC platform:
    • Ensure information is up to date and automated collections are working appropriately.
    • Ensure that Audit evidence is collected and validated.
    • Manage access to and keep information up to date for Branch's Security Trust Center.
    • Manage and maintain frameworks, policies, control content and control mapping.
  • Inform the proper stakeholders of important concerns, hazards, and risk to the organization.
  • Collaborate with stakeholders (Security, Engineering, Cloud Operations, Procurement, and Legal) to ensure security practices are integrated into daily operations, and are aligned with our GRC objectives.
  • Maintain up-to-date knowledge of procedures and methods that serve to broaden team knowledge and industry expertise.
  • Write and manage security standards, policies, and practices on an ongoing basis to make sure they meet corporate demands.
  • Assist the department in responding to inquiries from the business units about ongoing operational compliance.
  • Be proactive in seeking out areas for improvement and offer insightful advice and value-added guidance and/or automation for process and control enhancements.
  • Manage the end-to-end third-party vendor management lifecycle, including onboarding, due diligence, and ongoing monitoring of vendor risk, performance, and operational changes through established governance processes.
  • Partner with the Risk and Legal teams to share information and seek out areas for improvement, streamline processes and to reduce risk throughout the company.
  • Manage the security training and awareness program, responsible for promoting and enhancing our organization's security culture through effective awareness programs and initiatives.
  • Support the planning of penetration tests and the coordination of remediation efforts.

Qualifications:
  • 5-7 years of experience in a similar role
  • 3+ years of expertise conducting audits (SOC 2, PCI or ISO 27001), as well as handling audit responses
  • Excellent communication skills
    • Oral and written communication to an audience of employees as well as to the leadership team is necessary
  • Create and maintain clear, concise, and accurate documentation that supports our GRC initiatives
  • Knowledge of GRC tool techniques and best practices (Drata, HyperProof, AuditBoard, OneTrust)
  • Solid ethics and core values - Situations sometimes require discretion and may be of a confidential or sensitive nature
  • Excellent organizational, process improvement, and project management skills
  • Familiarity with security and compliance requirements for SOC 2, PCI, NIST CSF, ISO 27001, CCPA
  • CISA, CISM or are working toward certification

Compensation:

The base salary range for this role is $155-165k. The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc.

Location:

This position is classified as REMOTEwithin the United States of America.

We are unable to hire candidates located outside of the domestic U.S.

Benefits:
  • Market-leading medical, dental, and vision insurance
  • Stock options
  • Free Premium-Tier Origin Financial Wellness subscription
  • Monthly home-office stipend
  • 401k (TransAmerica)
  • 12-weeks paid parental leave for birthing and non-birthing parents
  • Flexible time off + sick and safe time
  • 11 paid company holidays

About Branch

Branch is a mobile-first technology company that provides financial services for hourly workers. The company's mission is to create a world where working Americans can grow financially. Branch offers a mobile app that allows users to access earned wages, budgeting tools, and financial wellness resources. Branch was founded in 2015 by Atif Siddiqi and has raised over $300 million in funding to date.
Learn more about Branch
Size
500 employees
Industry
Founded
2014

Similar Jobs

  • The PNC Financial Services Group, Inc
    LOB Risk Lead
    $91K — $169K *
    The PNC Financial Services Group, Inc
    Dallas, TX 75217 (Dallas County)
  • The PNC Financial Services Group, Inc
    LOB Risk Lead
    $91K — $169K *
    The PNC Financial Services Group, Inc
    Pittsburgh, PA 15237 (Allegheny County)
  • The PNC Financial Services Group, Inc
    LOB Risk Lead
    $91K — $169K *
    The PNC Financial Services Group, Inc
    Strongsville, OH 44136 (Cuyahoga County)
  • The PNC Financial Services Group, Inc
    LOB Risk Lead
    $91K — $169K *
    The PNC Financial Services Group, Inc
    Birmingham, AL 35242 (Shelby County)
  • Senior IT GRC Analyst
    $80K — $165K *
    Columbia Banking System, Inc.
    Los Angeles, CA 90011 (Los Angeles County)
  • Senior IT GRC Analyst
    $80K — $165K *
    Columbia Banking System, Inc.
    Las Vegas, NV 89110 (Clark County)

More Jobs at Branch

More Information Technology Jobs

Find similar Senior Information Security GRC Analyst jobs: