Live opening · Posted 7 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
1. About Our Client:
The organization operates in the financial technology sector, focusing on redesigning credit services to be more transparent and user-friendly. It addresses challenges in traditional lending by offering consumers flexible payment options without hidden fees or compounded interest. The organization emphasizes security as a critical component of its continued success and is evolving its security risk management practices by integrating engineering-driven approaches to protect both the company and its customers.
2. About the Opportunity:
The Security Risk Management Specialist II will play a key role in advancing the third-party risk and security governance programs. This position involves evaluating and improving risk management solutions, automating governance processes, and partnering with various stakeholders to ensure security policies effectively mitigate vendor-related risks. The role supports the transformation of security risk management into a more engineering-oriented discipline, contributing to the organization''s security posture and operational efficiency.
3. Responsibilities:
Conduct third-party security assessments, reviewing vendor questionnaires and evaluating security controls.
Build and maintain automation solutions to streamline manual governance, risk, and compliance workflows using Python and low-code tools.
Configure and manage integrations across ticketing, governance, risk, compliance, and vendor management platforms.
Collaborate with Procurement, Legal, Engineering, IT, Compliance, and Privacy teams on risk reviews and mitigation strategies.
Develop and maintain dashboards and metrics to provide clear visibility into third-party risk.
Contribute to process improvements and documentation to mature security governance practices.
4. Requirements:
Minimum of 3 years’ experience in Information Security, Risk Management, Compliance, or a related field.
Proficiency in Python scripting and familiarity with agentic coding tools such as Cursor, Claude Code, or Copilot.
Knowledge of cloud environments (AWS, GCP, Azure) and cloud security principles.
Understanding of security frameworks like NIST, ISO 27001, SOC 2, and PCI DSS.
Strong written and verbal communication skills, capable of conveying security risk concepts to diverse audiences.
Professional certification (CISSP, CISM, CISA, CRISC) or equivalent practical experience preferred.
Bachelor’s degree in a relevant field or equivalent experience is preferred.
5. Pay Range and Compensation Package:
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $130,000 - 180,000
USA Sapphire base pay range (all other U.S. states) per year: $115,000 - 165,000
Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness, and technology spending, and benefits covering medical, dental, and vision insurance for employees and dependents.
Visa sponsorship is not available for this position.
6. Benefits & Perks:
100% subsidized medical coverage for employees and their dependents
Dental and vision insurance for employees and their dependents
Monthly stipends for health, wellness, and technology expenses
Flexible vacation and holiday schedules
Employee stock purchase plan (ESPP) enabling discounted stock purchases
Equal Opportunity Statement:
Equal Opportunity Statement: Our client is an equal opportunity employer. They celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, or national origin.
Note:
RemoteHunter is a recruitment partner of this role. Please note that all employment decisions, including candidate assessment, interviews, hiring, compensation, and employment terms, are made exclusively by the hiring employer.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.