Security Analyst - Governance, Risk, and Compliance
San Francisco, CA OR Remote
Full Time Senior-level / Expert USD 60K - 100K *
About UsFounded in 2005 as the first peer-to-peer marketplace lending platform in the U.S., Prosper was built on a simple idea: connect people who want to borrow money with those who want to invest. Since inception, Prosper has helped more than a million people gain access to affordable credit with over $20 billion in loans originated through its platform. Our mission is to help our customers advance their financial well-being through a variety of products including personal loans, home equity lines of credit (HELOC) and credit card. Our diverse culture rewards accountability and cross functional teamwork because we believe this encourages innovative thinking and helps us deliver on our mission. We’re on a mission to hire the very best, and we are committed to creating exceptional employee experiences where everyone is respected and has access to equal opportunity. We realize that new ideas can come from everywhere. It is important to us that every hire connects with our vision, mission, and core values. Join a leading fintech company that’s democratizing finance for all!
About Our Technology TeamWe are aggressively growing our Technology team to support our various financial products. The ideal candidate is passionate about learning the Fintech domain and delivering cutting-edge, high-quality solutions to solve business problems. We utilize a progressive, test-driven, Agile development methodology that places a high premium on communication, teamwork, sound design and clean implementation.
Our ValuesDiversity expands opportunitiesCollaboration creates better solutions Curiosity fuels our innovationIntegrity defines all our relationshipsExcellence leads to longevity Simplicity guides our user experience Accountability at all levels drives results
COVID-19 Vaccination PolicyProsper is continuing to grow our team during the COVID-19 pandemic, conducting fully remote hiring and onboarding processes. Our philosophy as a business is to approach the COVID-19 situation with empathy and urgency. Prosper’s top priority is the health and safety of our employees and of the communities we serve, including our customers, partners, prospects, and candidates. In accordance with this priority, along with our legal responsibility to provide and maintain a workplace that is safe and free of known hazards, we have adopted a COVID-19 Vaccination Policy which requires all of our employees to receive vaccinations, unless they have an approved accommodation.
www.prosper.comOur Story & Team // Our Blog
Prosper is seeking a detail oriented, highly motivated, technology savvy and passionate security professional with a desire to support, promote and further mature the company's security GRC program.
Responsible in executing various security compliance initiatives such as risk assessments, security control audits and 3rd party risk assessments. You will use your strong communication, analytical and troubleshooting abilities to quickly identify and report on controls from various security domains, control and/or process gaps and to identify process and technology opportunities.
Applicants have rights under Federal Employment Laws.Family & Medical Leave Act (FMLA)Equal Employment Opportunity (EEO)Employee Polygraph Protection Act (EPPA)
California applicants: please click here to view our California Consumer Privacy Act (“CCPA”) Notice for Applicants, which describes your rights under the CCPA: https://www.prosper.com/plp/legal/privacy-notice-for-applicants/
At Prosper, we're looking for people with passion, integrity, and a hunger to learn. We encourage you to apply even if your experience doesn't precisely match the job description. Your unique skill set and diverse perspective will stand out and set you apart from other candidates. Prosper thrives with people who think outside of the box and aren't afraid to challenge the status quo. We invite you to join us on our mission to advance financial well-being.
Prosper is committed to an inclusive and diverse workplace. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law, including the San Francisco Fair Chance Ordinance. Prosper will consider for employment qualified applicants who are non-US citizens and will provide green card sponsorship.
About Our Technology TeamWe are aggressively growing our Technology team to support our various financial products. The ideal candidate is passionate about learning the Fintech domain and delivering cutting-edge, high-quality solutions to solve business problems. We utilize a progressive, test-driven, Agile development methodology that places a high premium on communication, teamwork, sound design and clean implementation.
Our ValuesDiversity expands opportunitiesCollaboration creates better solutions Curiosity fuels our innovationIntegrity defines all our relationshipsExcellence leads to longevity Simplicity guides our user experience Accountability at all levels drives results
COVID-19 Vaccination PolicyProsper is continuing to grow our team during the COVID-19 pandemic, conducting fully remote hiring and onboarding processes. Our philosophy as a business is to approach the COVID-19 situation with empathy and urgency. Prosper’s top priority is the health and safety of our employees and of the communities we serve, including our customers, partners, prospects, and candidates. In accordance with this priority, along with our legal responsibility to provide and maintain a workplace that is safe and free of known hazards, we have adopted a COVID-19 Vaccination Policy which requires all of our employees to receive vaccinations, unless they have an approved accommodation.
www.prosper.comOur Story & Team // Our Blog
Prosper is seeking a detail oriented, highly motivated, technology savvy and passionate security professional with a desire to support, promote and further mature the company's security GRC program.
Responsible in executing various security compliance initiatives such as risk assessments, security control audits and 3rd party risk assessments. You will use your strong communication, analytical and troubleshooting abilities to quickly identify and report on controls from various security domains, control and/or process gaps and to identify process and technology opportunities.
Problems You Will Solve
- Conduct periodic information security (and privacy) risk assessments
- Review, audit, and monitor security compliance programs against security policies, standards, and frameworks such as PCI-DSS, NIST, SOC 2, etc.
- Support developing remediation plans for issues and risks, coordinate activities with owners, and track remediation to completion
- Assist in documenting, and maintaining the security control matrix
- Support the management of documentation such as security policies, standards and guidelines, process, and data flows
- Perform periodic user access reviews
- Lead evidence collection for external audits related to SOC1, SOC2, PCI-DSS, etc.
- Perform vendor security risk assessments
- Assist in maturing partner and investor due diligence program as it relates to queries about information security
- Build and cultivate positive working relationships with stakeholders across various teams
About You
- B.S. degree in Management Information Systems, Computer Science, Business, or any technology related field
- 3-4 years of risk management, internal controls, security audit, control framework/compliance, information security, and/or technology process experience
- Very high attention to detail, high integrity, and business ethics
- Excellent skills around troubleshooting, problem-solving, analytical thinking, and project management
- Knowledge/Experience in security technologies such as firewalls, IDS, DLP, Vulnerability Scanners, DAM, etc.
- Ability to work independently to achieve objectives and deliver results
- Experience in security standards/frameworks such as PCI-DSS, NIST, SOC 2, etc.
- CISSP, CISA, CISM or similar security certification is ideal
- Big 4 Consulting experience is a plus
Applicants have rights under Federal Employment Laws.Family & Medical Leave Act (FMLA)Equal Employment Opportunity (EEO)Employee Polygraph Protection Act (EPPA)
California applicants: please click here to view our California Consumer Privacy Act (“CCPA”) Notice for Applicants, which describes your rights under the CCPA: https://www.prosper.com/plp/legal/privacy-notice-for-applicants/
At Prosper, we're looking for people with passion, integrity, and a hunger to learn. We encourage you to apply even if your experience doesn't precisely match the job description. Your unique skill set and diverse perspective will stand out and set you apart from other candidates. Prosper thrives with people who think outside of the box and aren't afraid to challenge the status quo. We invite you to join us on our mission to advance financial well-being.
Prosper is committed to an inclusive and diverse workplace. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law, including the San Francisco Fair Chance Ordinance. Prosper will consider for employment qualified applicants who are non-US citizens and will provide green card sponsorship.
* Salary range is an estimate based on our salary survey at salaries.infosec-jobs.com
Job perks/benefits:
Career development
Medical leave
Job regions:
Remote/Anywhere
North America
Job country:
United States
Job stats:
10
2
0
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Cyber Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Penetration Tester jobs
- Open Senior DevSecOps Engineer jobs
- Open Application Security Engineer/Architect jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Threat Intelligence Analyst jobs
- Open Staff Security Engineer jobs
- Open Lead Security Engineer jobs
- Open SOC Analyst jobs
- Open Cyber Security Analyst jobs
- Open Sr. Security Engineer jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cybersecurity Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Head of Information Security jobs
- Open Senior Penetration Tester jobs
- Open Senior Information Security Analyst jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Cloud Security Automation Specialist jobs
- Open Cloud Security Operations Lead jobs
- Open Offensive Security Engineer jobs
- Open Information Security Officer jobs
- Open Azure Security Engineer jobs
- Open Security Operations Analyst jobs
- Open DevOps-related jobs
- Open Application security-related jobs
- Open Audits-related jobs
- Open Analytics-related jobs
- Open PCI-related jobs
- Open OWASP-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open Security assessments-related jobs
- Open IDS-related jobs
- Open Forensics-related jobs
- Open JavaScript-related jobs
- Open Ruby-related jobs
- Open Splunk-related jobs
- Open Encryption-related jobs
- Open CEH-related jobs
- Open CISM-related jobs
- Open GDPR-related jobs
- Open Open Source-related jobs
- Open Agile-related jobs
- Open OSCP-related jobs
- Open Threat detection-related jobs
- Open Machine Learning-related jobs
- Open Intrusion detection-related jobs
- Open DevSecOps-related jobs