Security Compliance Manager
US - Remote; CA - San Francisco HQ
Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation fintech company using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
About The Role
The Governance, Risk, and Compliance (GRC) team handles a wide range of cross-functional activities, from security compliance certifications and audits, to risk management, inbound and outbound due diligence, third party risk management, security awareness, policy and procedures, and more.
Each of these ongoing parallel activities entails interpreting and setting requirements, assessing the effectiveness of security controls, risk-based decision making, cross-functional collaboration and communication, and staying up-to-date on security best practices and how changes in the evolving threat landscape need to inform our strategy.
We are seeking an experienced Security Compliance Manager responsible for monitoring and governing security controls in the cloud based on regulatory/compliance requirements and industry standards. Candidate must be able to assimilate knowledge quickly, understand stakeholder’s business challenges/risks, and act as a trusted advisor to lead change, policy adoption and monitor compliance against policies and standards.
Key job responsibilities:
- Build and maintain an integrated cybersecurity controls framework
- Monitor and report on compliance against Information Security policies and standards
- Maintain security compliance programs within a GRC tool
- Define and execute existing or new compliance initiatives (i.e. SOC2, PCI, FFIEC CAT, NIST CSF, GLBA)
- Work independently to conduct compliance quantitative assessments from beginning to end with minimal supervision, manage key stakeholders relationships
- Identify the root cause of control gaps and exceptions and suggest remediation steps
- Maintain a cybersecurity risk register
- Prioritize and drive cross-functional remediation efforts for identified gaps based on risk impact and criticality
- Compile and present compliance posture to senior leadership via metrics and dashboards
- BS degree in Computer Information Systems or related field
- 7+ years of experience with security GRC initiatives
- Experience with onboarding and monitoring cybersecurity controls in cloud environments specifically AWS
- Experience managing SOC2, PCI DSS, SOX ITGC, GLBA or other compliance standards and framework programs
- Strong knowledge of security risk management and running audits/certification programs
- Self-starter with strong interpersonal and communication skills
- Demonstrate ability to assimilate new knowledge quickly
- Comfortable working in a fast-paced, dynamic environment, and managing multiple projects concurrently
- Experience with GRC tool implementation
- Experience with scanning solutions for policy and technical standards compliance
Preferred qualifications
- Big 4, or management/IT consulting experience
- Relevant certification (e.g. CISA, CISSP, PCI QSA, AWS certifications) or equivalent expertise
- Have knowledge of NIST 800-53/800-37,NIST CSF, SOC 2, PCI, and/or ISO 27001 standards, integrated controls framework, and evaluating design and effectiveness of IT controls working directly with auditors, regulators, investors
- Experience in building successful compliance programs for banks or fintech
- Experience defining compliance roadmaps based on customer requirements, compliance documentation, and ensuring that committed assessments are delivered on schedule
- Technical fluency; comfortable understanding and discussing technology concepts, experience evaluating tradeoffs and new opportunities with technical team members
Why you’ll love working here:
- Competitive salary packages and bonuses
- Comprehensive medical, dental, vision and life insurance benefits
- Generous vacation and holidays
- Paid parental leave for eligible employees
- 401(k) and education on retirement planning
- Tuition reimbursement on approved programs
- Monthly contribution up to $200 to help you pay off your student loans
- Great health & well-being benefits including: telehealth parental support, subsidized gym program
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
Due to local law, all employees who will be working from, traveling to, or attending work related meetings in our New York City office must be fully vaccinated and boosted (when eligible).
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
SoFi is committed to embracing diversity. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com.
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Tags: Audits AWS CISA CISSP Cloud Compliance Finance FinTech Governance ISO 27001 Monitoring NIST PCI DSS PCI QSA Privacy Risk management SOC SOC 2 Strategy
Perks/benefits: Competitive pay Flex vacation Health care Insurance Medical leave Parental leave Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Cybersecurity Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Specialist jobs
- Open Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open Security Researcher jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open Information System Security Officer (ISSO) jobs
- Open Agile-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open CISM-related jobs
- Open Pentesting-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open APIs-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open DevSecOps-related jobs
- Open CI/CD-related jobs