Senior Information Security GRC Analyst

About us Branch is on a mission to empower workers with financial freedom. We do this by helping companies accelerate payments and providing working Americans with accessible, free financial services. We’re committed to building and delivering more inclusive, transparent, and frictionless financial products. Our goal of empowerment extends to our own employees, too. Have a great idea? Share it today and it might just get implemented tomorrow. As a member of our team, your voice and creativity matter—and they can directly impact our products, company, and culture. We not only focus on attracting great talent from across the country, but also on building teams that help that talent thrive. That means valuing a diversity of opinions and working styles, while creating a shared belief in innovation, initiative, and winning together. Come join our team as we develop new ways to improve the lives of working Americans. About the role Branch is seeking an experienced Security Governance, Risk, and Compliance (GRC) professional to join our team. This position will work in all aspects of GRC, so broad knowledge is preferred across multiple frameworks and related policy and procedure lifecycle management. The ideal candidate will have a background in managing relationships with internal stakeholders (C Suite, Risk, and Legal), external partners (3rd party vendors, auditors, sub-processors), and working closely with members of the Security team. Responsibilities include, but are not limited to - Manage and maintain the Branch Information Security Program, security function programs and processes. Own internal Branch controls. Maintain an accurate security program and all the associated processes across all corporate functions. - Ambassador and champion of the Branch Information Security Program and security awareness. - Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA). - Conduct comprehensive gap analysis to identify deficiencies and areas for improvement in existing controls. - Experience implementing new frameworks and integrating into existing audit cycles. - Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with the frameworks (SOC 2, ISO 27001, PCI, NIST, CCPA) implemented by Branch. - Manage Branch’s Drata GRC platform - Ensure information is up to date and automated collections are working appropriately. - Ensure that Audit evidence is collected and validated. - Manage access to and keep information up to date for Branch’s Security Trust Center. - Manage and maintain frameworks, policies, control content and control mapping. - Inform the proper stakeholders of important concerns, hazards, and risk to the organization. - Collaborate with stakeholders (Security, Engineering, Cloud Operations, Procurement, and Legal) to ensure security practices are integrated into daily operations, and are aligned with our GRC objectives. - Maintain up-to-date knowledge of procedures and methods that serve to broaden team knowledge and industry expertise. - Write and manage security standards, policies, and practices on an ongoing basis to make sure they meet corporate demands. - Assist the department in responding to inquiries from the business units about ongoing operational compliance. - Be proactive in seeking out areas for improvement and offer insightful advice and value-added guidance and/or automation for process and control enhancements. - Manage the end-to-end third-party vendor management lifecycle, including onboarding, due diligence, and ongoing monitoring of vendor risk, performance, and operational changes through established governance processes. - Partner with the Risk and Legal teams to share information and seek out areas for improvement, streamline processes and to reduce risk throughout the company. - Manage the security training and awareness program, responsible for promoting and enhancing our organization's security culture through effective awareness programs and initiatives. - Support the planning of penetration tests and the coordination of remediation efforts. Qualifications - 5-7 years of experience in a similar role - 3+ years of expertise conducting audits (SOC 2, PCI or ISO 27001), as well as handling audit responses - Excellent communication skills - Oral and written communication to an audience of employees as well as to the leadership team is necessary - Create and maintain clear, concise, and accurate documentation that supports our GRC initiatives - Knowledge of GRC tool techniques and best practices (Drata, HyperProof, AuditBoard, OneTrust) - Solid ethics and core values - Situations sometimes require discretion and may be of a confidential or sensitive nature - Excellent organizational, process improvement, and project management skills - Familiarity with security and compliance requirements for SOC 2, PCI, NIST CSF, ISO 27001, CCPA - CISA, CISM or are working toward certification Compensation The base salary range for this role is $155-165k. The salary range displayed reflects an average base salary range for the position across all the U.S. The base salary offered to an applicant could be higher or lower based on each applicant's specific skill set, depth of experience, relevant education or training, etc. Location This position is classified as REMOTEwithin the United States of America. We are unable to hire candidates located outside of the domestic U.S. Benefits - Market-leading medical, dental, and vision insurance - Stock options - Free Premium-Tier Origin Financial Wellness subscription - Monthly home-office stipend - 401k (TransAmerica) - 12-weeks paid parental leave for birthing and non-birthing parents - Flexible time off + sick and safe time - 11 paid company holidays - Branch@Branch Same Day Pay Option Working at Branch A remote-first company with employees located throughout the U.S., Branch emphasizes transparency, accountability, and trust to create a collaborative environment where our product, engineering, marketing, customer support, customer success, and sales teams can all thrive together. Learn more about what we do in this Branch_Manifesto" data-renderer-mark="true" rel="nofollow ugc noopener noreferrer" target="_blank">video! Our collaborative spirit has helped us become an award-winning FinTech company, with Branch’s innovation and workplace recognized across industries. Branch has been honored by Inc., the Webby Awards, Benzinga FinTech Awards, FinTech Breakthrough Awards, Top Workplaces USA, Great Places to Work, and EY Entrepreneur of the Year, Heartland, among others. Learn more about our culture, approach, technology, and people here https//www.branchapp.com/about Branch is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Must be currently authorized to work in the USA without sponsorship or transfer. No third-parties, please. View how Branch collects your personal data here. Apply To This Job

Back to blog
Ads

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...