Information Security Analyst

Sylvan, Inc.

Detroit (MI)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sylvan, Inc. is seeking a detail-oriented Information Security Analyst to design, assess, and document information security controls with a focus on ITGC and SOX compliance.

The role supports internal and external audits and drives process improvements across cross-functional teams. The successful candidate will maintain control matrices, SOX documentation, and evidence; coordinate audit activities; and communicate security concepts to non-technical stakeholders.

Qualifications

  • Bachelor's degree in a related field.
  • 3–6 years of information security, IT audit or compliance experience.
  • Hands-on ITGC design, testing, and remediation in a SOX environment.
  • Experience coordinating external audits (Big 4 or equivalent).
  • Proven ability to document processes, narratives, and risk matrices.
  • Strong written and verbal communication for diverse stakeholders.

Responsibilities

  • Design, implement, and monitor ITGC across access, change, operations, and SDLC.
  • Support SOX programs: scoping, risk assessment, control mapping, testing.
  • Remediate deficiencies and track CAPs to resolution.
  • Collaborate with process owners to embed IT controls in operations.
  • Maintain SOX docs, control matrices, and evidence per PCAOB/SEC.

Skills

ITGC design
SOX compliance
Audit coordination
GRC tools
Documentation skills
Communication
Regulatory understanding
Analytical thinking
Cloud security controls
Risk assessment

Education

Bachelor's degree in Information Security, Computer Science, Information Systems, Accounting/Finance (MIS)

Tools

AuditBoard
Workiva
ServiceNow GRC
Microsoft Office Suite

Job description

We are seeking a detail-oriented and experienced Information Security Analyst to join our security and compliance team. The successful candidate will play a key role in designing, assessing, and documenting information security controls, with a strong focus on IT General Controls (ITGC), SOX compliance, internal and external audit support, and process improvement. This role requires the ability to bridge technical security requirements with regulatory compliance obligations and communicate effectively with cross‑functional stakeholders.

Key Responsibilities
ITGC & SOX Compliance
  • Design, implement, and monitor IT General Controls (ITGC) across logical access, change management, computer operations, and SDLC domains.
  • Support annual SOX compliance programs, including scoping, risk assessment, control mapping, and testing coordination.
  • Identify and remediate control deficiencies; track findings through to resolution and validate management remediation actions.
  • Collaborate with business process owners to ensure SOX IT controls are embedded in day‑to‑day operations.
  • Maintain control matrices, SOX documentation, and supporting evidence in accordance with PCAOB and SEC requirements.
Internal & External Audit Support
  • Serve as the primary point of contact for internal and external auditors during IT audit engagements.
  • Coordinate the gathering, review, and submission of audit evidence packages to ensure completeness and accuracy.
  • Assist in preparing management responses to audit findings and tracking corrective action plans (CAPs).
  • Support SOC 1 / SOC 2 Type II audit engagements and other third‑party assessments.
  • Analyze audit observations to identify systemic issues and drive long‑term process improvements.
Process Design & Documentation
  • Develop and maintain information security policies, procedures, standards, and guidelines aligned with frameworks such as NIST CSF, ISO 27001, and CIS Controls.
  • Design and document end‑to‑end security and compliance processes, including control narratives, process flow diagrams, and risk and control matrices (RCMs).
  • Facilitate control walkthroughs with process owners and document evidence of operating effectiveness.
  • Maintain an up‑to‑date library of security process documentation and ensure version control and periodic review cycles.
  • Conduct risk assessments to identify gaps between current security posture and industry standards or regulatory requirements.
  • Evaluate the design and operating effectiveness of controls through self‑assessment and testing activities.
  • Prepare management‑level risk reports and dashboards, communicating findings clearly to technical and non‑technical audiences.
Required Qualifications
  • Bachelor’s Degree in Information Security, Computer Science, Information Systems, Accounting/Finance (MIS), or a related field.
  • 3–6 years of experience in information security, IT audit, or compliance roles.
  • Demonstrated hands‑on experience with ITGC design, testing, and remediation in a SOX environment.
  • Experience coordinating and supporting external audit engagements (Big 4 or equivalent).
  • Proficiency in developing process documentation, control narratives, and risk and control matrices.
  • Strong analytical and problem‑solving skills with keen attention to detail.
  • Excellent written and verbal communication skills; ability to convey complex technical concepts to non‑technical stakeholders.
Preferred Qualifications
  • Professional certifications such as CISA, CISSP, CRISC, CIA, or CISM.
  • Experience with GRC platforms (e.g., ServiceNow GRC, AuditBoard, Workiva, MetricStream).
  • Familiarity with cloud security controls (AWS, Azure, GCP) and how they relate to ITGC.
  • Knowledge of SOC 1 / SOC 2 attestation standards and Trust Service Criteria.
  • Experience working in a Big 4 accounting firm or publicly traded company.
  • Understanding of data privacy regulations (GDPR, CCPA) and their intersection with security controls.
Technical Skills & Tools
Frameworks

Principal frameworks include NIST CSF, ISO 27001, CIS Controls, and applicable regulatory standards.

Audit & GRC Tools

AuditBoard, Workiva, ServiceNow GRC, or equivalent.

Security Tools

SIEM, IAM/PAM platforms, vulnerability management tools.

Documentation

Preferred tools for creating and managing documentation include Microsoft Office Suite (Excel, Word, PowerPoint – advanced).

Core Competencies
  • Integrity & Accountability — Handles sensitive financial and security data with discretion.
  • Analytical Thinking — Evaluates complex control environments and identifies root causes.
  • Collaboration — Works effectively across security, IT, finance, legal, and operations teams.
  • Communication — Translates technical risks into business language for executive audiences.
  • Adaptability — Thrives in fast‑paced environments with evolving regulatory requirements.
  • Continuous Improvement — Proactively identifies opportunities to strengthen controls and processes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead DI Security and Compliance Analyst
Lead DI Security and Compliance Analyst

Jobtailor • Kentucky

On-site
USD 110,000 - 165,000
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000
Information Security Analyst
Information Security Analyst

Veriipro • Phoenix (AZ)

On-site
USD 90,000 - 120,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Senior IT Audit & GRC Lead (SOX & ITGC)
Senior IT Audit & GRC Lead (SOX & ITGC)

Jobtailor • Kentucky

On-site
USD 110,000 - 165,000
Senior Manager, IT Controls & Audit Compliance
Senior Manager, IT Controls & Audit Compliance

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Illinois Attorney General • Springfield (IL)

On-site
USD 65,000 - 90,000