Information Security GRC Analyst III

Advance America, Cash Advance Centers, Inc.

Greenville (SC)

On-site

USD 90,000 - 140,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive wages
401(k) savings with company match
Company paid holidays
Tuition reimbursement
Business casual environment
Rewards & Recognition program
Employee Assistance Program
Downtown Greenville office with free 2

Job summary

Purpose Financial, Inc. seeks an experienced Information Security GRC professional to design, audit, and maintain governance and controls across SOC 2 Type II, ISO 27001, and CIS/CSS frameworks.

You will manage risk assessments, evidence collection, and third‑party oversight in a fast‑paced fintech environment. You will collaborate with IT, SecOps, Legal, and Internal Audit to ensure audit readiness and continuous compliance across multiple business units, while guiding policy development and

Qualifications

  • Bachelor’s degree in Information Security or equivalent experience.
  • 3–5+ years of experience in information security GRC, compliance, or audit roles.
  • Hands-on experience with SOC 2 Type II audits (as auditee, control owner, or auditor).
  • Strong written communication skills and ability to produce policy documents, audit evidence, and executive reports.
  • Experience with GRC platforms and managing remediation tracking.

Responsibilities

  • Maintain and evolve information security policies, standards, and controls mapped to SOC 2, ISO 27001, NIST, and CIS.
  • Conduct risk assessments and maintain risk registers with structured evidence for mitigation.
  • Own end-to-end audit preparation for SOC 2 Type II and ISO 27001 certification, including testing and evidence collection.
  • Coordinate with IT, SecOps, Legal, Internal Audit, and stakeholders to protect company information assets.
  • Develop training and reporting to drive control adoption and audit readiness.

Skills

SOC 2 Type II audits
GRC platforms
Policy & risk reporting
Written communication
Project management

Education

Bachelor’s degree in Information Security

Tools

GRC platforms

Job description

Select how often (in days) to receive an alert:

Purpose Financial, Inc. is an innovative consumer financial services company that offers a diverse suite of credit products, promoting financial inclusion and meeting consumers wherever they are. Through its brands, the company is committed to helping customers achieve their version of financial stability in the moment and in the future. Since 1997, Purpose Financial has been a pioneer in the consumer credit and financial services market offering money solutions in over 800 storefronts locations and online lending. Providing services in over 23 states, Purpose Financial employs over 2,500 team members.

At Purpose Financial we are always on the lookout for motivated individuals who share in our values of mutual respect to join our team of outstanding professionals.

We offer:

  • Competitive Wages
  • 401(k) Savings Plan with Company Match
  • Company Paid Holidays
  • Tuition Reimbursement
  • Business Casual Environment
  • Rewards & Recognition Program
  • Employee Assistance Program
  • Office in downtown Greenville that offers free parking, onsite gym, free snacks/drinks

Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for Purpose Financials information security program. This role is the operational backbone of our compliance posture owing to SOC 2 Type II readiness and certification, driving ISO 27001 certification and ongoing ISMS maintenance, and supporting the broader Information Security Program across NIST CSF, NIST SP 800-53/800-171, CIS Controls, and PCI DSS. The ideal candidate brings an organized, project-managed approach to policy, risk, third-party oversight, audit readiness, and continuous compliance. Partnering closely with IT, SecOps, Legal, Internal Audit, and business stakeholders to protect the information assets owned by or entrusted to the Company.

Job Responsibility
  • Governance & Policy- Maintain and evolve the Company's information security policies, standards, and controls mapped to SOC 2, ISO 27001, NIST, and CIS frameworks; manage the policy exception process with documented justification and approval.
  • Risk Management- Conduct risk assessments, maintain the risk register, and support risk acceptance decisions with structured evidence; elevate material risks to leadership with mitigation plans.
  • Compliance & Audit Readiness- Own end-to-end audit preparation for SOC 2 Type II and ISO 27001 certification, including control testing, evidence collection, gap remediation, and findings tracking. Maintain the Company's ISMS, conduct Statement of Applicability (SoA) reviews, support internal audits and management reviews, and serve as the primary liaison with external certification bodies throughout the certification and surveillance audit lifecycle.
  • Control Implementation & Monitoring- Partner with IT and SecOps to operationalize controls across access management, encryption, logging, vulnerability management, and backup/DR; define evidence sources and test cadence.
  • Continuous Monitoring- Leverage GRC platform automated monitoring capabilities to maintain real-time visibility into control health; triage failing controls, coordinating remediation with owners, and ensure evidence remains audit-ready throughout the observation period.
  • Evidence Collection & Management - Maintain a structured evidence repository (e.g., SharePoint, GRC platform) to support SOC 2 Type II and ISO 27001 audit cycles; coordinate evidence requests from external auditors, establish and enforce evidence collection cadences (monthly, quarterly, and annual), and ensure completeness and integrity of the evidence package throughout the audit observation period.
  • Third-Party Risk Management (TPRM) - Manage the third-party risk management program including vendor risk assessments, security questionnaires (SIG/CAIQ), contract review support, and ongoing monitoring of critical vendors to ensure alignment with the Company's security and compliance requirements.
  • Change Management & Control Lifecycle - Manage the full control lifecycle including new control design, change management, deprecation, and exception handling; ensure all control changes are documented, reviewed, and aligned with SOC 2 Type II and ISO 27001 audit requirements.
  • Stakeholder Communications & Training - Develop and deliver control owner training, security awareness materials, and compliance guidance to drive adoption of security controls across business units; serve as a trusted advisor to cross-functional teams on GRC-related obligations and best practices.
  • Metrics & Reporting - Produce dashboards and status reports on risk posture, control health, and audit readiness for both technical teams and executive/Board-level stakeholders.
  • Operational Support- Support incident response, BCP/DR planning, and privacy obligations; publish practical guidance and job aids to drive control adoption across the organization.
Job Responsibilities Cont.
Education Required

Bachelor’s degree in Information Security or equivalent experience.

Experience Required
  • 3–5+ years of experience in information security GRC, compliance, or audit roles.
  • Hands-on experience withSOC 2 Type IIaudits (as auditee, control owner, or auditor).
  • Working knowledge ofSOC 2, ISO 27001, NIST CSF, NIST SP 800-53, and CIS Controls.
  • Experience maintaining risk registers, conducting risk assessments, and managing remediation tracking.
  • Strong written communication skills - ability to produce clear policy documents, audit evidence packages, and executive-level reports.
  • Demonstrated ability to manage multiple workstreams with a project-managed approach.
  • Experience with GRC platforms.
Knowledge Required

Excellent written and verbal communications skills; adaptability and flexibility to changing environment; and comfortable working in a dynamic, high volume, fast-paced environment. Ability to understand and ensure compliance with policies, procedures, and laws governing our industry/business and products.

Preferred Qualifications:

  • Experience infinancial services, fintech, or consumer lendingenvironments.
  • Familiarity withPCI DSSrequirements and control environments.
  • Certifications: CISA, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent.
  • Exposure to privacy frameworks (GLBA, CCPA, state-level financial privacy regulations)
  • Ability to work collaboratively with cross-functional teams and influence stakeholders.
Physical Requirements

Sitting for long periods of time; standing occasionally; walking; bending; squatting; kneeling; pushing/pulling; reaching; twisting; frequent lifting of less than 10 lbs., occasional lifting of up to 20 lbs.; driving and having access during the workday to an insured and reliable transportation; typing; data entry; grasping; transferring items between hands and/or to another person or receptacle; use of office equipment to include computers; ability to travel to, be physically present at, and complete the physical requirements of the position at any assigned location.

OKR

Travel

0-10%

Attire

Business Casual

Other

Must be eligible to work in the USA and able to pass a background check

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.
Requisition ID: 46682


Nearest Major Market: Greenville
Nearest Secondary Market: South Carolina

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Data Quality Analyst
Data Quality Analyst

Advance America, Cash Advance Centers, Inc. • Greenville (SC)

On-site
USD 70,000 - 95,000
Competitive wages
401(k) with company match
Paid holidays
+5
Service Desk Manager
Service Desk Manager

Advance America, Cash Advance Centers, Inc. • Greenville (SC)

On-site
USD 65,000 - 92,000
Competitive Wages
401(k) Savings Plan with Company Match
Company Paid Holidays
+5
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
GRC Cybersecurity Analyst III
GRC Cybersecurity Analyst III

ICCU • Meridian (ID), Chubbuck (ID)

On-site
USD 105,000 - 150,000
Senior Site Reliability Engineer - AWS, Kubernetes & CI/CD
Senior Site Reliability Engineer - AWS, Kubernetes & CI/CD

Advance America, Cash Advance Centers, Inc. • Greenville (SC)

On-site
USD 110,000 - 160,000
Competitive Wages
401(k) Plan with Company Match
Company Paid Holidays
+5
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE Vernova • United States

On-site
USD 85,000 - 120,000
Relocation assistance
Information Security Analyst (Greenville)
Information Security Analyst (Greenville)

Southern First Bank • Greenville (SC)

On-site
USD 70,000 - 110,000
Corporate Counsel
Corporate Counsel

Advance America, Cash Advance Centers, Inc. • Greenville (SC)

On-site
USD 170,000 - 250,000
Competitive wages
401(k) match
Paid holidays
+5
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000