Junior Information Security & Compliance Analyst

Veracity Insurance Solutions

Pleasant Grove (UT)

On-site

USD 55,000 - 70,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health, dental, and vision plans
4 weeks Paid Time Off
10 company holidays with 2 floating
401K with employer match
Personal assistance programs

Job summary

Veracity Insurance Solutions in Pleasant Grove, Utah is seeking a Junior Information Security & Compliance Analyst. The role supports the security and compliance program, automating recurring tasks and maintaining audit-ready records across SOC 2 and PCI DSS.

You'll gain hands-on experience with cloud platforms, security tooling, and audits, while partnering with IT, Legal, and Compliance teams. Ideal for an early-career professional with 0–2 years in security, a relevant degree, and the desire

Qualifications

  • 0–2 years of professional experience in security, internships or support count.
  • Bachelor's degree in Information Systems, IT, Cybersecurity, or related field, or equivalent experience.
  • Familiarity with at least one major cloud or productivity platform (AWS, M365/Azure, or Google Workspace).
  • Ability to own recurring, detail-heavy work to completion without reminders.
  • Comfort with spreadsheets, Jira, and documentation tools.
  • Excellent verbal and written communication for audits and records.
  • Discretion handling sensitive information including customer PII/NPI.
  • Coachability and curiosity about security, open to learning.
  • Composure under pressure during audits, incidents, and deadlines.
  • Health, dental, and vision plans; competitive time off; and 401K.
  • Paid time off and holidays support work-life balance.
  • Employer matching 401K and personal assistance programs.

Responsibilities

  • Monitor security dashboards, alerts, and logs across AWS, M365, Google Workspace, Grafana.
  • Run recurring vulnerability scans across cloud, endpoint, and apps; manage remediation tracker.
  • Serve as first-line triage for phishing and security questions; escalate with context.
  • Support incident response as first responder and scribe; draft post-incident notes.
  • Maintain security tooling health: MFA, agents, logging, and email security; report gaps.
  • Execute user access provisioning, role changes, and deprovisioning; ensure same-day removal.
  • Run quarterly access reviews; pull reports, chase responses, document evidence.
  • Enforce least-privilege and RBAC; flag orphaned accounts for remediation.
  • Maintain records of privileged/service/third-party accounts across units.
  • Collect and refresh audit evidence for SOC 2 and PCI DSS; support auditor requests.
  • Support SOC 2 and PCI DSS audits—track requests and prepare materials.
  • Maintain policy library, annual review calendar, approvals, and attestation tracking.
  • Support vendor risk assessments; collect SOC 2 reports and DPAs; flag gaps.
  • Perform internal control testing with evidence under senior guidance.
  • Draft responses to security questionnaires for review by the analyst.
  • Maintain asset inventory and security awareness training with completion tracking.
  • Build and maintain security metrics: vulnerabilities, SLA, access reviews, training.
  • Write runbooks, SOPs, and checklists for repeatable work.
  • Partner with IT, Engineering, Compliance, Legal, and Service teams for consistency.
  • Identify tasks to automate or streamline and propose improvements.
  • Other duties as assigned.

Skills

Detail-oriented
Communication skills
Coachability
Auditing mindset
Team collaboration
Problem solving

Education

Bachelor's degree in Information Systems / IT / Cybersecurity

Tools

AWS
Microsoft 365 / Azure
Google Workspace
Grafana
Jira

Job description

Junior Information Security & Compliance Analyst

Veracity Insurance Solutions Pleasant Grove, Utah, United States

About this position

At Veracity, we aim to be a different kind of insurance partner – one that is free from outside investors, venture capital, or the pressures of a corporate parent.

Ours is a culture of empowerment – one that believes in effort, results, and accountability. We believe that transparency fosters trust, trust fosters growth, and that growth drives innovation. Our commitment to rigorous evaluation and relentless execution lead to rapid evolution.

We answer only to the small business owners we serve, and this independence allows us to stay focused on what matters most: helping their businesses thrive by providing expert guidance and best‑class insurance policies.

We’re growing fast and want you to be a part of it!

We’re seeking a precise, persistent, and coachable Junior Information Security & Compliance Analyst to join our team. Reporting to the Information Security & Compliance Analyst, this role is the execution engine of Veracity's security and compliance program – carrying the recurring, deadline‑driven work that keeps the program credible and audit‑ready across Veracity, Insurance Canopy, and InsCipher.

This is a deliberately structured entry‑level role – the incumbent is not expected to arrive with deep security experience, but is expected to be precise, persistent, and coachable, and to build real technical and audit depth on the job. Over time, this person should take full ownership of the recurring compliance calendar and become the company's second line of security response.

Key Responsibilities
  • Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and elevate per established runbooks
  • Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow‑up with system owners, and verify and close findings within defined SLAs
  • Serve as first‑line triage for employee‑reported phishing and security questions – escalating confirmed issues promptly with context already gathered
  • Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post‑incident summary and lessons learned for senior review
  • Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps
  • Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same‑day removal of access for departures
  • Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence
  • Enforce least‑privilege and role‑based access practices in day‑to‑day requests – flagging standing privileges and orphaned accounts for remediation
  • Maintain accurate records of privileged accounts, service accounts, and third‑party access across business units
  • Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently
  • Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff
  • Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking
  • Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review
  • Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff
  • Draft responses to customer and carrier security questionnaires and diligence requests for review by the Information Security & Compliance Analyst
  • Maintain the asset inventory and security awareness training program including completion tracking and follow‑up with non‑completers
  • Build and maintain security and compliance metrics reporting – open vulnerabilities, SLA performance, access review status, and training completion
  • Write and maintain runbooks, SOPs, and checklists for recurring work so that it is repeatable and transferable
  • Partner with IT, Engineering, Compliance, Legal, and Service teams so that controls are applied consistently without unnecessary friction to the business
  • Identify repetitive security and compliance tasks that can be automated or streamlined and propose improvements
  • Required to perform other duties as requested, directed, or assigned
Requirements and Qualifications
  • 0–2 years of professional experience – internships, IT helpdesk or support, systems administration, or audit and compliance support all count; this role is intended to be a first or second job in security
  • Bachelor's degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or a relevant certification in lieu of a degree
  • Working familiarity with at least one major cloud or productivity platform – AWS, Microsoft 365/Azure, or Google Workspace – including where users, permissions, and logs live
  • Demonstrated ability to own recurring, detail‑heavy work to completion without reminders
  • Comfort with spreadsheets, ticketing systems such as Jira, and documentation tools
  • Excellent verbal and written communication skills – able to ask a busy system owner for evidence and actually get it, and to write documentation an auditor will accept
  • Sound judgment and discretion handling sensitive, regulated, and confidential information including customer PII and NPI
  • Coachability and genuine curiosity about security – willing to be taught and willing to say "I don't know" early rather than let an item quietly slip
  • Composure under pressure during audits, incidents, and deadlines
  • Health, dental, and vision plans
  • Amazing work‑life balance with 4 weeks of Paid Time Off
  • 10 Paid Company Holidays with 2 floating holidays
  • 401K Programs with employer match
  • Personal assistance programs for support in a healthy personal and work life
Why Veracity?

Here at Veracity, you’ll be part of a team of trailblazers and visionaries. We’re not just revolutionizing the way people “do” insurance; we are creating a whole new paradigm. Here, you will experience a vibrant and inclusive workplace where your ideas matter! With us, you have a chance to:

  • Engage in groundbreaking projects that are reshaping the insurance landscape
  • Collaborate with a group of dedicated, like‑minded professionals
  • Experience a culture that prioritizes growth and development
Compensation Range

$55k/yr - $70k/yr

We are proud to be an equal‑opportunity employer. We are committed to providing equal opportunities to all qualified applicants, regardless of race, color, religion, sex, national origin, disability, or any other legally protected characteristics.

If you need accommodation, please let us know during the interview process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Information Security & Compliance Analyst
Junior Information Security & Compliance Analyst

Veracity Insurance Solutions, LLC • Pleasant Grove (UT)

On-site
USD 55,000 - 70,000
Health, dental, and vision plans
4 weeks paid time off
10 holidays + 2 floating holidays
+2
Junior Information Security & Compliance Analyst
Junior Information Security & Compliance Analyst

Socket.dev • Utah

Hybrid
USD 55,000 - 70,000
Health plan
Dental plan
Vision plan
+4
Software Engineering Manager
Software Engineering Manager

Veracity Insurance Solutions, LLC • United States

Hybrid
USD 150,000 - 180,000
Health, dental, and vision plans
401K Programs with employer match
4 weeks of Paid Time Off
+1
Atlassian System Administrator
Atlassian System Administrator

Veracity Insurance • Northern (KY)

Hybrid
USD 85,000 - 100,000
Health insurance
Dental plan
Vision plan
+2
Lead AI Engineer
Lead AI Engineer

Veracity Insurance Solutions • Pleasant Grove (UT)

On-site
USD 200,000 - 220,000
Health, dental, vision plans
4 weeks paid time off
401(k) with employer match
+1
Partner Development Associate
Partner Development Associate

Veracity Insurance Solutions • Pleasant Grove (UT)

Remote
USD 42,000
Health, dental, and vision plans
4 weeks of Paid Time Off
401K Programs with employer match
Product Marketing Manager
Product Marketing Manager

Socket.dev • Utah

Hybrid
USD 105,000 - 115,000
Health, dental, and vision plans
4 weeks of Paid Time Off
10 Paid Company Holidays
+2
Entry-Level Information Security & Compliance Analyst
Entry-Level Information Security & Compliance Analyst

Veracity Insurance Solutions • Pleasant Grove (UT)

On-site
USD 55,000 - 70,000
Health, dental, and vision plans
4 weeks Paid Time Off
10 company holidays with 2 floating
+2
Sr. Information Security Analyst (SOC/SIEM (Splunk, CrowdStrike, Scripting)
Sr. Information Security Analyst (SOC/SIEM (Splunk, CrowdStrike, Scripting)

Vertafore • Denver (CO)

On-site
USD 16,000 - 25,000
Medical, vision & dental plans
401(k) Retirement Savings Plan with 1:
Employee Assistance Program (EAP)
+2
Administrative Assistant
Administrative Assistant

Veracity Insurance Solutions • Pleasant Grove (UT)

On-site
Health, dental, and vision plans
4 weeks Paid Time Off
401K Programs with employer match
+1