Turn this role into an interview — a resume and cover letter built around what this employer wants.
Valon Mortgage is seeking a Sr. Security Analyst to join our growing security team. You will work closely with the Head of Security GRC to protect our systems, data, and cloud infrastructure across the organization.
You will implement frameworks (SOC 2, NIST CSF, CIS), support audits, manage risk registers, and build AI-assisted GRC workflows to scale security and compliance across functions. Maintain security metrics, KPIs, and collaborate with cross-functional teams to reduce risk and
Experience or exposure to startup environments is a plusProven experience in a security analyst related role, with a focus on security compliance, risk management, security issue management, and/or security program managementBasic knowledge of cloud security and public cloud environmentsStrong organization and project management skillsSelf-starter that can work autonomously, be agile, and balance multiple projects and operational effortsExcellent communication and collaboration skills, with the ability to explain security concepts to technical and non-technical stakeholdersExperience or exposure to financial services or tech organizations is a plusExperience maintaining a security risk register and issue management processesExperience developing, automating, and scaling security and GRC processes leveraging AI tools / agentic capabilitiesExperience with security and compliance frameworks and requirements (OWASP, SOC 2, NIST CSF / 800-53, ISO 27001/2, CIS, NYDFS, CCPA or others.)Bachelor’s degree in Computer Science, Information Security, Technology, or a related fieldExperience with operational activities including issue management, security reviews, control monitoring, incident management, and reportingExperience with security compliance frameworks and risk assessmentsHand-on experience with AI tooling and assisted workflowsMinimum of 5+ years as a security analyst or security program manager with relevant responsibilities and backgroundRelevant security certifications based on career experience (CompTIA Security+, CC, SSCP or related), or seasoned career level (CISSP, CISM, CRISC or related)