Sr. Analyst, IT Security, Risk & Compliance

Prosum

Irvine (CA)

Hybrid

USD 125,000 - 145,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model (2 days onsite)
Annual bonus (up to 10%)

Job summary

Prosum is seeking a hands-on IT Security, Risk & Compliance professional in Irvine, CA. This hybrid role gives you ownership to build and mature our security program as we implement a practical framework.

You will operate the ISMS, manage controls, risk registers, audits, and remediation. Collaborate with internal teams, third-party security partners, and the global parent organization to advance security posture.

Qualifications

  • 5+ years of hands-on IT security, risk, and compliance experience.
  • Experience with security controls, audits, risk assessments, remediation and testing.
  • Familiarity with ISO 27001, NIST, SOC 2 or SOX ITGC.
  • Strong documentation, coordination, and communication skills.
  • Ability to operate independently in a evolving security program.

Responsibilities

  • Own day-to-day operation of the IT security and GRC program.
  • Operate ISMS, security controls, risk register, compliance activities, and control calendar.
  • Coordinate control testing, access reviews, assessments, audit readiness.
  • Gather audit evidence, maintain docs, drive remediation.
  • Investigate security incidents and vulnerabilities, coordinate response.
  • Collaborate with stakeholders, vendors, and global parent organization.
  • Develop and maintain security policies, SOPs, playbooks, narratives.
  • Track security awareness and program health.
  • Identify opportunities to mature the security program.

Skills

IT Security
GRC
Security Controls
Risk Assessments
Audit & Compliance
Incident Response
Cloud Security
IAM

Tools

ISO 27001
NIST
SOC 2
SOX ITGC

Job description

Irvine, CA | Hybrid - 2 days/week onsite | $125K-$145K + 10% bonus

We're looking for a hands-on IT Security, Risk & Compliance professional to join a fast-growing, consumer-focused company that is actively building and maturing its security program.

This is a great opportunity for someone who wants real ownership and impact. The security/GRC framework is being built today, so you'll have the opportunity to come in during the implementation phase and help turn the framework into a practical, operational security program.

What You'll Do
  • Own the day-to-day operation and execution of the IT security and GRC program.
  • Operate and maintain the company's ISMS, security controls, risk register, compliance activities and control calendar.
  • Coordinate and execute control testing, access reviews, assessments and audit-readiness activities.
  • Gather and validate audit evidence, maintain documentation and drive findings through remediation and closure.
  • Investigate and coordinate the response to security incidents, vulnerabilities, access issues and security findings.
  • Work closely with internal stakeholders, third-party security partners, vendors and the company's global parent organization.
  • Develop and maintain security policies, SOPs, playbooks, control narratives and other security documentation.
  • Track security awareness, phishing education, compliance activities, remediation and overall security program health.
  • Identify opportunities to improve and mature the security program over time.
What They're Looking For
  • 5+ years of experience in IT Security, GRC, Information Security, Security Compliance or a related area.
  • Hands-on experience with security controls, audits, risk assessments, compliance, remediation and control testing.
  • Experience with one or more frameworks such as ISO 27001, NIST, SOC 2 or SOX ITGC.
  • Strong understanding of Microsoft 365, Entra ID/Azure AD, endpoint management, IAM, cloud security and security operations.
  • Experience investigating or coordinating security incidents and vulnerability remediation.
  • Strong documentation, organization, communication and follow-through skills.
  • Someone who can work independently, navigate ambiguity and figure things out without needing constant direction.
Why This Opportunity?

This isn't a role where you'll simply maintain someone else's mature security program.

The company is actively building its security/GRC framework, giving you the opportunity to help establish how the program operates, take ownership of the controls and processes, and play a meaningful role in its continued maturity.

You'll also work in a highly cloud-based, technology-driven environment with significant exposure to third-party technology and security partners and a global parent organization.

If you're a security/GRC professional who enjoys ownership, problem-solving and building something rather than simply maintaining it, this could be an excellent opportunity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hybrid IT Security & GRC Lead — Own & Build the Program
Hybrid IT Security & GRC Lead — Own & Build the Program

Prosum • Irvine (CA)

Hybrid
USD 125,000 - 145,000
Hybrid work model (2 days onsite)
Annual bonus (up to 10%)
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Snr GRC Analyst
Snr GRC Analyst

Tiro Security, LLC • California (MO)

On-site
USD 100,000 - 150,000
Sr. Security Engineer/Analyst (GRC)
Sr. Security Engineer/Analyst (GRC)

Insight Global • United States

Hybrid
USD 120,000 - 160,000
Head of Information Security and GRC
Head of Information Security and GRC

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity
Sr. GRC Analyst
Sr. GRC Analyst

TriCom Technical Services • Overland Park (KS)

On-site
USD 100,000 - 140,000
Low-cost employee benefits
Paid time off
Paid Holidays
+1
GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 150,000
Lead GRC Security Engineer
Lead GRC Security Engineer

Lorien • United States

Remote
USD 165,000 - 240,000
Information Security Sr Anlyst
Information Security Sr Anlyst

TALENT Software Services • Cary (NC)

On-site
USD 100,000 - 130,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices