GRC Security and Access Governance Risk Analyst
4 weeks ago
About DailyPay
DailyPay is a leading on-demand pay solution that helps America's top employers build stronger relationships with their employees. Our award-winning technology platform enables workers to feel more motivated to work harder and stay longer on the job, while supporting their financial well-being outside of the workplace.
As a GRC Security Analyst at DailyPay, you will play a crucial part in ensuring compliance with regulatory requirements and protecting sensitive data. You will assess, analyze, and mitigate risks associated with the organization's information security posture, as well as access to information systems.
Key Responsibilities
- Risk Assessment
- Analyze access privileges, segregation of duties, and other control mechanisms to identify potential risks
- Conduct regular risk assessments to identify and evaluate potential threats and vulnerabilities
- Analyze security controls, policies, and procedures to identify gaps and weaknesses
- Develop risk matrices and prioritize risks based on likelihood and impact
- Compliance Management
- Ensure compliance with relevant regulatory and industry frameworks (e.g. SOC2, ISO 27001, PCI DSS, SOX 404, GDPR, CCPA)
- Develop and maintain compliance documentation and evidence
- Policy Development and Enforcement
- Assist in the development, implementation, and maintenance of information security policies including building relevant procedures to meet policy objectives
- Ensure adherence to established policies and procedures by conducting regular audits and reviews
- Identify and address non-compliance issues
- Access Review and Certification
- Oversee periodic access reviews to ensure that individuals have appropriate access privileges based on their roles and responsibilities
- Certify access reviews and recommend changes as needed
- Security Controls
- Assist in the development, implementation, and maintenance of security controls
- Review and evaluate the effectiveness of existing controls
- Identify and address control deficiencies
- Identity and Access Management (IAM)
- Collaborate with the IAM team to ensure effective management of user identities and access privileges
- Assist in the implementation and maintenance of IAM systems and processes
- Incident Response
- Contribute to incident response plans and procedures related to information security incidents
- Assist in the investigation and remediation of security incidents
What We Offer
- Exceptional health, vision, and dental care
- Opportunity for equity ownership
- Life and AD&D, short- and long-term disability
- Employee Assistance Program
- Employee Resource Groups
- Fun company outings and events
- Unlimited PTO
- 401K with company match
Pay Transparency
DailyPay takes a market-based approach to compensation, which may vary depending on your location. United States locations are categorized into three tiers based on a cost of labor index for that geographic area. The salary ranges are listed by geographic tier. Additionally, this role may be eligible for variable incentive compensation and stock options. Where a candidate fits within the compensation range for a role is based on their demonstrated experience, qualifications, skills, and internal equity.
New York City: $111,000—$144,000 USD
Remote, Premium (California, Connecticut, Washington D.C., New Jersey, New York, Massachusetts, Washington): $102,000—$133,000 USD
Remote, Standard: $97,000—$126,000 USD
DailyPay is committed to fostering an inclusive, equitable culture of belonging, grounded in empathy and respect, which values openness to opinions, awareness of lived experiences, fair treatment and access for all. We strive to build and develop diverse teams to create an organization where innovation thrives, where the full potential of each person is engaged, and their views, beliefs and values are integrated into our ways of working.
We encourage people of all backgrounds to join us on our mission. If you require reasonable accommodation for any aspect of the recruitment process, please send a request to peopleops@dailypay.com. All requests for accommodation will be addressed as confidentially as practicable.
DailyPay is an equal opportunity employer. All qualified applicants will receive consideration without regard to race, color, religion or creed, alienage or citizenship status, political affiliation, marital or partnership status, age, national origin, ancestry, physical or mental disability, medical condition, veteran status, gender, gender identity, pregnancy, childbirth (or related medical conditions), sex, sexual orientation, sexual and other reproductive health decisions, genetic disorder, genetic predisposition, carrier status, military status, familial status, or domestic violence victim status and any other basis protected under federal, state, or local laws.
-
Security Risk Analyst
4 weeks ago
New York, New York, United States RIT Solutions, Inc. Full timeJob Summary:The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the technology-focused analysts, engineers and administrators in the IT organization. The Security Risk Analyst must be able to translate the IT-risk requirements and constraints of the business into technical control...
-
Cyber Security Analyst
4 weeks ago
New York, New York, United States Intelligent Staffing Full timeJob Summary:Cyber Security Analyst - Risk and Complianceis responsible for reviewing, monitoring, and resolving security findings within an organization. This role involves conducting risk and vulnerability assessments, validation testing, compliance reviews, and audits following NIST standards. The ideal candidate will have expertise in conducting ISO 27001...
-
Security Risk Analyst
4 weeks ago
New York, New York, United States Innova Solutions Full timeJob Title: Security Risk AnalystJob Summary:Innova Solutions is seeking a highly skilled Security Risk Analyst to join our team. As a Security Risk Analyst, you will be responsible for translating IT-risk requirements and constraints of the business into technical control requirements and specifications. You will also develop metrics for ongoing performance...
-
New York, New York, United States Bell Soft LLC Full timeJob Title: Cyber Security GRC Specialist with Vendor Risk Assessment ExpertiseJob Description:We are seeking a highly skilled Cyber Security GRC Specialist with expertise in Vendor Risk Assessment to join our team at Bell Soft LLC.Key Responsibilities:* Ensure vendor security architecture and design meets firm policies, external guidelines, and regulatory...
-
Risk Management Analyst
4 weeks ago
New York, New York, United States Crdit Agricole S.A. Full timeJob Title: US Operations Risk AnalystJob Summary: We are seeking a highly motivated and detail-oriented US Operations Risk Analyst to join our Risk Division in New York. As a key member of the CUSO Operational Risk Team, you will assist in the oversight of the effectiveness of operational risk management and third-party risk management within the CUSO...
-
IT Risk Management Strategist
4 weeks ago
New York, New York, United States Hispanic Technology Executive Council Full timeWe care and make a positive difference.IT Governance, Risk, and Compliance Strategy LeadThe IT Governance, Risk, and Compliance Strategy Lead will drive the strategic IT GRC division's vision, operating model, budget, and planning activities, and outcomes for the division, which is part of the Information Risk and Cybersecurity (IRC) department.Key...
-
Senior Technology Risk Analyst
4 weeks ago
New York, New York, United States FanDuel Full timeAbout FanDuelFanDuel Group is a leading sports-tech entertainment company that is revolutionizing the way consumers engage with their favorite sports, teams, and leagues.With a presence across all 50 states and approximately 17 million customers, FanDuel is a premier gaming destination in the United States.The company has a portfolio of leading brands across...
-
Senior Risk and Compliance Professional
4 weeks ago
New York, New York, United States Cantor Fitzgerald Securities Full timeJob Title: Sr. GRC AnalystAbout the Role:Cantor Fitzgerald Securities is seeking an experienced risk and compliance professional to join our Information Security-GRC Team. As a key member of our team, you will be responsible for driving efforts across Cybersecurity controls framework initiatives, including user access recertification, policy management,...
-
Director of Information Security and Governance
4 weeks ago
New York, New York, United States Rockstar Full timeAbout the RoleWe are seeking a highly experienced and strategic Information Security GRC Director to join our team at Rockstar Games.As a key member of our security team, you will be responsible for building and leading a team of security experts to drive key, strategic programs that mitigate risk in a scalable way.This is a full-time, in-office position...
-
Business Analyst IV
4 weeks ago
New York, New York, United States Saxon Global Full timeAt Saxon Global, we are seeking a skilled Governance, Risk and Controls (GRC) Business Analyst to support the Head of GRC in partnering with stakeholders across the three lines of defense to develop and articulate our governance, risk management and compliance controls framework, strategy, and ecosystem.This role will pursue agreement on a consistent...
-
Senior IT Security Risk Analyst
4 weeks ago
New York, New York, United States Fidelity Information Services Full timeAbout the RoleWe are seeking a highly skilled Senior IT Security Risk Analyst to join our team at Fidelity Information Services. As a key member of our Enterprise Risk Management team, you will be responsible for implementing the FIS enterprise risk management framework to ensure the business has robust risk management arrangements and adequate internal and...
-
Security Risk Analyst
3 weeks ago
New York, New York, United States Sumitomo Mitsui Banking Corporation Full timeAs a Security Risk Analyst with Sumitomo Mitsui Banking Corporation, you will play a crucial role in protecting the organization's sensitive data from unauthorized access. You will work closely with vendors and engineers to continuously improve the quality of data loss prevention detections, ensuring the integrity of our systems and data.Key responsibilities...
-
Information Security Risk Analyst
4 weeks ago
New York, New York, United States Children's Hospital Full timeAbout UsChildren's Minnesota is a leading pediatric health system in the United States, providing care exclusively to children from birth through young adulthood. As a not-for-profit organization, we are committed to delivering high-quality, patient-centered care to our community.Job SummaryWe are seeking an experienced Information Security Risk Analyst to...
-
IT Governance Specialist
4 weeks ago
New York, New York, United States LABINE AND ASSOCIATES, INC. Full timeJob SummaryAn IT Governance Analyst is sought by LABINE AND ASSOCIATES, INC. to perform a variety of tasks to accomplish the objectives including but not limited to the evaluation of IT governance, IT audits, security risks and Vendor Management.Key Responsibilities Lead discussions of vendor management with corporate department representatives, information...
-
Senior Risk Governance Specialist
4 weeks ago
New York, New York, United States Deutsche Bank Full timeJob Title: Model Risk Portfolio GovernanceAbout the Role:We are seeking a highly motivated and experienced professional to join our Model Risk Governance team as a Senior Risk Governance Specialist. In this role, you will contribute to a wide range of tasks centered on complex risk analysis and reporting.Key Responsibilities:Perform regular and ad hoc...
-
Enterprise Security Product Management Leader
4 weeks ago
New York, New York, United States Intuit Inc Full timeProduct Management Leader OpportunityWe are seeking an experienced Product Management leader to join our CyberCRAFT Product Management organization and drive our Enterprise Security & Compliance product strategy and execution across key domains, including Governance, Risk, and Compliance (GRC), Application Security, Third Party Security, Workforce Identity,...
-
Senior Civil Engineer
4 weeks ago
New York, New York, United States Gedeon GRC Consulting Full timeSenior Civil Engineer - Project LeadGedeon GRC Consulting is seeking a highly skilled Senior Civil Engineer to lead our project teams in creating detailed designs for civil projects. This role requires strong leadership and coordination skills to ensure projects are completed on time and within budget.Responsibilities:Develop and implement project plans to...
-
Cyber Security Engineer
4 weeks ago
New York, New York, United States TherapyNotes Full timeAbout TherapyNotesTherapyNotes is a leading provider of behavioral health Practice Management and EHR software. Our cutting-edge SaaS solution handles scheduling, billing, documenting, telehealth, and more, allowing clinicians to focus on patient care.Our TeamWe're a dynamic team of professionals who love to innovate and push the envelope, keeping our...
-
Senior Risk and Compliance Professional
4 weeks ago
New York, New York, United States Cantor Fitzgerald Full timeThe Information Security-GRC Team at Cantor Fitzgerald is seeking a seasoned risk and compliance professional to drive initiatives across Cybersecurity controls framework. This role will focus on user access recertification, policy management, vendor assessment, and client due diligence. The successful candidate will also contribute to Cantor's Cybersecurity...
-
Quantitative Analyst
4 weeks ago
New York, New York, United States Citigroup Inc Full timeJob Title: Quantitative Analyst - Markets Risk ModelingJob Summary:We are seeking a highly skilled Quantitative Analyst to join our Markets Quantitative Analysis team in New York City. As a Quantitative Analyst, you will be responsible for developing and maintaining complex models to assess risk on RMBS and CMBS securities. You will work closely with senior...