Junior Information Security – Compliance Analyst

Job not on LinkedIn

🔥 13 minutes ago

⛷️ Utah – Remote

infoinfo

💵 $55k - $70k / year

⏰ Full Time

🟢 Junior

🔐 Security Analyst

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Veracity Insurance Solutions, LLC

Veracity Insurance Solutions, LLC

51 - 200 employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

Veracity Insurance Solutions, LLC is a national excess & surplus (E&S) wholesale brokerage and managing general agent that provides in-house underwriting and binding authority with A-rated carriers. The firm specializes in product liability, general liability, professional liability and property insurance across niche sectors (beauty & cosmetics, vitamins & supplements, e-cigarettes/vape, CBD/hemp, sporting goods, consumer and industrial products) and offers program management, risk purchasing group (RPG) management, surplus lines filing, licensing and compliance services for retail agents and businesses nationwide. Veracity is licensed in all 50 states and emphasizes fast turnaround, tailored specialty programs, and broker-focused distribution.

📋 Description

• Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana; triage, document disposition, and escalate per established runbooks • Run recurring vulnerability scans across cloud, endpoint, and application surfaces; maintain remediation tracking and verify findings are closed within SLAs • Triage employee-reported phishing and security questions and escalate confirmed issues • Support incident response as first responder and scribe; capture timelines, preserve evidence, maintain ticket hygiene, and draft post-incident summaries • Maintain security tooling coverage including MFA enrollment, endpoint agents, logging agents, and email security • Execute user access provisioning, role changes, and deprovisioning for onboarding and termination • Run quarterly user access reviews and document exceptions and completed evidence • Enforce least-privilege and role-based access practices; maintain privileged, service, and third-party access records • Collect and maintain audit evidence for SOC 2 and PCI DSS • Support SOC 2 and PCI DSS audit cycles and auditor communications • Maintain the policy and procedure library, review calendar, approval records, and employee attestations • Support vendor risk assessments and maintain the vendor inventory • Perform assigned internal control testing and document results • Draft customer and carrier security questionnaire responses for review • Maintain the asset inventory and security awareness training program • Build and maintain security and compliance metrics reporting • Write and maintain runbooks, SOPs, and checklists • Partner with IT, Engineering, Compliance, Legal, and Service teams • Identify repetitive tasks that can be automated or streamlined and propose improvements • Perform other duties as requested, directed, or assigned

🎯 Requirements

• 0–2 years of professional experience; internships, IT helpdesk or support, systems administration, or audit and compliance support count • Bachelor's degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or a relevant certification in lieu of a degree • Working familiarity with at least one major cloud or productivity platform: AWS, Microsoft 365/Azure, or Google Workspace, including where users, permissions, and logs live • Ability to own recurring, detail-heavy work to completion without reminders • Comfort with spreadsheets, ticketing systems such as Jira, and documentation tools • Excellent verbal and written communication skills • Sound judgment and discretion handling sensitive, regulated, and confidential information including customer PII and NPI • Coachability and genuine curiosity about security • Composure under pressure during audits, incidents, and deadlines

🏖️ Benefits

• Health, dental, and vision plans • 4 weeks of Paid Time Off • 10 Paid Company Holidays with 2 floating holidays • 401K Programs with employer match • Personal assistance programs for support in a healthy personal and work life • Engage in groundbreaking projects that are reshaping the insurance landscape • Collaborate with a group of dedicated, like-minded professionals • Experience a culture that prioritizes growth and development

Apply Now

Similar Jobs

🔥 3 hours ago

ShorePoint Inc

1 - 10

💼 Consulting

🏥 Healthcare

📦 Logistics

Security Compliance Analyst supporting ShorePoint’s cybersecurity services for federal customers. Managing FISMA, RMF, ATO, ICAM compliance documentation, audits, and continuous monitoring.

🔥 13 hours ago

Gifthealth

501 - 1000

🏥 Healthcare

📦 Logistics

💼 Consulting

Information Security Analyst protecting Gifthealth’s prescription and healthcare services platform. Monitoring threats, managing vulnerabilities, and coordinating incident response across business teams.

🇺🇸 United States – Remote

💵 $73k - $86k / year

💰 $40M Private Equity Round - GiftHealth on 2023-04

⏰ Full Time

🟢 Junior

🟡 Mid-level

🔐 Security Analyst

🚫👨‍🎓 No degree required

🕒 Yesterday

USG

5001 - 10000

🏗️ Construction

🏭 Manufacturing

Identity and access security analyst supporting SailPoint governance, IAM lifecycle controls, SSO, and MFA. USG manufactures wall, ceiling, flooring, sheathing, and roofing products.

🕒 September 11

Tusker

201 - 500

🚘 Automotive

👥 HR Tech

🤝 B2B

Cyber Security Analyst I monitoring alerts and investigating threats for Tusker’s managed security services clients. Supporting incident response, endpoint security, and security investigations on a four-day schedule.

🕒 September 10

EnableComp

501 - 1000

💼 Consulting

🛡️ Insurance

📦 Logistics

Information Security Analyst securing systems and compliance for EnableComp’s healthcare revenue cycle management platform. Managing audits, access reviews, vendor assessments, and emerging cyber-threat monitoring.