Senior Security Analyst Customer Assurance
Summary
Owns security contract reviews for fintech customers, defining defensible positions, building scalable processes, and responding to questionnaires while leveraging AI-assisted workflows.
You own the Security Contracts workstream, reviewing customer security provisions, defining defensible security positions, building scalable review processes, analyzing contract patterns, managing program metrics, developing AI-assisted workflows, responding to questionnaires, and supporting customer audit calls.
Responsibilities
- Lead security contract reviews
- Shape the security contract review strategy
- Design intake processes, tiered SLAs, runbooks, and handoff protocols
- Track security contract requests and identify recurring patterns
- Join customer and data partner calls as a security subject matter expert
- Define KPIs and report on program health
- Build AI-assisted workflows for security assurance and reporting
- Respond to customer security questionnaires
- Support external audit calls
Requirements
- Review security provisions in MSAs, DPAs, and security addenda
- Understand incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions
- Translate security posture and risk appetite into defensible contract positions
- Represent security programs to customers and financial institution partners
- Understand SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, and NIST 800-53
- Have experience in fintech, payments, or financial services
- Build security trust enablement programs, intake processes, tiered SLAs, escalation paths, and runbooks
- Define KPIs, build tracking infrastructure, and report on program health
- Communicate effectively with Legal and go-to-market teams
- Build and scale AI-assisted workflows
- Experience redlining security contract language is a plus
Benefits
- Equity
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)