Sr. Information Security Analyst
Betterment · Betterment HQ - New York City
About this role
**About Betterment** Betterment is a leading, technology-driven financial services company offering investing, savings, and retirement solutions for retail investors and investment advisors, plus financial wellness solutions (including a 401(k) for small and medium-sized businesses). We’re headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays). **About the Role** We’re seeking a **Senior Information Security** professional with deep experience in **governance, risk, and compliance** to serve as a senior individual contributor on our **Govern & Control** team. You’ll own and mature risk management processes that underpin the trust we hold with clients, investors, and regulators, and help raise the bar for analysts around you. This role is a small, independent **second line-of-defense** function integrated with the broader security program. You’ll report to the **Director of Information Security** and partner closely with Security Engineering, Engineering, business leaders, and other risk functions including **Compliance** and **Legal**. **Base Salary (NYC)** - **$170,000–$185,000** This role may also be eligible for **variable compensation** in the form of a company incentive bonus. **A Day in the Life** - Lead major program areas (e.g., vulnerability management, third-party risk, identity theft oversight, business continuity/disaster recovery, or issues management) with limited supervision; accountable for outcomes and OKRs. - Lead end-to-end risk assessment processes, including high-stakes ones; document summarized risk conclusions substantiated by data. - Design and document complex internal controls (including reports/automation); drive leverage of AI and automation tooling. - Provide effective challenge to Engineering partners and partner with Compliance and Security Engineering to mature risk processes and reduce risk. - Measure risk using professional judgment and quantifiable methods; drive decisions on accepting or treating risk within appetite. - Author high-quality updates to policies/procedures; own program-level and KRI reporting to leadership and governance committees (may serve as Chair/Secretary). - Act as escalation point and reviewer for junior analysts to improve consistency and quality. - Track regulatory changes and industry trends; map them to Betterment’s business and stay engaged in the professional community. **What We’re Looking For** **Required** - **6+ years** in security GRC, technology risk, technology audit, or security operations, including demonstrated senior-level ownership. - Expert depth in at least one security domain (e.g., vulnerability management, SDLC, application security, or cloud computing) with broad horizontal skills (**T-shaped** profile). - Strong, hands-on security risk management knowledge: **CIA triad**, control design/operation, and one or more control governance frameworks (e.g., **SOC 2, ISO 27001, NIST CSF**). - Strong command of security controls for **cloud computing** and **third-party SaaS** (logical access management, third-party due diligence & ongoing monitoring, vulnerability governance). - Fluency in audit reports and risk assessments, including control testing with appropriate sampling and results reporting. - Ability to use quantifiable methods to measure risk and drive stakeholders to sound risk acceptance/treatment decisions within appetite. - Strong cross-disciplinary
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.