careertakescareertakes

Information Security Analyst II (GRC)

Confidential ClientFinancial Services
Entry LevelFull-timeOn-Site$78,068 - $97,585
Superior, Colorado
14 Hours Ago

The Information Security Analyst II (GRC) at Confidential Client is responsible for executing and maintaining the organization's Governance, Risk, and Compliance program within the Information Security team. This role involves ensuring regulatory compliance, conducting risk assessments, developing security policies, delivering security training, supporting incident response and business continuity plans, and collaborating across departments to uphold cybersecurity standards and protect member data. The position offers growth opportunities in a supportive, community-focused environment and requires 0-2 years of relevant experience with foundational knowledge of security frameworks and tools.

Boost your chances. Upload your resume to see your match score.

Unlock Match Rate
Description

About Careertakes

👉 Important disclosure: Careertakes is a third-party recruiting platform supporting this hiring process. If selected, you will be employed directly by our client, IT.

Applicants for this role may also receive access to additional matched opportunities through the Careertakes platform.


Position Overview

Confidential Client is seeking an Information Security Analyst II (GRC) to support Governance, Risk, and Compliance (GRC) activities within the Information Security team. This is a full-time, on-site role in Superior, CO focused on integrating security frameworks into day-to-day operations, supporting regulatory compliance, conducting risk assessments, and maintaining security policies, training, and control testing.


Compensation & Benefits

  • Salary range: $78,068.04 – $97,585.05 per year (range provided per Colorado pay transparency requirements).
  • Benefits include:
    • Comprehensive medical, dental, and vision insurance
    • Generous paid time off and 12 paid holidays
    • Annual discretionary bonus based on organizational results
    • 401(k) plan
    • Wellness program and tuition assistance
    • Employee loan discounts, EAP, life and disability coverage

What You’ll Do (Key Responsibilities)

Governance

  • Stay current with financial and regulatory guidance (e.g., FFIEC, NCUA) and incorporate requirements into the security program.
  • Apply industry security frameworks (PCI DSS, NIST 800-53, ISO 27001, CIS, MITRE ATT&CK, OWASP Top 10) to Confidential Client processes.
  • Develop, implement, and maintain policies, standards, and procedures that align with organizational objectives.
  • Design and deliver employee training on compliance, security awareness, and risk topics.

Risk Management

  • Perform risk assessments to identify threats to member and organizational data, applications, and security tooling.
  • Document findings and recommend practical mitigation strategies.
  • Support incident response (ISIRP), business continuity, and disaster recovery planning and tabletop exercises.

Compliance & Control Testing

  • Monitor and support compliance with applicable frameworks and regulatory obligations.
  • Assist with internal and external audits and examinations; provide evidence and track remediation.
  • Conduct control testing, manage findings, document remediation progress, and participate in exception management and risk acceptance reviews.
  • Monitor phishing reports and InfoSec ticketing activity to ensure timely investigation and resolution.

Collaboration & Reporting

  • Work with IT, risk/compliance, and operational teams to align cybersecurity objectives across the organization.
  • Produce regular reports for leadership on program status, compliance gaps, and risk trends.
  • Define and maintain InfoSec metrics and key risk indicators (KRIs) to measure program effectiveness.
  • Serve as a GRC resource for employees and encourage a culture of compliance and security awareness.

Qualifications

Education & Certifications

  • Associate’s or Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience.
  • Entry-level security certifications preferred (CompTIA Security+, SSCP) or willingness to obtain.

Required Knowledge

  • Basic understanding of information security concepts, principles, and best practices.
  • Familiarity with frameworks: PCI DSS, NIST, CIS, OWASP, and related standards.
  • Basic Microsoft Windows desktop/server knowledge and introductory Linux familiarity.
  • Fundamental networking concepts and awareness of common cyber threats and vulnerabilities.

Experience

  • 0–2 years in IT, cybersecurity, or a related technical role.
  • Experience supporting IT systems, help desk, infrastructure, or security operations preferred.
  • Exposure to regulated environments (financial services preferred) is a plus.

Technical & Professional Skills

  • Willingness and aptitude to learn and grow in information security.
  • Hands-on or exposure to security tools (endpoint protection, vulnerability scanners, log monitoring) preferred.
  • Strong documentation, analytical, and troubleshooting skills.
  • Good written and verbal communication and a customer-service orientation.
  • Strong organizational skills with the ability to manage multiple priorities.

Working Conditions

  • Standard office environment in Superior, CO; Monday–Friday, 40 hours per week (typical schedule).
  • Low to moderate noise; occasional lifting up to 30 lbs.
  • Reasonable accommodations will be provided in accordance with the Americans with Disabilities Act as appropriate.

Why Apply

This role is an opportunity to join Confidential Client’s IT team and build practical GRC experience across policy, risk assessment, compliance testing, and security training. The position is designed for someone early in their cybersecurity career who wants structured growth, mentorship, and exposure to regulatory and framework-driven security programs.


Equal Opportunity & Hiring Transparency

Careertakes and our client are Equal Opportunity Employers committed to building a diverse and inclusive workforce. We prohibit discrimination or harassment of any kind. To support a fair and efficient hiring process, AI tools may be used to assist with application review or resume screening. These tools do not replace human decision-making. Final hiring decisions are made by people.

If you have questions about how your data is used, please contact us directly.

Negotiate a higher salary! Check the salary ranges for this job type in your area.

View My Salary Range