SlipstreamJobsFresh Startup & VC-Backed Jobs

Information Security Compliance Analyst

Vestwell - New York, NY, United States - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 90,000 - 105,000 / annual

Vestwell is a financial technology platform powering the savings economy across retirement, education, and healthcare. The company serves over 350,000 businesses and 2M active savers with $50B in assets across all 50 states. The Corporate Information Technology team is seeking an experienced Information Security Compliance Analyst to monitor compliance systems in a rapidly scaling organization. This role is central to ensuring Vestwell maintains robust security and regulatory posture. Key Responsibilities: - Manage cybersecurity risk processes, including risk registers, findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance within the GRC solution - Manage cybersecurity compliance obligations across regulatory, contractual, and customer requirements, including NIST, ISO, and SOC 1&2 standards - Coordinate cybersecurity audits, assessments, evidence requests, customer reviews, and remediation tracking in partnership with Legal, Compliance, IT, and business leaders - Support customer, vendor, supplier, and subcontractor cybersecurity risk management, including questionnaires, contract reviews, and security expectations - Review SOC controls and compare them to current actions - Develop new automations to confirm compliance - Respond to RFPs and build a knowledge library to accelerate RFP response processes - Work cross-functionally with Security, Engineering, Legal, and Compliance teams to identify and correct flaws in compliance systems The role is hybrid, based in either the New York City or Austin office. You will be part of Vestwell's collaborative hybrid operation with offices in Midtown Manhattan, Austin, King of Prussia, and Scottsdale. Requirements: Must-Have: - Experience with SOC, ISO, and other audits - Experience responding to RFPs - Experience working across teams to implement new compliance processes - Vendor management and review experience - Sound working knowledge of compliance frameworks and audit processes - Detail-oriented with strong analytical skills - Good communication, interpersonal, and leadership skills Nice-to-Have: - Familiarity with Crowdstrike, Vanta, or Responsive software - Led an audit response

Similar roles