SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 115,000 - 145,000 / annual
Valon is building an AI-native operating system for regulated finance, starting with mortgage servicing. As a Series C company backed by a16z, Valon operates its own mortgage servicing business managing $110+ billion in loans, using this operational expertise to build software that truly works in regulated industries. The company has transformed mortgage servicing from a 0% margin business into 60%+ margins while improving customer experience.
The Security team at Valon is responsible for protecting sensitive financial information and infrastructure processing billions of dollars in mortgage loans. You will work closely with the Head of Security GRC and cross-functional teams to design and deliver secure, scalable capabilities for ValonOS, the company's unified platform.
As Senior Security Analyst, you will implement and maintain compliance with major frameworks (SOC 2, NIST CSF, CIS) and regulatory requirements (NYDFS, GLBA, Safeguards, CCPA). Key responsibilities include supporting internal and external security audits, building AI-assisted GRC workflows to scale security functions, maintaining the security risk register, managing security governance projects, and supporting customer security due diligence. You will also manage vendor security risk assessments, facilitate remediation across stakeholders, and support operational security activities including incident management and security awareness.
The ideal candidate has 5+ years as a security analyst or security program manager with proven experience in compliance, risk management, and security program management. You should be familiar with security frameworks (OWASP, SOC 2, NIST, ISO 27001/2, CIS, NYDFS, CCPA), have basic cloud security knowledge, and hands-on experience with AI tooling and agentic workflows. A bachelor's degree in Computer Science, Information Security, or related field is required, along with relevant certifications (Security+, CC, SSCP, CISSP, CISM, CRISC). Experience in startup environments or financial services is a plus. You must be a self-starter who can work autonomously, balance multiple projects, and communicate security concepts to both technical and non-technical stakeholders.