InfoSec GRC Analyst /Senior Analyst

BILL • South Bay

Company

BILL

Location

South Bay

Type

Full Time

Job Description

Build your career with purpose. Be a champion for small and mid-size businesses.

BILL is a leader in financial automation software for small and midsize businesses (SMBs). As a champion of SMBs, we are dedicated to automating the future of finance so businesses can thrive. Hundreds of thousands of businesses trust BILL solutions to manage financial workflows, including payables, receivables, and spend and expense management. With BILL, businesses are connected to a network of millions of members, so they can pay or get paid faster. Through our automated solutions, we help SMBs simplify and control their finances, so they can confidently manage their businesses, and succeed on their terms. 

BILL is a trusted partner of leading U.S. financial institutions, accounting firms, and accounting software providers. We have operations in San Jose, CA, Draper, UT, Houston, TX and Sydney, AUS and are continuing to expand into other geographic locations. If you’re looking for a place that helps you do the best work of your career, look no further than BILL.

Make your impact within a rapidly growing Fintech Company

The InfoSec Governance, Risk and Compliance (GRC) team works within the Information Security (InfoSec) organization at BILL to implement, monitor, and continuously improve BILL’s security governance, risk, and compliance programs.

As an InfoSec GRC analyst, reporting to the Director of GRC Customer Audit, Assurance and Third-party Security Risk Management, you will be responsible for collaborating cross-functionally with the business on GRC activities and supporting the company’s obligation to identify technology and security risks, and manage legal, regulatory and compliance risks. This role will be critical as we mature our controls and overall Information Security program.

In this role you will 

  • Assess security compliance with policies, standards, and regulations through controls monitoring, controls testing and performance of security risk assessments. Serve as a subject matter resource to assess compliance implications for areas that have gaps
  • Stay updated on developing regulatory concerns and changing IT/security trends. Develop a close partnership with control owners, educating them on applicable security compliance requirements, security risk areas, mitigations, process improvements, and risk-appropriate control recommendations
  • Support coordination of internal and external audits that are associated with cybersecurity and technology risks, including facilitating audit evidence collections, responses to observations and reporting 
  • Respond to customer and partner security due diligence requests, and ensure that BILL meets customer and partner requirements
  • Support issue management efforts, which include remediation tracking, status reporting and validating closure of security gaps, non-compliance issues and/or security risk.
  • Assist in continuous controls monitoring utilizing GRC solution, dashboards, analytics, automation, and other supporting tools.
  • Assist in preparing ongoing reports with specified metrics/key performance indicators related to compliance activities, audit results, remediation plans, and other compliance efforts and present them to management
  • Assist in evaluating security risk associated with Third-Party/Vendor to ensure that Third-Parties’ technology environment and security controls appropriately protect shared data, that contracts have the appropriate security requirements, and that those requirements are met through regular re-assessments
  • Provide expertise and consulting with the objective of helping BILL manage Third-Party security risk to an acceptable level
  • Be an advocate for security best practices and the security compliance resource for stakeholders from departments throughout the company

We’d love to chat if you have:

  • 3+ years of experience in technology risk and compliance roles. Preferably at a technology or SaaS / Cloud company, and / or as an auditor at Big 4 firm
  • Knowledge and experience with compliance and regulatory frameworks, standards and controls, such as NIST, ISO27001, PCI DSS, SSAE 18 (SOC), COSO, SOX
  • Understanding of security techniques, practices, and controls that can be applied to address risks
  • Experience working and collaborating effectively with technical or non-technical subject matter experts, and internal/external auditors in gathering information and demonstrating compliance with standards
  • Experience with the monitoring and evaluation of technology processes and controls including design and operating effectiveness testing and reporting on results and recommendations
  • Experience with Third-Party / Vendor Security Risk Management
  • Experience working with Fintech GRC or top tier bank compliance or audit function will be preferred 
  • Possess strong oral and written communication skill, and strong project management and organizational skills 
  • Action-oriented with the ability to multi-task and work in agile, changing and fast growing environments
  • Bachelor’s degree in Information Systems, Security, Technology or similar field of interest or equivalent work experience
  • Relevant professional designation (CISSP, CISA, CRISC, CRMA, CIPP)

Let’s talk about benefits

  • 100% paid employee health, dental, and vision plans (choose HMO, PPO, or HDHP)
  • HSA & FSA accounts 
  • Life Insurance, Long & Short-term disability coverage
  • Employee Assistance Program (EAP)
  • 11+ Observed holidays and wellness days and flexible time off 
  • Employee Stock Purchase Program with employee discounts
  • Wellness & Fitness initiatives
  • Employee recognition and referral programs
  • And much more

This role is based in California.

The estimated base salary range for this role is noted below for our office location in San Jose, CA. Additionally, this role is eligible to participate in BILL’s bonus and equity plan. Our ranges for each role and job level are based on a variety of factors including candidate experience, expertise, and geographic location and may vary from the amounts listed above. The role is also eligible for a competitive benefits package that includes: medical, dental, vision, life and disability insurance, 401(k) retirement plan, flexible spending & health savings account, paid holidays, paid time off, and other company benefits.

San Jose pay range
$110,200—$132,100 USD

We live our culture and values every day

At BILL, we’re different by design—it's our culture. Our CEO is a trusted entrepreneur who lives our cultural values: Humble, Authentic, Passionate, Accountable, and Fun. People here love being their authentic selves, contributing unique experiences, sharing ideas, perspectives, and intellectual curiosity. We celebrate our diversity as the heart and soul of how we work, grow, and succeed together. Inspiring people with meaningful career experiences they love really does make the dream work and our successes just keep getting better. There’s no limit to what we can build and where we can go from here. We’d love you to join us.
BILL is proudly an Equal Opportunity Employer where everyone is welcome. Our innovation and technology are inspired by an inclusive culture unlike any other. Everyone brings a different personal story and perspective and this diverse mix of minds, backgrounds, and experiences is where our greatest ideas come from. We welcome people of all races, ethnicities, ages, religions, abilities, genders, and sexual orientations to make us an even more vibrant company. We want everyone to bring their authentic selves here, to share our values, shape our vision, drive innovation, and become part of a culture we celebrate every day.

BILL Culture:

  • Humble - We check our egos at the door. We are curious. We listen, accept feedback.
  • Authentic - We earn and show trust by being real—embracing our authentic selves.
  • Passionate - We care deeply about each other and our customers.
  • Accountable - We are duty-bound to each other, our customers, and society.
  • Fun - We wrap it all together by building connections and enjoying time spent together.

Our Applicant Privacy Notice describes how BILL treats the personal information it receives from applicants

Apply Now

Date Posted

03/12/2023

Views

14

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

AI Solution Manager, ServiceNow Platform - ServiceNow

Views in the last 30 days - 0

ServiceNow a global market leader in AIenhanced technology is seeking an AI Solution Manager to lead the implementation of AI solutions for complex bu...

View Details

Senior Software Engineer, Devices Automation - Block

Views in the last 30 days - 0

Square a company that has evolved since its inception in 2009 is seeking a Software Engineer with extensive experience in embedded devices and test en...

View Details

Senior Systems Infrastructure Engineer - BlackLine

Views in the last 30 days - 0

BlackLine is seeking a highly skilled Infrastructure Engineer to design build and manage corporate environments across Azure AWS and GCP platforms The...

View Details

Solution Manager, Workday - BlackLine

Views in the last 30 days - 0

BlackLine is a leading provider of cloud software that automates and controls the entire financial close process The company is committed to modernizi...

View Details

Senior Program Manager, Global Occupational Health & Safety - ServiceNow

Views in the last 30 days - 0

ServiceNow is seeking a Health Safety Program Manager to design implement and lead a comprehensive corporate safety program The role involves develop...

View Details

Senior Finance Manager, Central FP&A - Palo Alto Networks

Views in the last 30 days - 0

Palo Alto Networks is seeking a Senior Finance Manager with 10 years of experience in FPA The role involves leading ad hoc projects collaborating with...

View Details