Lead Analyst II, GRC

Root Columbus, OH

Company

Root

Location

Columbus, OH

Type

Full Time

Job Description

CURRENT ROOT EMPLOYEES - Please apply using the career page in Workday. This career site is for external applicants only.


 

The Opportunity

Root is changing the way an industry works by leveraging technology and data to build the best products possible, and the information security team at Root is a key contributor to that effort. Teams are given ownership over projects and results, as we've found that the people closest to the problems are the best at solving them. Root is also a "work where it works best" company, and we will support you working in whatever location works best for you across the US.
 

Root's Information Security team is dedicated to managing information security risk within the organization, while enabling development and product teams to do their cutting-edge work, and we're looking for a Lead Analyst II, GRC to join us. In this role, you'll be a key contributor to the execution and continued development of Root's risk management processes, compliance program, and governance activities to appropriately manage risk and address regulatory requirements.
 

Root is a "work where it works best" company. This means we will support you working in whatever location that works best for you across the US.

Salary Range: $128,235 - $160,294 (Bonus and LTI Eligible)

How You Will Make An Impact

  • Significantly contribute to the ongoing development and maturation of Root's information security risk management processes to appropriately manage risk in alignment with the organization's risk appetite and continuously monitor the risk landscape/control environment

  • Conduct regular risk assessments across the organization, working with a variety of teams/functions to identify, evaluate, and mitigate risks

  • Drive and support compliance with Root's information security regulatory requirements, performing readiness assessments, ensuring policies and controls adequately address relevant requirements, reporting on Root's compliance status, and driving remediation efforts as necessary

  • Lead the ongoing development and management of Root's information security control framework

  • Perform analysis of the information security control environment to monitor effectiveness, identify gaps, and inform compliance reporting

  • Facilitate issue management/risk mitigation activities, collaborating with teams across the organization to identify appropriate risk remediation strategies and track remediation to completion

  • Develop and manage information security policies and standards

  • Perform control design and effectiveness testing of information security controls

  • Define, monitor, and report on key metrics related to the control environment

  • Participate in regulatory exams and other third-party audits

  • Coach others on applying risk management practices and a risk-based approach to security; Contribute to the creation of a risk-aware culture
     

What You Will Need To Succeed

  • 5+ years of experience in executing information security risk management activities, including risk assessment, response, and monitoring processes

  • Expert-level understanding of information security control frameworks, standards, and regulations (such as NIST CSF, PCI DSS, and insurance data security laws or similar)

  • In-depth experience designing and evaluating controls to reduce information security risk

  • Excellent problem solving skills and attention to detail

  • Experience developing reports and metrics including data analysis and data visualization

  • Strong leadership skills; naturally collaborative, excels at influencing without direct authority

  • Proven ability to balance security with the ongoing needs of the business while maintaining compliance and meeting risk management requirements

  • Active security certification (CISM, CISSP, CIA, CISA, etc.) preferred

  • Familiarity with applying security controls in public cloud environments (e.g. AWS)


 

Don't meet every single requirement?

Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Root, Inc., we are dedicated to building a diverse and inclusive workplace, so if you're excited about this role but your past experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyway!

Join us

At Root, we judge people based on the merit of their work, not who they are. If you are passionate about what this role entails and solving real problems, we encourage you to apply. We want to learn about you and what you can add to our team.

Who we are

We're harnessing the power of technology to revolutionize insurance. Using machine learning and mobile telematic platforms, we've built one of the most innovative FinTech companies in the world. And we're just getting started.

What draws people to Root

Our success is in large part due to our unwavering standards in hiring. We recognize that our products are only as good as the people building and promoting them. We want individuals who find solutions by going through the cycle of ideation to implementation with curiosity, rigor, and an analytical lens. Ask anyone who works here and you'll hear similar reasons for why they joined:

Autonomy-for assertive self-starters, the opportunities to contribute are limitless.

Impact-by challenging the way it's always been done, we solve problems that have a big impact on our business.

Collaboration-we encourage rich discussion and civil debate at every turn.

People-we are inspired by the collection of crazy-smart people around us.

Apply Now

Date Posted

01/22/2025

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

Engineering Manager - Cloud - Bold Penguin

Views in the last 30 days - 0

Bold Penguin a leading digital solution platform for small commercial insurance is seeking an Engineering Manager with 6 years of relevant experience ...

View Details

Creative Director - AndHealth

Views in the last 30 days - 0

AndHealth is seeking a handson highly creative and strategic Creative Director to lead and execute all aspects of their creative initiatives The role ...

View Details

Risk Management - Business Banking Transformation Project Manager - Vice President - JPMorganChase

Views in the last 30 days - 0

JPMorgan Chase is seeking a Strategic Analytics Analyst in Risk Management and Compliance The role involves leading and managing projects to transform...

View Details

Partner Solutions Manager - Beam Benefits

Views in the last 30 days - 0

Beam Benefits founded in 2012 is a digital employee benefits company offering dental vision life disability and supplemental health coverage The compa...

View Details

Operations Associate - Lyft

Views in the last 30 days - 0

Lyfts Flexdrive subsidiary is seeking a fulltime Operations Associate in Cincinnati The role involves assisting customers with the car rental process ...

View Details

Lead Software Engineer - JPMorganChase

Views in the last 30 days - 0

JPMorgan Chase is offering a Lead Software Engineer position in the Enterprise technology Corporate Data and Analytics service team The role involves ...

View Details