Security Analyst, Governance, Risk, and Compliance (GRC) (Remote Optional)

| Greater NYC Area | Hybrid
Sorry, this job was removed at 7:08 a.m. (EST) on Wednesday, November 17, 2021
Find out who's hiring in Greater NYC Area.
See all Data + Analytics jobs in Greater NYC Area
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

The Petal mission


Petal’s mission is to bring financial opportunity and innovation to everyone. 


We're pioneering a new approach to credit, by analyzing an applicant’s banking history, in addition to credit history, to determine their creditworthiness. We call this technology a Cash Score — and it takes into account income, spending, and savings. It’s currently helping thousands of people qualify for credit at better rates, even if they’ve never had it before. 


We bring the same ingenuity to our credit card products. Our simple and intuitive app gives members access to credit score tracking, budgeting tools, subscription management, and automated payment options—everything they need to make financial progress. 


Now more than ever, Americans need help improving their credit safely, responsibly, and affordably. If this sounds like something you’d like to be a part of, apply now, and let’s change this trillion-dollar industry together.


At Petal, we're looking for people with kindness, positivity, and integrity. You're encouraged to apply even if your experience doesn't precisely match the job description. Your skills and potential will stand out—and set you apart—especially if your career has taken some extraordinary twists and turns. At Petal, we welcome diverse perspectives from people who think rigorously and aren't afraid to challenge assumptions.


The Infrastructure & Security Engineering Team 


The Infrastructure & Security Engineering team manages security, product infrastructure, and IT support for Petal. So far, we have focused on growing the IT support and product infrastructure areas. Now we are expanding the security function, and there is tremendous opportunity to grow in an environment with a modern tech stack (no Outlook Web Access!).


The Security Analyst, Governance, Risk, and Compliance (GRC) role 


The Security Analyst, GRC will coordinate and execute a growing slate of activities related to information security risk management practices at Petal, including policy/document management, third-party security reviews, internal assessments, and certification activities such as SOC 2 and PCI.

Key responsibilities:

  • Steer Petal security activities toward a transparent and people-centric program that is directly connected to business value.
  • Coordinate periodic security assessment and audit activities, particularly those required by business partners or compliance frameworks/regulations.
  • Develop and maintain security policies and related documentation.
  • Report on Petal’s developing maturity across security domains.
  • Identify and measure meaningful metrics that help to clarify how we can improve our security practices.
  • Collaborate closely and maintain alignment with key stakeholders including Security Operations, Information Technology, Legal, and Compliance.

Characteristics of a successful candidate:

  • Outstanding communication skills, verbal, written, and visual. We believe creating excellent documentation, building relationships, and maintaining alignment with others will help us deliver results.
  • Rigorous execution, reporting, and tracking for follow-through. We need to build trust among our stakeholders that we will be reliable in delivering our security objectives and monitoring for quality. This includes leveraging collaborative tooling for tracking (e.g., issue trackers, project management software, documentation platforms, etc).
  • Analytical mindset. More important than any specific security framework or tool is a methodical mindset for exploring risks, learning new concepts, and finding creative solutions.
  • Excitement and curiosity in security challenges faced by FinTechs. Introductory understanding of security in business environments and motivation for growth in the security field is important.

Nice-to-haves:

  • Experience with security compliance frameworks (e.g., SOC 2, PCI-DSS, NIST CSF), expertise across security domains, or background in FinTechs is a plus.
  • Working knowledge of cloud services, including major infrastructure/platform-as-a-service providers (e.g., AWS), and related security considerations (e.g., authentication, third-party risk management, etc).

For our California employment information privacy statement, please click here.

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
  • People Operations
    • PythonLanguages
    • RLanguages
    • SqlLanguages
    • TypeScriptLanguages
    • PandasLibraries
    • ReactLibraries
    • CircleCIFrameworks
    • DockerFrameworks
    • FlaskFrameworks
    • gRPCFrameworks
    • KubernetesFrameworks
    • ElasticsearchDatabases
    • PostgreSQLDatabases
    • RedisDatabases
    • AWS (Amazon Web Services)Services
    • GitHubServices
    • Google AnalyticsAnalytics
    • LookerAnalytics
    • OptimizelyAnalytics
    • FigmaDesign
    • IllustratorDesign
    • MiroDesign
    • PhotoshopDesign
    • ConfluenceManagement
    • Google DriveManagement
    • Google DocsManagement
    • Google SlidesManagement
    • JIRAManagement
    • Monday.comManagement
    • EasyRetro Management
    • WebflowCMS
    • Iterable CRM
    • SendGridEmail
    • SlackCollaboration
    • ZoomCollaboration
    • Monday.comProject Management

Location

Petal's HQ office is located in the lovely SoHo neighborhood in lower Manhattan, New York City and is near the Spring St, Houston and Canal Street subway stops.

An Insider's view of Petal

What's something quirky about your company?

At Petal we celebrate our big wins with an unlikely pairing of Popeyes and Prosecco. The origin story remains a mystery — but if we accomplish something really big you can bet that delicious fried chicken and bubbles are on the horizon.

Liza

Talent, Senior Manager

What's the biggest problem your team is solving?

On the Payments team, we're working to increase the speed of payments processing for our members. This way we can deliver a real-time experience, reduce the likelihood of payment reversals, and allow faster access to a member's available credit.

Rohini

Senior Product Manager II

How has your career grown since starting at the company?

I started at Petal as a Credit Ops Analyst. Since then, I’ve had the chance to learn from industry experts, contribute to other sectors of the company, and further pursue my passions. I now have the privilege of leading the department where I got my start. Petal has allowed me to zero in on my purpose and continues to advocate for my development.

Allen

Risk Ops Manager

How do you make yourself accessible to the rest of the team?

Being accessible means that folks have multiple channels to engage with me & contribute ideas, give feedback, influence direction, & seek information. A few channels I use include office hours, monthly AMA's, Tech town halls, & ad-hoc check-ins. It means listening actively, assuming positive intent, asking constructive questions, & trusting others.

John

VP Engineering

How do you collaborate with other teams in the company?

As a PM, I work on delivering an engaging and frictionless app experience for users as they progress on their credit building journey. One of my favorite aspects of Petal’s culture is the egoless, team-first atmosphere that allows Petalians across functions ranging from Compliance to Design to make great things happen for our users together.

Harper

Senior Product Manager I

What are Petal Perks + Benefits

Petal Benefits Overview

Our people are our best perk. Petal is made up of some incredibly kind, inclusive, mission-driven, and passionate folks.

But, besides our team, we offer: In person and virtual team events such as magic shows and game nights, lunch and learns with both external entrepreneurs and internal team members, flexible PTO, medical/dental/vision benefits, 401(k) and a number of Employee Resource Groups you can get involved in. And we're open to hearing more about what would make you more productive and fulfilled!

Culture
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity manifesto
Mean gender pay gap below 10%
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Dental insurance
Vision insurance
Health insurance
Mental health benefits
Financial & Retirement
401(K)
Company equity
Performance bonus
Child Care & Parental Leave Benefits
Generous parental leave
Family medical leave
Return-to-work program post parental leave
Vacation & Time Off Benefits
Unlimited vacation policy
Generous PTO
Sabbatical
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Pet friendly
Home-office stipend for remote employees
Professional Development Benefits
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education available during work hours

More Jobs at Petal

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about PetalFind similar jobs like this