
IT Security Compliance Analyst - REMOTE
Velera · United States
- Hybrid
- Full-time
- $108,200 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Support IT compliance programs and research risks.
- Develop security metrics and report compliance priorities.
- Collaborate with leaders on IT compliance practices.
- Conduct audits and manage corrective actions.
- Maintain knowledge of financial industry regulations.
About the role
About Velera
Velera is a leading fintech solutions provider and CUSO, serving over 4,000 financial institutions in North America. Our purpose is to accelerate partners' success through innovative financial technology solutions and inspired service. We foster a remote-first, inclusive culture where employees are valued, respected, and empowered.The Opportunity
The IT Security Compliance Analyst plays a crucial role in supporting Velera's IT Compliance Programs. This position involves researching risks, identifying issues, developing solutions, and providing essential reporting, training, and other support. The analyst will oversee and gather information on ongoing Velera activities, develop information security metrics for senior leadership, and report on key compliance priorities. A significant aspect of this role includes owning the execution and processes to meet stated priorities and collaborating with functional ITS and business leaders to drive IT compliance practices and adoption.Day in the Life
- Audit user and system security configurations for compliance with internal and external requirements.
- Perform audits and follow-up on corrective actions; participate in internal audit activities for compliance verification.
- Interact and coordinate with appropriate business unit resources for audit participation.
- Provide information to management regarding negative business impact caused by violations of confidentiality, integrity, or availability of information and information systems.
- Understand the application of security concepts across a broad scope of IT areas, including data communications, network design, operations, database structures, operating systems, application development, security risk assessment, and disaster recovery.
- Provide ongoing guidance and support to the organization to promote a progressive and sustainable compliance culture.
- Prepare and provide updates for monthly internal and external compliance reports.
- Document and maintain risk-based compliance policies and procedures; develop materials for ITS's compliance intranet site.
- Coordinate training material and monitoring records, and the distribution of regulatory information.
- Implement and maintain operational plans for key control activities to ensure compliance with regulatory, legal, and corporate policies.
- Respond to internal and external inquiries to clarify regulatory requirements.
- Assist in developing processes to identify, quantify, analyze, and report on Velera Technology Risk and Compliance status.
- Function as a liaison between business units with compliance responsibilities to collect, report, and retain compliance documentation.
- Identify ongoing process improvements, operational gaps, and potential remediation steps; assist/lead re-design and coordination of remediation efforts.
- Maintain knowledge of legislation and regulation changes related to the financial industry, particularly finance industry security and privacy regulations, and assist in leading internal efforts to ensure compliance.
- Lead and/or participate in special project teams supporting general business initiatives outside the primary security function.
- Perform other duties as assigned.
Qualifications
- Bachelor’s degree in computer science or related discipline, or equivalent combination of education and experience required.
- Risk management, governance, or security certification (CRISC, CGEIT, CISSP, CISM, CISA) required.
- Project Management certification (PMP) preferred.
- Five (5) years of related work experience, including a combination of at least three (3) years’ experience in Internal IT Systems Auditing and three (3) years’ experience in internal control projects in the financial industry required.
- Working knowledge of SSAE 16 and PCI requirements.
- Working knowledge of ISO27000 series of standards, PCI, COBIT, ITIL, and Sarbanes Oxley rules surrounding IT.
- Working knowledge of NACHA.
- Working knowledge of OFAC, BSA, GLBA, Patriot Act, and other Federal or State laws impacting National Security requirements or privacy.
About Velera
At Velera, inclusion is fundamental to our operations, guided by a people‑helping‑people philosophy. We cultivate a culture where every employee feels valued, respected, and empowered. We are committed to building a diverse workforce and fostering meaningful connections across our teams. Our remote‑first, flexible environment prioritizes psychological safety, well-being, and belonging, enabling individuals and teams to collaborate and thrive. Together, we are shaping a new era of secure, innovative solutions for our clients and communities.Benefits
- Competitive wages
- Medical with telemedicine
- Dental and Vision
- Basic and Optional Life Insurance
- Paid Time Off (PTO)
- Maternity, Parental, Family Care
- Community Volunteer Time Off
- 12 Paid Holidays
- Company Paid Disability Insurance
- 401k (with employer match)
- Health Savings Accounts (HSA) with company provided contributions
- Flexible Spending Accounts (FSA)
- Supplemental Insurance
- Mental Health and Well-being: Employee Assistance Program (EAP)
- Tuition Reimbursement
- Wellness program
Equal Opportunity Employer
Velera is an Equal Opportunity Employer committed to diversity and inclusion. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, or membership in any other protected group. Velera is an E-Verify Employer. Sponsorship is not available for this role.Key skills/competency
- IT Security Compliance
- Risk Management
- Auditing
- Regulatory Compliance
- Information Security
- Financial Industry Regulations
- SSAE 16
- PCI DSS
- COBIT
- ITIL
Skills & topics
- IT Security
- Compliance Analyst
- Risk Management
- Information Security
- Auditing
- Financial Services
- Fintech
- Remote
- SSAE 16
- PCI DSS
- COBIT
- ITIL
- CRISC
- CGEIT
- CISSP
- CISM
- CISA
- PMP
- NACHA
- OFAC
- BSA
- GLBA
- Patriot Act
- Velera
How to get hired
- Tailor your resume: Highlight your experience in IT auditing, risk management, and financial industry compliance, specifically mentioning SSAE 16, PCI, COBIT, ITIL, NACHA, OFAC, BSA, GLBA, and Patriot Act.
- Showcase certifications: Clearly list your required risk management/security certifications (CRISC, CGEIT, CISSP, CISM, CISA) and preferred PMP on your resume and application.
- Demonstrate financial industry expertise: Emphasize your 3+ years of experience in internal control projects within the financial sector.
- Prepare for technical questions: Be ready to discuss your understanding of security concepts across various IT areas and your knowledge of key compliance frameworks and regulations.
- Understand Velera's mission: Align your application and interview responses with Velera's 'people helping people' philosophy and commitment to innovation in fintech.
Technical preparation
Master SSAE 16, PCI, ISO27000, COBIT, ITIL.,Understand NACHA, OFAC, BSA, GLBA, Patriot Act.,Practice IT system auditing and internal controls.,Develop security metrics and risk reporting.
Behavioral questions
Describe a compliance issue you resolved.,How do you handle conflicting priorities?,Explain security concepts to non-technical staff.,How do you stay updated on regulations?
Frequently asked questions
- What are the key certifications required for the IT Security Compliance Analyst role at Velera?
- For the IT Security Compliance Analyst position at Velera, a risk management, governance, or security certification such as CRISC, CGEIT, CISSP, CISM, or CISA is required. A Project Management Professional (PMP) certification is preferred.
- What specific regulations and standards should I be familiar with for the IT Security Compliance Analyst job at Velera?
- You should have working knowledge of SSAE 16, PCI requirements, ISO27000 series, COBIT, ITIL, Sarbanes Oxley (SOX) IT rules, NACHA, OFAC, BSA, GLBA, and the Patriot Act. Familiarity with other Federal or State laws impacting national security or privacy in the financial industry is also beneficial.
- What is the required experience for the IT Security Compliance Analyst position at Velera?
- Velera requires five years of related work experience. This includes a combination of at least three years in Internal IT Systems Auditing and three years in internal control projects within the financial industry.
- Is this IT Security Compliance Analyst role remote or on-site at Velera?
- This IT Security Compliance Analyst role at Velera is a remote position, aligning with Velera's remote-first work environment.
- Can I apply for the IT Security Compliance Analyst position at Velera if I need sponsorship?
- No, this role is currently not eligible for sponsorship. Velera is unable to provide visa sponsorship for this IT Security Compliance Analyst position.
- What is the salary range for the IT Security Compliance Analyst role at Velera?
- The listed salary range for the IT Security Compliance Analyst position at Velera is $84,900.00 to $108,200.00 annually, with the actual pay adjusted based on experience and other factors.
- What kind of training and development is offered for the IT Security Compliance Analyst at Velera?
- While specific details on training programs for this role are not fully elaborated, Velera offers a supportive environment and tuition reimbursement, indicating a commitment to employee growth. The role itself involves developing training materials for others, suggesting a focus on knowledge sharing.
- How does Velera support a healthy work-life balance for its remote employees, such as the IT Security Compliance Analyst?
Similar roles
Open positions we recommend based on this role.