初级信息安全管理分析师
Junior Information Security & Compliance Analyst
在Veracity,我们希望成为一种不同的保险合作伙伴——一个不受外部投资者、风险投资或母公司压力影响的合作伙伴。
我们的文化是赋权——我们相信努力、成果和问责制。我们认为透明度促进信任,信任促进增长,而增长推动创新。我们对严格评估和不懈执行的承诺,带来了快速的进化。
我们只对所服务的小企业主负责,这种独立性使我们能够专注于最重要的事情:通过提供专业指导和一流的保险政策,帮助他们的业务蓬勃发展。
我们发展迅速,希望你能成为其中一员!
我们正在寻找一位精准、坚持且易于指导的初级信息安全与合规分析师加入我们的团队。向信息安全与合规分析师汇报,该职位是Veracity安全和合规计划的执行引擎——负责持续进行、有截止日期的工作,确保计划在Veracity、Insurance Canopy和InsCipher中保持可信和可审计。
这是一个有意设计的入门级职位——候选人不需要拥有深厚的安全经验,但需要具备精准、坚持和可指导的特质,并在工作中逐步建立真正的技术和审计深度。随着时间推移,此人应全面负责定期合规日历,并成为公司的第二道安全响应防线。
主要职责
- 监控AWS、Microsoft 365、Google Workspace和Grafana的安全仪表盘、警报和日志——根据既定操作手册进行分类、记录处理结果并升级问题
- 在云、终端和应用表面执行定期漏洞扫描——维护修复跟踪器,与系统负责人跟进,并在定义的SLA内验证和关闭发现的问题
- 作为员工报告的钓鱼攻击和安全问题的第一线处理人员——及时升级已收集上下文的确认问题
- 作为第一响应者和记录员支持事件响应——记录时间线,保存证据,维护工单卫生,并撰写事后总结和经验教训供上级审查
- 维护安全工具的覆盖范围和健康状态,包括MFA注册、终端代理、日志代理和电子邮件安全——并报告存在的缺口
- 执行用户访问权限的分配、角色变更和撤销
查看英文原文
At Veracity, we aim to be a different kind of insurance partner – one that is free from outside investors, venture capital, or the pressures of a corporate parent.
Ours is a culture of empowerment – one that believes in effort, results, and accountability. We believe that transparency fosters trust, trust fosters growth, and that growth drives innovation. Our commitment to rigorous evaluation and relentless execution lead to rapid evolution.
We answer only to the small business owners we serve, and this independence allows us to stay focused on what matters most: helping their businesses thrive by providing expert guidance and best-in-class insurance policies.
We’re growing fast and want you to be a part of it!
We're seeking a precise, persistent, and coachable Junior Information Security & Compliance Analyst to join our team. Reporting to the Information Security & Compliance Analyst, this role is the execution engine of Veracity's security and compliance program – carrying the recurring, deadline-driven work that keeps the program credible and audit-ready across Veracity, Insurance Canopy, and InsCipher.
This is a deliberately structured entry-level role – the incumbent is not expected to arrive with deep security experience, but is expected to be precise, persistent, and coachable, and to build real technical and audit depth on the job. Over time, this person should take full ownership of the recurring compliance calendar and become the company's second line of security response.
Key Responsibilities
- Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and escalate per established runbooks
- Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow-up with system owners, and verify and close findings within defined SLAs
- Serve as first-line triage for employee-reported phishing and security questions – escalating confirmed issues promptly with context already gathered
- Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post-incident summary and lessons learned for senior review
- Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps
- Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same-day removal of access for departures
- Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence
- Enforce least-privilege and role-based access practices in day-to-day requests – flagging standing privileges and orphaned accounts for remediation
- Maintain accurate records of privileged accounts, service accounts, and third-party access across business units
- Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently
- Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff
- Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking
- Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review
- Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff
- Draft responses to customer and carrier security questionnaires and diligence requests for review by the Information Security & Compliance Analyst
- Maintain the asset inventory and security awareness training program including completion tracking and follow-up with non-completers
- Build and maintain security and compliance metrics reporting – open vulnerabilities, SLA performance, access review status, and training completion
- Write and maintain runbooks, SOPs, and checklists for recurring work so that it is repeatable and transferable
- Partner with IT, Engineering, Compliance, Legal, and Service teams so that controls are applied consistently without unnecessary friction to the business
- Identify repetitive security and compliance tasks that can be automated or streamlined and propose improvements
- Required to perform other duties as requested, directed, or assigned
Requirements and Qualifications
- 0–2 years of professional experience – internships, IT helpdesk or support, systems administration, or audit and compliance support all count; this role is intended to be a first or second job in security
- Bachelor's degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or a relevant certification in lieu of a degree
- Working familiarity with at least one major cloud or productivity platform – AWS, Microsoft 365/Azure, or Google Workspace – including where users, permissions, and logs live
- Demonstrated ability to own recurring, detail-heavy work to completion without reminders
- Comfort with spreadsheets, ticketing systems such as Jira, and documentation tools
- Excellent verbal and written communication skills – able to ask a busy system owner for evidence and actually get it, and to write documentation an auditor will accept
- Sound judgment and discretion handling sensitive, regulated, and confidential information including customer PII and NPI
- Coachability and genuine curiosity about security – willing to be taught and willing to say "I don't know" early rather than let an item quietly slip
- Composure under pressure during audits, incidents, and deadlines
Perks
- Health, dental, and vision plans
- Amazing work-life balance with 4 weeks of Paid Time Off
- 10 Paid Company Holidays with 2 floating holidays
- 401K Programs with employer match
- Personal assistance programs for support in a healthy personal and work life
Why Veracity?
Here at Veracity, you’ll be part of a team of trailblazers and visionaries. We’re not just revolutionizing the way people “do” insurance; we are creating a whole new paradigm. Here, you will experience a vibrant and inclusive workplace where your ideas matter! With us, you have a chance to:
- Engage in groundbreaking projects that are reshaping the insurance landscape
- Collaborate with a group of dedicated, like-minded professionals
- Experience a culture that prioritizes growth and development
Compensation Range:$55k/yr - $70k/yr
We are proud to be an equal-opportunity employer. We are committed to providing equal opportunities to all qualified applicants, regardless of race, color, religion, sex, national origin, disability, or any other legally protected characteristics.
If you need accommodation, please let us know during the interview process.
Originally posted on Himalayas