Senior Information Security Analyst

Betterment

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
New York, NY
Salary
$170,000–$185,000 / yr
Posted
4 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $170k
This role $178k
$115k most similar roles pay here $212k

This role pays more than 62% of similar roles. Most pay $137,700–$202,881 — the shaded band above. At the midpoint, this role pays about $178k versus about $170k for comparable roles.

Based on 240 similar postings.

Employer

About Betterment

Betterment is an automated investment service (robo-advisor) that uses technology to provide personalized investment management, retirement planning, and savings optimization at low cost for retail investors. Industry: Financial Technology & Wealth Management

Betterment currently has 15 open roles on FindRole.

Listed pay typically runs $170,000–$195,000 across 15 roles with salary data.

Most-posted roles

View all roles at Betterment

At a glance

TL;DR · Senior Information Security Analyst

Sr. Information Security Analyst The Sr. Information Security Analyst joins the Govern & Control team as a senior individual contributor to manage and mature risk management processes within a technology-driven financial services environment. This role involves leading major programs such as vulnerability management, third-party risk, identity theft oversight, and business continuity while designing complex internal controls using AI and automation tools. The successful candidate will perform end-to-end risk assessments, author policy updates, and provide effective challenge to engineering partners to reduce risk. Key requirements include expertise in the CIA triad, control governance frameworks like SOC 2, ISO 27001, or NIST CSF, and experience with cloud computing and third-party SaaS security. The role requires a T-shaped profile with deep knowledge in areas like SDLC or application security to navigate complex regulatory landscapes and ensure robust information security.

What you'll do

  • Manage major security programs including vulnerability management, third-party risk, and business continuity.
  • Lead end-to-end risk assessment processes and document data-backed risk conclusions.
  • Design and document complex internal controls using automation and AI tools to scale operations.
  • Provide "effective challenge" to engineering partners to mature risk processes and reduce security risks.
  • Author high-quality policy updates and manage KRI reporting for leadership and governance committees.
  • Act as an escalation point and reviewer to ensure the quality of work from junior analysts.
  • Monitor regulatory changes and industry trends to align them with business requirements.

What we're looking for

  • 6+ years of experience in security GRC, technology risk, technology audit, or security operations with senior-level ownership.
  • Expert-level depth in at least one security domain such as vulnerability management, SDLC, application security, or cloud computing.
  • Hands-on command of the CIA triad, control design and operation, and frameworks like SOC 2, ISO 27001, or NIST CSF.
  • Strong knowledge of security controls for cloud computing and third-party SaaS, including logical access and vulnerability governance.
  • Fluency in the structure and content of audit reports and risk assessments, including testing and results reporting.
  • Ability to use professional judgment and quantifiable methods to drive stakeholders toward sound risk acceptance or treatment decisions.
  • Strong cross-disciplinary communication skills to influence partners across Engineering, business, Compliance, and Legal.
  • Moderate understanding of financial services operations and Product/Engineering; experience in regulated financial services is preferred.
  • Professional designations such as CISSP, CISA, CISM, or AWS Cloud certifications are preferred.
  • Experience mentoring analysts or auditors or leading a governance committee is preferred.

More like this

Similar roles

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 17 days ago $125,000–$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp

Senior Information Security Analyst

McKesson Corporation

Irving, TX 13 days ago $169,950–$179,300
Azure AWS Databricks Azure Data Factory Python PowerShell JavaScript Zero Trust NIST ISO 27001 HIPAA GDPR Vulnerability Management Penetration Testing Linux Windows Unix Automation Orchestration
7+ yrs exp

Senior Security Analyst

SpaceX

Redmond, WA 13 days ago $130,000–$195,000
SIEM Splunk Elastic Incident Response Linux Windows macOS Scripting Forensics Reverse Engineering Cloud Security C2 TTPs SOC Cybersecurity
5+ yrs exp

Senior SAP Security Analyst

Abbott

Madison, WI 31 days ago $78,000–$156,000
SAP SAP GRC Fiori OData SaaS Microsoft Office SOD Risk Analysis and Remediation Compliant User Provisioning Superuser Privilege Management Emergency Access Management SAC Datasphere IBP IAS/IPS
5+ yrs exp

Senior Cyber Security Analyst

FedEx

Memphis, TN +2 12 days ago
GCP Terraform Python Go Bash CI/CD Git Zero Trust Cloud Armor VPC Service Controls Cloud IDS SIEM AWS Azure Network Security Infrastructure as Code
4+ yrs exp Hybrid

Senior Specialist, Info Security Systems Engineer

L3Harris

Colorado Springs, CO 20 days ago $92,500–$171,500
DevSecOps CI/CD SAST Fortify Coverity GitLab Splunk Tenable Nessus SysML UML UAF IaaS PaaS SaaS Encryption Vulnerability Management Firewalls Malware Analysis
6+ yrs exp