×
Register Here to Apply for Jobs or Post Jobs. X

Information Security GRC Analyst III

Job in Greenville, Greenville County, South Carolina, 29610, USA
Listing for: Advance America, Cash Advance Centers, Inc.
Full Time position
Listed on 2026-09-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 120000 USD Yearly USD 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Select how often (in days) to receive an alert:

Purpose Financial, Inc. is an innovative consumer financial services company that offers a diverse suite of credit products, promoting financial inclusion and meeting consumers wherever they are. Through its brands, the company is committed to helping customers achieve their version of financial stability in the moment and in the future. Since 1997, Purpose Financial has been a pioneer in the consumer credit and financial services market offering money solutions in over 800 storefronts locations and online lending.

Providing services in over 23 states, Purpose Financial employs over 2,500 team members.

At Purpose Financial we are always on the lookout for motivated individuals who share in our values of mutual respect to join our team of outstanding professionals.

We offer:

  • Competitive Wages
  • 401(k) Savings Plan with Company Match
  • Company Paid Holidays
  • Tuition Reimbursement
  • Business Casual Environment
  • Rewards & Recognition Program
  • Employee Assistance Program
  • Office in downtown Greenville that offers free parking, onsite gym, free snacks/drinks

Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for Purpose Financials information security program. This role is the operational backbone of our compliance posture owing to SOC 2 Type II readiness and certification, driving ISO 27001 certification and ongoing ISMS maintenance, and supporting the broader Information Security Program across NIST CSF, NIST SP 800-53/800-171, CIS Controls, and PCI DSS.

The ideal candidate brings an organized, project-managed approach to policy, risk, third-party oversight, audit readiness, and continuous compliance. Partnering closely with IT, Sec Ops, Legal, Internal Audit, and business stakeholders to protect the information assets owned by or entrusted to the Company.

Job Responsibility
  • Governance & Policy
    - Maintain and evolve the Company's information security policies, standards, and controls mapped to SOC 2, ISO 27001, NIST, and CIS frameworks; manage the policy exception process with documented justification and approval.
  • Risk Management
    - Conduct risk assessments, maintain the risk register, and support risk acceptance decisions with structured evidence; elevate material risks to leadership with mitigation plans.
  • Compliance & Audit Readiness
    - Own end-to-end audit preparation for SOC 2 Type II and ISO 27001 certification, including control testing, evidence collection, gap remediation, and findings tracking. Maintain the Company's ISMS, conduct Statement of Applicability (SoA) reviews, support internal audits and management reviews, and serve as the primary liaison with external certification bodies throughout the certification and surveillance audit lifecycle.
  • Control Implementation & Monitoring
    - Partner with IT and Sec Ops to operationalize controls across access management, encryption, logging, vulnerability management, and backup/DR; define evidence sources and test cadence.
  • Continuous Monitoring
    - Leverage GRC platform automated monitoring capabilities to maintain real-time visibility into control health; triage failing controls, coordinating remediation with owners, and ensure evidence remains audit-ready throughout the observation period.
  • Evidence Collection & Management - Maintain a structured evidence repository (e.g., SharePoint, GRC platform) to support SOC 2 Type II and ISO 27001 audit cycles; coordinate evidence requests from external auditors, establish and enforce evidence collection cadences (monthly, quarterly, and annual), and ensure completeness and integrity of the evidence package throughout the audit observation period.
  • Third-Party Risk Management (TPRM) - Manage the third-party risk management program including vendor risk assessments, security questionnaires (SIG/CAIQ), contract review support, and ongoing monitoring of critical vendors to ensure alignment with the Company's security and compliance requirements.
  • Change Management & Control Lifecycle - Manage the full control lifecycle including new control design, change management, deprecation, and exception handling; ensure all control changes are documented, reviewed, and aligned with SOC 2 Type II and ISO 27001 audit requirements.
  • Stakeholder Communications & Training - Develop and deliver control owner training, security awareness materials, and compliance guidance to drive adoption of security controls across business units; serve as a trusted advisor to cross-functional teams on…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary