Senior Security Analyst
New York, New York County, New York, 10261, USA
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
About the Company
Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing.
We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.
Rather than build on top of broken legacy systems, we took a different approach: we built and operate our own mortgage servicing business managing $110+ billion in loans. This wasn't the end goal, it was how we deeply understood the complexity needed to build software that actually works in regulated industries.
The results speak for themselves. We've transformed mortgage servicing from a 0% margin business into 60%+ margins while dramatically improving customer experience. Major enterprise contracts are now deploying across the industry.
ValonOS is our unified platform that makes every process structured and programmable and it is perfectly positioned for the AI era. When everything flows through one system with rich data, AI agents don't just automate tasks, they continuously improve entire operations. Mortgage servicing is just the beginning of our vision to transform regulated industries and beyond.
Security at ValonOur customers entrust us with some of their most sensitive and personal financial information, and it is the ultimate mission of Valon’s Security team to ensure we have sound programs, processes, and automation in place to safeguard our customers’ data. The Security team protects the infrastructure and data for processing billions of dollars of mortgage loans.
In addition to protecting Valon’s internal systems, the Security team partners closely with Product and Engineering to design and deliver secure, scalable, and trustworthy capabilities for ValonOS. We work cross-functionally across all teams at Valon to enable security throughout the organization. We engage with external security auditors, pentesting firms, and partners to continuously evaluate Valon’s security posture.
Valon offices are located in New York City and San Francisco, but we fully support remote work!
About the RoleWe are seeking a motivated Sr. Security Analyst to join our growing team! As a key security member working closely with the Head of Security GRC and the Security team at Valon, you will play a critical role in ensuring the security of our organization's systems, cloud infrastructure, products and data.
This position requires a strong foundation in security risk and compliance principles, hands-on experience leveraging AI-assisted processes to strengthen GRC functions and operational activities, an automation first mindset, and a proactive approach to problem-solving. You will collaborate with cross-functional teams to protect our most critical assets and uphold trust with our customers and stakeholders.
ResponsibilitiesImplement and maintain compliance with frameworks (SOC 2, NIST CSF, CIS) and regulatory requirements (NYDFS, GLBA, Safeguards, CCPA and related)
Support internal and external security audits and exams, including evidence gathering and remediation tracking
Build AI assisted GRC workflows for scaling GRC and security functions
Maintain and manage security risk register, risk assessments, and remediation processes
Manage security governance and compliance projects, and assist with other project management efforts
Manage security metrics, KPIs and reporting
Support customer security due diligence processes
Review, manage, and monitor security policies for compliance
Facilitate remediation for security and compliance issues across stakeholders
Manage vendor security risk assessments
Support on-call and operational security activities including security monitoring, incident management, general security reviews, security awareness and training, and other tasks
Proven experience in a security analyst related role, with a focus on security compliance, risk management, security issue management, and/or security program management.
Experience with security and compliance frameworks and requirements (OWASP, SOC 2, NIST CSF / 800-53, ISO 27001/2, CIS, NYDFS, CCPA or others.)
Basic knowledge of cloud security and public cloud environments
Self-starter that can…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).