Junior Information Security & Compliance Analyst
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Veracity, we aim to be a different kind of insurance partner – one that is free from outside investors, venture capital, or the pressures of a corporate parent.
Ours is a culture of empowerment – one that believes in effort, results, and accountability. We believe that transparency fosters trust, trust foster growth, and that growth drives innovation. Our commitment to rigorous evaluation and relentless execution lead to rapid evolution.
We answer only to the small business owners we serve, and this independence allows us to stay focused on what matters most: helping their businesses thrive by providing expert guidance and best-in-class insurance policies.
We’re growing fast and want you to be a part of it!
We’re seeking a precise, persistent, and coachable Junior Information Security & Compliance Analyst to join our team. Reporting to the Information Security & Compliance Analyst, this role is the execution engine of Veracity's security and compliance program – carrying the recurring, deadline-driven work that keeps the program credible and audit-ready across Veracity, Insurance Canopy, and Ins Cipher.
This is a deliberately structured entry-level role – the incumbent is not expected to arrive with deep security experience, but is expected to be precise, persistent, and coachable, and to build real technical and audit depth on the job. Over time, this person should take full ownership of the recurring compliance calendar and become the company's second line of security response.
Key Responsibilities- Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and elevate per established runbooks
- Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow-up with system owners, and verify and close findings within defined SLAs
- Serve as first-line triage for employee-reported phishing and security questions – escalating confirmed issues promptly with context already gathered
- Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post-incident summary and lessons learned for senior review
- Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps
- Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same-day removal of access for departures
- Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence
- Enforce least-privilege and role-based access practices in day-to-day requests – flagging standing privileges and orphaned accounts for remediation
- Maintain accurate records of privileged accounts, service accounts, and third-party access across business units
- Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently
- Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff
- Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking
- Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review
- Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff
- Draft…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).