×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Risk & Compliance Analyst

Job in Ponte Vedra Beach, St. Johns County, Florida, 32082, USA
Listing for: APCO Holdings, LLC
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 115000 - 165000 USD Yearly USD 115000.00 165000.00 YEAR
Job Description & How to Apply Below

APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers.

Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.

We are looking for a Senior Security Risk & Compliance Analyst to support and strengthen APCO’s security governance, risk, and compliance (GRC) initiatives. In this role, you will help drive compliance efforts, assess security controls, identify risks, and support the organization’s ongoing commitment to maintaining a strong security posture and regulatory compliance.

What You'll DoAudit & Compliance
  • Support the planning, coordination, and execution of compliance audits, including readiness assessments and external audit engagements
  • Partner with control owners to document, implement, and maintain compliance controls aligned control requirements.
  • Collect, review, and validate audit evidence to ensure completeness and accuracy
  • Track audit findings, exceptions, and remediation efforts through closure
  • Act as a liaison between internal stakeholders and external auditors
Internal Audit
  • Perform internal audits and control assessments to evaluate the effectiveness of security and compliance controls
  • Develop audit plans, testing procedures, and audit reports
  • Identify control gaps and recommend remediation actions
  • Monitor and track remediation efforts to ensure timely resolution
GRC Platform Management
  • Administer and maintain the organization’s GRC platform
  • Configure audit workflows and maintain accurate, up-to-date due diligence responses within the GRC platform.
  • Ensure data integrity and accuracy within the system
  • Generate dashboards and reports for compliance status, audit tracking, and risk posture
Risk Registration & Management
  • Maintain the enterprise risk register, including identification, classification, and documentation of risks
  • Facilitate risk assessments with business and IT stakeholders
  • Evaluate risk severity based on likelihood and impact
  • Track risk treatment plans (remediation, acceptance, transfer, avoidance)
  • Provide regular reporting on risk posture to leadership
Governance & Cross-Functional Collaboration
  • Collaborate with IT, Security, Legal, and business units to ensure alignment with compliance requirements
  • Assist in the development and maintenance of security policies, standards, and procedures
  • Support other compliance initiatives as needed (e.g., regulatory, customer security questionnaires)
Qualifications
  • Bachelor’s degree in Information Security, Information Systems, or related field (or equivalent experience)
  • At least 5 years of experience in security compliance, audit, or GRC
  • Hands‑on experience with SOC 2 audits and Trust Services Criteria and New York 23 NYCRR 500, or other regulatory compliance.
  • Experience with performing internal audits and control testing
  • Familiarity with GRC tools (e.g., Service Now GRC, Archer GRC)
  • Strong understanding of risk management principles and frameworks
  • Knowledge of common frameworks (e.g., AICPA SOC 2, ISO 27001, NIST)
  • Experience with leading cybersecurity due diligence activities, including responding to customer and partner security questionnaires accurately and in a timely manner
  • Strong analytical, organizational, and communication skills
Preferred Certifications
  • Certified Information Systems Auditor (CISA) or
  • Certified in Risk and Information Systems Control (CRISC) or
  • Certified Information Systems Security Professional (CISSP)
This Role Might Be a Great Fit If You…
  • Enjoy identifying risks and improving security processes
  • Thrive in cross-functional, collaborative environments
  • Like balancing technical security concepts with governance and compliance
  • Are motivated by protecting systems, data, and organizational integrity
What We Offer
  • Competiti…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary