Sr. Cyber Assurance Analyst, Finance
Job in
Redmond, King County, Washington, 98052, USA
Listed on 2026-08-09
Listing for:
SpaceX
Full Time
position Listed on 2026-08-09
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
SR. CYBER ASSURANCE ANALYST, FINANCE
Cyber Assurance is the practice of providing confidence that systems, products and processes meet security, regulatory and compliance obligations. It bridges governance with technical execution -- validating that controls are in place, risks are managed, and requirements are met for both internal and customer-facing systems.
As a teammate you will operate within Information Assurance, working closely with engineers to understand systems, how controls are implemented, be hands-on with collecting and reviewing evidence, and driving efficiencies and remediation efforts, along with providing technical support for finance systems
As an ideal candidate, you love living at the intersection of security, compliance, finance systems, and risk management. You thrive on rolling up your sleeves to dig into configs, access controls, change logs, system designs, and evidence packages while making sense of challenging, complex, or ambiguous requirements. You're as comfortable explaining ITGCs, SOC1/2 and ISO frameworks, and risk concepts to non-technical and technical teams as you are reviewing a user access matrix, validating a change management control, or identifying an insecure default configuration.
You are firm when it matters, but flexible in finding practical ways to move the ball forward. You excel at handling concurrent complex efforts and flourish in an environment where learning never ceases-where the breadth of operations ranges from rockets to financial ledgers, and ERP systems-and where teams are laser-focused on mission accomplishment. Excitement guaranteed.
RESPONSIBILITIES:
- Lead and support ITtesting, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits/certification efforts.
- Partner with engineers and system owners to gather, validate, and package technical evidence for security controls (access management, change management, computer operations, system development lifecycle, configurations, logs, etc.).
- Perform technical security and risk assessments of systems, supporting IT infrastructure, and related networks; identify deviations from security policy, standards, ITrequirements, or regulatory expectations.
- Identify security controls, IT and compliance gaps (especially those impacting financial reporting or SOC readiness), advise on remediation, and drive timely resolution with engineering and process owners.
- Maintain clear documentation of security controls, control processes, risk assessments, evidence, and audit artifacts.
- Identify and drive assessment and audit efficiency through system integration, data analytics/utilization, GRC tooling, automation, and process improvement.
- Support third-party risk management efforts for suppliers, including onboarding assessments and periodic reviews.
- Identify and propose business-enabling actions by maintaining an up-to-date understanding of emerging information security and IT risks, changes in SOC 1/SOC 2 standards, ITbest practices, and new compliance/assurance techniques.
- Mentor fellow teammates and take an active role in their development.
- High school diploma or equivalency certificate.
- 5+ years of experience in cybersecurity compliance, audit or technical security roles with strong knowledge in security compliance frameworks.
- 5+ years of experience with control testing, security standards/policy development, security audits, or security risk management.
- Ability to interpret code/configurations, access controls, change records, and system/network designs for IT SOC 1/SOC 2, and compliance implications.
- Experience with security and compliance tooling such as vulnerability scanners, SIEMs, access review platforms, change management systems, container security, and system configuration baseline checks (e.g., CIS Benchmarks, STIGs).
- Hands-on experience with finance systems (ERP, general ledger, payment, or related platforms) and supporting IT application control testing or certifications.
- Knowledge of U.S. and international regulatory and assurance requirements relevant to finance and IT (e.g., SOX, SOC 1, SOC 2, COSO, NIST, ISO 27001, GDPR, and related frameworks).
- Experience evaluating third-party risk (especially for finance/IT vendors), communicating with external stakeholders/auditors, and supporting mitigations.
- Strong communication skills across all organizational levels and ability to build cross-organizational coalitions (Finance, Engineering, IT, Legal, External Auditors).
- Direct experience with external audits, SOC examinations, regulatory compliance reviews, and management of audit evidence packages.
- Project and program management experience, tooling integration, and delivery in highly fluid…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×