×
Register Here to Apply for Jobs or Post Jobs. X

Sr IT Risk Security Analyst

Job in San Jose, Santa Clara County, California, 95199, USA
Listing for: Symetra
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 80000 - 133000 USD Yearly USD 80000.00 133000.00 YEAR
Job Description & How to Apply Below

Company Overview

Symetra Investment Management ("SIM") is a SEC-registered investment advisory firm with approximately $78 billion in assets under management as of March 31, 2025. Symetra Financial Corporation ("SFC") , a diversified financial services company with $68.4 billion in assets as of December 31, 2024, headquartered in Bellevue, Washington is the sole shareholder of SIM. SFC is also the holding company of Symetra Life Insurance Company ("Symetra Life") , which was founded in 1957, and has insurer financial strength ratings of 'A' by A.M. Best and Standard & Poor's and 'A1' by Moody's.

Symetra Life is among the top 40 largest life insurance companies in the United States (based on statutory admitted assets as of December 31, 2024) and has approximately 2.3 million customers and over 2,600 employees nationwide. SFC is a wholly owned subsidiary of Sumitomo Life Insurance Company, a mutual life insurance company with head offices in Osaka and Tokyo, Japan.

Founded in 1907, Sumitomo is one of the largest life insurance companies in Japan with $327 billion of assets as of March 31, 2025. SIM currently has recently begun marketing its investment management services to third-party institutional investors.

About the role

The Senior IT Risk and Security Analyst (RSA) is a critical member of the Information Security Officer's (ISO's) team. The RSA's role is to act as an interface between IT, Audit Services and the business for overall IT risk management. The RSA must be able to understand our current IT Control environment including IT General Controls and ISO 27001 Information Security Critical Controls while improving our risk posture.

The RSA coordinates with several stakeholders including business, audit services, and IT to manage, evaluate and remediate issues.

What you will do
  • Serve as a trusted advisor to IT and business teams by identifying technology, security, and operational risks, recommending effective controls, and ensuring risks are properly assessed, documented, and mitigated.
  • Lead enterprise IT risk management activities, including annual risk assessments, risk committee facilitation, risk reporting, policy development, risk register management, and continuous improvement of the organization's risk management framework.
  • Support third-party technology risk management across the vendor lifecycle, including risk tiering, pre-contract due diligence, security assessments, and periodic monitoring. Evaluate SOC reports, ISO 27001 certifications, security questionnaires, penetration tests, external security ratings, encryption and data-handling practices, AI usage, contractual controls, and business continuity capabilities; document risk ratings and findings, drive remediation, and elevate unresolved risks in partnership with Procurement, Legal, business owners, and security teams.
  • Manage and enhance IT audit and compliance programs, including SOX IT General Controls (ITGCs), ISO 27001 security controls, regulatory requirements, and internal/external audit activities to ensure controls are designed and operating effectively.
  • Partner with control owners, auditors, and business stakeholders to track audit findings, drive remediation efforts, provide training, and ensure sustainable compliance across technology and business functions.
  • Evaluate third-party vendors, emerging technologies, and business initiatives to identify security and operational risks, implement monitoring controls, and support disaster recovery and business continuity planning efforts.
  • Develop executive-level reporting and dashboards that communicate risk exposure, audit results, compliance status, and remediation progress to senior leadership and governance committees.
  • Conduct reviews of information systems, business applications, infrastructure, and operational processes to assess security posture, control effectiveness, and alignment with company objectives.
  • Maintain ownership of risk management tools and processes, ensuring accurate documentation, reporting, workflow management, and ongoing program maturity.
Who You Are
  • You're an analytical problem solver with a strong understanding of information security, IT risk management, audit methodologies, compliance frameworks, and internal controls.
  • You have experience managing complex risk assessments, audit programs, and compliance initiatives, with the ability to translate technical risks into business-focused recommendations.
  • You're an effective communicator who can confidently collaborate with executives, auditors, IT leaders, business stakeholders, and external vendors to influence positive outcomes.
  • You thrive working independently while also serving as a trusted advisor, mentor, and subject matter expert for colleagues and cross-functional teams.
  • You possess strong organizational skills and attention to detail, enabling you to manage multiple priorities, maintain accurate documentation, and deliver high-quality results in a fast-paced environment.
Nice to Haves
  • Bachelor's degree in information…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary