Junior Information Security & Compliance Analyst
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Support
We're seeking a precise, persistent, and coachable Junior Information Security & Compliance Analyst to join our team. Reporting to the Information Security & Compliance Analyst, this role is the execution engine of Veracity's security and compliance program – carrying the recurring, deadline-driven work that keeps the program credible and audit-ready across Veracity, Insurance Canopy, and Ins Cipher. This is a deliberately structured entry-level role – the incumbent is not expected to arrive with deep security experience, but is expected to be precise, persistent, and coachable, and to build real technical and audit depth on the job.
Over time, this person should take full ownership of the recurring compliance calendar and become the company's second line of security response.
- Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and escalat per established runbooks
- Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow-up with system owners, and verify and close findings within defined SLAs
- Serve as first-line triage for employee-reported phishing and security questions – escalating confirmed issues promptly with context already gathered
- Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post-incident summary and lessons learned for senior review
- Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps
- Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same-day removal of access for departures
- Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence
- Enforce least-privilege and role-based access practices in day-to-day requests – flagging standing privileges and orphaned accounts for remediation
- Maintain accurate records of privileged accounts, service accounts, and third-party access across business units
- Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently
- Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff
- Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking
- Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review
- Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff
- Draft responses to customer and carrier security questionnaires and diligence requests for review by the Information Security & Compliance Analyst
- Maintain the asset inventory and security awareness training program including completion tracking and follow-up with non-completers
- Build and maintain security and compliance metrics reporting – open vulnerabilities, SLA performance, access review status, and training completion
- Write and maintain runbooks, SOPs, and checklists for recurring work so that it is repeatable and transferable
- Partner with IT, Engineering, Compliance, Legal, and Service teams so that controls are applied consistently without unnecessary friction to the business
- Identify repetitive security and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).