Sr. Information Security Analyst

Betterment•New York, NY
•$170,000 - $185,000•Hybrid

About The Position

Betterment is seeking a Senior Information Security professional with deep experience in governance, risk, and compliance to serve as a senior individual contributor on their Govern & Control team. This role will own and mature the risk management processes that underpin the trust Betterment holds with clients, investors, and regulators. The role operates within the Govern & Control team, a small, independent second line-of-defense function integrated with the broader security program. The role reports to the Director of Information Security and partners closely with security teams in engineering, lines of business across the company, and other risk functions including Compliance and Legal. As the senior analyst on the team, this individual will set standards for how the work is done, mentor other analysts, and act as a trusted advisor to stakeholders and leadership. This role is based out of their NYC office and is eligible for variable compensation in the form of a company incentive bonus.

Requirements

  • 6+ years of experience in security GRC, technology risk, technology audit, or security operations, including demonstrated senior-level ownership.
  • Expert-level depth in at least one security domain (for example vulnerability management, SDLC, application security, or cloud computing), paired with broad horizontal skills across the business. This is the "T-shaped" profile expected at this level.
  • Deep, hands-on command of security risk management: the CIA triad, control design and operation, and one or more control governance frameworks (for example SOC 2, ISO 27001, NIST CSF).
  • Strong command of security controls for cloud computing and third-party SaaS, including logical access management, third-party due diligence and ongoing monitoring, and vulnerability governance.
  • Fluency in the structure and content of audit reports and risk assessments, including audit and assessment control testing with appropriate sampling and results reporting.
  • Ability to use professional judgment and quantifiable methods to measure risk, and to drive stakeholders to sound risk acceptance or treatment decisions within appetite ("effective challenge").
  • Strong cross-disciplinary communication and relationship building, with a track record of influencing without authority across Engineering, business, Compliance, and Legal.
  • Moderate understanding of financial services operations and of Product/Engineering.
  • Experience learning and applying new skills quickly, including through research and the use of AI and automation.

Nice To Haves

  • Professional designations such as CISSP, CISA, CISM, AWS Cloud certifications, or other.
  • Experience in regulated financial services, and with audits or regulatory examinations.
  • Experience mentoring analysts or auditors, or leading a governance committee.

Responsibilities

  • Leads major program areas with limited supervision, such as vulnerability management, third-party risk, identity theft oversight, business continuity and disaster recovery, or issues management, and is accountable for their outcomes and Key Results (OKRs).
  • Leads risk assessment processes end to end, including the hardest and highest-stakes ones, and documents summarized risk conclusions substantiated by data. Sets the template other analysts follow.
  • Designs and documents complex internal controls, which may include building reports or automation. AI and automation tooling is available to scale this work, and you are expected to drive that leverage.
  • Provides effective challenge, primarily to partners in Engineering, and partners with Compliance and Security Engineering to mature risk processes and reduce risk (new tools, processes, or reporting practices).
  • Uses professional judgment and quantifiable methods to measure risk, and drives decisions on accepting or treating risk within our appetite.
  • Independently authors high-quality updates to policies and procedures, and owns program-level and KRI reporting to leadership and governance committees. May serve in a leadership role (Chair or Secretary) for a governance committee.
  • Acts as escalation point and reviewer for the work of more junior analysts, raising the consistency and quality of the team's output.
  • Follows regulatory changes and industry trends closely, maps them to Betterment's business, and stays engaged in the professional community.

Benefits

  • medical, dental, and vision coverage
  • life and AD&D insurance
  • short- and long-term disability
  • infertility support and WPATH-aligned transgender health benefits
  • an Employee Assistance Program (EAP)
  • transit benefits
  • FSA and HSA options
  • Equity for all employees, including new hire and refresher grants.
  • Flexible paid time off
  • paid parental leave
  • a fully paid four-week sabbatical in your sixth year.
  • Company-paid professional coaching for all employees.
  • Day-one 401(k) match plus matching on qualified student loan payments.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service