Senior Cyber Governance, Risk, Compliance Analyst

FINRA•Rockville, MD
•$97,700 - $211,400•Hybrid

About The Position

The Senior Security Analyst is responsible for supporting functions spanning IT Risk Management and Governance & Compliance operations. This role will work across enterprise-wide cybersecurity initiatives, balancing strategic risk with tactical compliance execution.

Requirements

  • Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, or equivalent training and / or work experience preferred.
  • Minimum of seven (7) years of professional experience in the design, operation, and monitoring of IT systems, with substantial emphasis on cybersecurity.
  • Minimum three (3) years designing, operating, monitoring, and assessing security controls for AWS-based systems.
  • Hands-on experience applying the NIST Risk Management Framework (RMF, per NIST SP 800-37) across the full system lifecycle, including the Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor steps
  • Proven experience building, operating, and maintaining an enterprise cyber risk register within a GRC platform from risk identification through closure.

Responsibilities

  • Create and maintain cybersecurity policies, procedures, and standards documentation including system hardening guidelines and security baselines.
  • Create and maintain cybersecurity policies, procedures, and standards documentation.
  • Maintain enterprise risk registers within Governance, Risk, and Compliance tools and provide regular risk reporting to stakeholders and senior leadership.
  • Maintain risk registers and provide regular risk reporting to stakeholders.
  • Develop risk treatment strategies and recommendations to technical teams including control implementation roadmaps, risk acceptance justifications, and prioritized remediation plans.
  • Conduct IT and cybersecurity risk assessments across the enterprise environment, including threat modeling, vulnerability analysis, likelihood and impact evaluation, and the application of established risk assessment methodologies (NIST) to identify and quantify risks to information systems.
  • Develop, update, and maintain System Security Plans (SSPs) for organizational systems.
  • Coordinate and support internal and external audits, assessments, and regulatory examinations by proactively collecting artifacts from cross-functional teams while independently gathering as much documentation as possible directly from source systems to streamline the audit process and reduce operational impact on other departments.
  • Manage end-to-end vulnerability management processes, including coordinating vulnerability scanning activities, triaging and prioritizing identified vulnerabilities based on severity, tracking remediation efforts through completion, validating successful mitigation, maintaining metrics and reporting dashboards, and ensuring timely closure of security weaknesses in alignment with organizational policies and risk tolerance.
  • Maintain and update Plan of Action and Milestone (POA&M) documentation to include tracking remediation activities to closure.
  • Ensure compliance with applicable security frameworks (NIST, SOC, PCI).
  • Provide authorization and continuous monitoring activities for information systems by participating in security control assessments, preparing authorization packages and supporting documentation, facilitating Authority to Operate (ATO) processes, implementing continuous monitoring strategies, tracking and reporting on security control effectiveness, identifying control deficiencies, and coordinating ongoing assessments to maintain authorization status throughout the system lifecycle.
  • Demonstration of FINRA’s values.
  • Collaboration, both in-person and virtually, in furtherance of FINRA’s mission of investor protection and market integrity.

Benefits

  • comprehensive health, dental and vision insurance
  • basic life, accidental death and dismemberment, supplemental life, spouse/domestic partner and dependent life, and spouse/domestic partner and dependent accidental death and dismemberment, short- and long-term disability, long-term care, business travel accident, disability and legal
  • immediate participation and vesting in a 401(k) plan with company match
  • eligibility for participation in an additional FINRA-funded retirement contribution
  • tuition reimbursement
  • commuter benefits
  • adoption assistance
  • backup family care
  • surrogacy benefits
  • employee assistance
  • wellness programs
  • discretionary bonus
  • overtime pay
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service