SSDLC Risk and Compliance Advisor - Mid Level

USAACharlotte, NC
2dHybrid

About The Position

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families. Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful. The Opportunity We are seeking a motivated and meticulous SSLDC Risk and Compliance Advisor I to join our team supporting technology groups involved in software development, changes, remediations, and outage management. This mid-level role is responsible for ensuring that all processes are performed accurately, in a timely manner, and in strict alignment to industry frameworks and compliance standards from a risk and compliance perspective. Your responsibilities will include monitoring activities, reviewing technical documentation and metrics (such as availability metrics), and ensuring security assessments are performed. While historically the team has focused on IT Operations aspects like configuration management, assessment management, capacity management, service desk, and monitoring, this role will increasingly focus on the Secure Software Development Lifecycle (SSLDC). The ideal candidate will possess experience in risk assessment and compliance monitoring within software development and IT operations environments. You should have a deep understanding of IT operations, coupled with practical experience in software development and secure development lifecycle (SSDLC) practices. An ability to integrate security assessments and compliance requirements seamlessly into the SDLC/SSDLC is needed. Strong analytical skills for reviewing technical documentation, processes, and controls are required, along with a comprehensive awareness of relevant regulatory frameworks including OWASP, NIST 800-53, NIST 800-218, and FFIEC guidelines. Prior experience in large, regulated financial institutions is helpful. Superb communication and teamwork skills are a must. Possession of one or more of the following certifications is highly preferred: CISSP, CISM, or CISA. We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: Charlotte, NC or Tampa, FL. Relocation assistance is not available for this position.

Requirements

  • Bachelor’s degree or 4 additional years of related experience beyond the minimum required may be substituted in lieu of a degree.
  • 4 years relevant experience in risk, compliance, legal or audit within the financial services or insurance industry or specialized technical fields directly related to the role.
  • Risk and/or compliance experience in a highly matrixed environment.
  • Knowledge of compliance laws, regulations, and regulatory expectations.
  • An ability to apply regulatory risk and compliance knowledge to consult and provide guidance.
  • An ability to challenge in business or team settings.
  • Work with internal and external partners in a highly collaborative environment.
  • Critical thinking and knowledge of data analysis tools and techniques and decision-making abilities to recommend data-driven solutions.
  • Proactively identifies potential concerns and recommends solutions.
  • Proficiency with Microsoft Office products including Word, Excel, and PowerPoint

Nice To Haves

  • Risk Assessment & Compliance in IT/SDLC: Experience in conducting risk assessments and performing compliance monitoring within software development and IT operations environments.
  • IT Operations & Secure Development: Deep understanding of IT operations, coupled with practical experience in software development and secure development lifecycle (SSDLC) practices.
  • Integrated Security & Compliance: Ability to integrate security assessments and compliance requirements seamlessly into the Software Development Lifecycle (SDLC) and Secure Software Development Lifecycle (SSDLC).
  • Technical Documentation Analysis: Strong analytical skills for reviewing technical documentation, processes, and controls.
  • Regulatory Framework Knowledge: Comprehensive awareness of relevant regulatory frameworks, including OWASP, NIST 800-53, NIST 800-218, and FFIEC guidelines.
  • Financial Institution Experience: Prior experience working within large, regulated financial institutions.
  • Security Certifications: Possession of one or more of the following highly preferred certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA).
  • Communication & Collaboration: Superb communication, interpersonal, and collaboration skills.

Responsibilities

  • Partners with key team members in the business to identify, assess, aggregate and document risk and compliance controls, including risks associated with new or modified products, services, distribution channels, regulations, and third-party operations.
  • Communicates results of risk and compliance work to governance committees, business process owners and various levels of leadership.
  • Contributes to the implementation of new risk and compliance policies, practices, appetites, and solutions to ensure well-rounded understanding and management of risks according to industry standard process.
  • Implements assigned risk or compliance activities in accordance with enterprise policies and procedures.
  • Maintains and expands knowledge of the competitive/regulatory landscape and the company's key challenges.
  • Reviews laws and regulations for business impact and makes proposals for awareness and action.
  • May coordinate and respond to regulatory requirements and requests and ensures the execution of examinations.
  • Performs work on risk and compliance processes that focus on improving strategies, tools, and methodologies to measure, monitor, and report risks.
  • Applies knowledge to assess data and produce analytical insights to understand business objectives, drive business decisions and influence solution strategies.
  • Actively contributes in multi-functional teams to identify, assess, aggregate, and mitigate current and emerging risk events.
  • Contributes to stress test plans for a line of business or the enterprise including the evaluation of results and framing of contingency plans in partnership with key business partners

Benefits

  • At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs.
  • Additionally, our career path planning and continuing education assists employees with their professional goals.
  • For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service