Possible Finance Logo

Possible Finance

InfoSec Compliance Analyst

Posted 7 Days Ago
Remote
Hiring Remotely in USA
128K-135K
Mid level
Remote
Hiring Remotely in USA
128K-135K
Mid level
The InfoSec Compliance Analyst will manage audits, compliance initiatives, and security policies to ensure regulatory adherence and risk management.
The summary above was generated by AI

We’re on a mission to help our customers and their communities unlock economic mobility for generations to come. Join the team that’s making our goal a reality.

At Possible, we’re building a new type of consumer finance company. One that helps our customers stay out of debt rather than profit from them staying in it. As a Public Benefit Corporation, it is our mission and responsibility to help communities unlock economic mobility through affordable credit products crafted to improve financial health.

Founded in 2017, our lead VCs are Canvas and Union Square Ventures. We have over 100,000 reviews on the App Store with a 4.8-star average rating.

Since our founding, we have redefined how people approach small-dollar loans—delivering over $1 billion in funding to more than 1 million customers, issuing over 4 million loans, and saving our customers more than $500 million.

We are seeking a driven and meticulous Information Security Compliance Analyst to support the intersection of project management, financial services compliance, and information security initiatives. This cross-functional role will own and lead our Information Technology, Information Security, and Cybersecurity audit and other functions (external IT audits, InfoSec questionnaires, PCI audits, disaster recovery audits, etc.), enabling the organization to maintain regulatory compliance, minimize risk, and safeguard sensitive data.

The ideal candidate will be proactive, organized, and comfortable collaborating across multiple teams, including Product, Engineering, Legal, Compliance, and Operations, and with external parties, including our bank partner and third-party audit firms.

Key ResponsibilitiesInformation Security Support
  • Assist with administering, documenting, auditing, and enforcing the organization's information security policies and standards.
  • Coordinate vulnerability management, user access reviews, and security incident response drills.
  • Support third-party risk management by evaluating vendor security practices and contracts.
  • Lead the annual PCI audit, and associated internal processes and controls.
  • Lead work (i.e., access control review) associated with quarterly and annual tasks to ensure the fulfillment of controls associated with compliance with internal policy, PCI, and SOC requirements.
Compliance & Regulatory Oversight
  • Supervise evolving regulatory requirements within the IT space (primarily PCI DSS, SOC 2) and assist in translating them into actionable internal policies and procedures.
  • Serve as primary owner of responses to audits, examinations, and internal controls testing within the Information Technology, Information Security, and Cybersecurity area.
  • Maintain documentation related to risk assessments, compliance certifications, vendor due diligence, and regulatory filings.
Project Management
  • Serve as a project coordinator for compliance and security-related initiatives, ensuring we achieve our goals and commitments.
  • Develop project plans, handle risk logs, and supervise progress on remediation activities from security assessments or compliance reviews.
Required Qualifications
  • Proven ability in compliance, Information Technology, Information Security, Cybersecurity, and IT Audits, preferably within financial services or fintech environments.
  • Familiarity with IT / InfoSec regulatory standards (Specifically: PCI DSS, ISO 27001, SOC 1 & 2).
  • Deep Understanding of basic information security concepts (e.g., access control, encryption, incident response).
  • Experience with FFIEC Information Technology, Information Security, and Business Continuity Management booklets.
  • Excellent documentation, communication, and organizational skills.
  • Ability to work independently, prioritize multiple tasks, and collaborate with cross-functional stakeholders.
Preferred Qualifications
  • Bachelor’s degree or equivalent experience in Information Security, Business Administration, Risk Management, Finance, or related field.
  • Industry certifications such as:
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP) Associate or full.
  • Familiarity with security technologies (SIEM tools, endpoint protection, encryption technologies).
  • Experience working in AWS environments, with OKTA and Kandji.

This is a Hybrid position. We work in the office three days a week, and our office is centrally located in downtown Seattle.

The compensation range for this role is $127,700 to $134,800. We also offer significant stock options, comprehensive benefits, a bonus plan, commuter benefits, and an excellent office space with complimentary drinks and food options.

Possible Finance is dedicated to financial fairness and community empowerment. We welcome diverse perspectives and experiences to help us achieve our mission of unlocking economic mobility for generations to come.

Learn more about us as a Public Benefit Company.

Top Skills

AWS
Encryption Technologies
Endpoint Protection
Iso 27001
Pci Dss
Siem Tools
Soc 1
Soc 2

Similar Jobs

2 Hours Ago
Remote or Hybrid
Denver, CO, USA
135K-160K Annually
Mid level
135K-160K Annually
Mid level
Sales • Generative AI
As a Customer Success Engineer, you'll interact with customers to troubleshoot technical issues, collaborate with engineering, and advocate for product needs based on customer feedback.
Top Skills: AWSDockerMongodbNestjsReactRedisTerraformTypescriptVite
3 Hours Ago
Remote or Hybrid
Denver, CO, USA
160K-185K Annually
Mid level
160K-185K Annually
Mid level
Sales • Generative AI
Join an early-stage startup as a Staff Engineer, working on a B2B sales platform. You'll develop full-stack features with significant ownership and impact on revenue. Collaborate closely with leadership, focus on customer value, and contribute to product direction through insights and user feedback.
Top Skills: AWSDockerMongodbNestjsReactRedisTerraformTypescriptVite
4 Hours Ago
In-Office or Remote
San Francisco, CA, USA
222K-349K Annually
Expert/Leader
222K-349K Annually
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
The Senior Principal Product Designer will lead design initiatives across teams, delivering high-quality solutions and influencing product direction, while mentoring other designers.
Top Skills: Interaction DesignUxVisual Design

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account