This range is provided by United Community. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.
Base pay range
$49,972.00 / yr - $76,958.00 / yr
About The Role
United Community is seeking an experienced Information Security Controls Analyst to serve as a subject matter expert in evaluating and strengthening our cybersecurity and technology controls. This role plays a critical part in assessing risk exposure, recommending control improvements, and ensuring alignment with regulatory standards and business risk tolerance. You'll collaborate with enterprise risk, compliance, and legal teams to provide visibility into our risk posture and drive meaningful change across the organization.
Responsibilities
- Review and document the adequacy of security and technology controls across business and IT environments.
- Evaluate control posture through interviews, documentation reviews, and workflow analysis.
- Recommend and support implementation of risk reduction strategies via policies, procedures, and technical controls.
- Partner with risk management and security leadership to align controls with organizational risk tolerance.
- Identify control strengths and weaknesses related to privacy, security, resiliency, and compliance.
- Document and advocate for control improvements that balance risk with operational efficiency.
- Support control development across testing, QA, and production environments.
- Present control effectiveness reports to senior risk leadership.
- Stay current on regulatory requirements, internal policies, and industry best practices.
- Participate in required compliance training and support internal / external audit activities.
Requirements
3+ years in cybersecurity or IT practitioner roles.2+ years in IT risk or controls analysis.Practical experience with risk management and IT control frameworks.Bachelor's degree preferred in Information Assurance, Computer Science, Engineering, or a related technical field.Strong understanding of risk frameworks (CRI, COSO, RMF, COBIT, NIST).Familiarity with regulatory standards (PCI, FFIEC, SOX, HIPAA, GDPR, CCPA, GLBA).Experience with CIS CSC, ISO 2700, or NIST CSF.Excellent written and verbal communication across all organizational levels.Strong organizational skills and ability to meet SLAs.Sound judgment and decision-making in complex scenarios.High integrity, trustworthiness, and adaptability.Preferred Qualifications
Certifications such as CISSP, CISA, CRISC, or CISM.Technical experience with enterprise networks, applications, and directory services.Familiarity with enterprise GRC platforms.Travel and Work Arrangements
Up to 5% travel required.This is a full-time, non-remote positionConditions of Employment
Must be able to pass a criminal background & credit checkEqual Opportunity Employer
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and / or expression, status as a veteran, and basis of disability or any other federal, state, or local protected class. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
J-18808-Ljbffr