At TaxValet, we are looking for a Sr. Cyber Security Analyst to join our team. This is a Governance, Risk, and Compliance (GRC) role where you will support and improve our security compliance and risk management program. You will work closely with security, engineering, legal, and customer teams to ensure our security posture remains strong, transparent, and audit-ready.
What You'll Do
- Assist in the preparation and execution of third-party audits and assessments, including SOC 2, PCI-DSS, NIST CSF, and ISO 27001.
- Support the development and maintenance of our GRC program, ensuring alignment with business and regulatory requirements through policies, controls, and risk processes.
- Respond to customer security questionnaires and due diligence requests.
- Conduct and manage vendor security assessments, maintain risk tracking, and ensure third-party compliance.
- Perform risk assessments across systems, tools, and business processes; manage mitigation plans and maintain an exceptions register.
- Contribute to access governance, including quarterly access reviews, enforcement of least privilege, and identity and access documentation.
- Draft, review, and update security policies, standards, and procedures to reflect current risk posture and best practices.
- Lead or support security awareness programs to promote a risk-conscious culture among staff and end users.
- Contribute to the development and testing of incident response and disaster recovery plans.
- Monitor and analyze cybersecurity threats, trends, and technologies, and recommend enhancements to security posture.
- Help ensure the security of IT infrastructure by supporting the implementation and maintenance of measures against unauthorized access, cyber threats, and vulnerabilities.
- Track and report on compliance status, audit readiness, and risk trends to key stakeholders.
What We're Looking For
- 3–5 years of experience in cybersecurity or IT risk/compliance, with a focus on GRC.
- Familiarity with major frameworks like SOC 2, PCI-DSS, ISO/IEC 27001, and NIST CSF.
- Experience supporting third-party audits or certifications.
- Knowledge of risk management processes and frameworks.
- Ability to respond to security due diligence questionnaires and document technical and organizational controls.
- Understanding of access governance and identity lifecycle best practices.
- Excellent communication, documentation, and stakeholder coordination skills.
- Comfort with tools like Vanta, Drata, or similar GRC platforms.
Nice to Have
- Experience in a SaaS, FinTech, or regulated technology environment.
- Familiarity with cloud environments such as GCP, AWS, or Azure.
- Understanding of security operations, incident response, or DevSecOps concepts.
- Certifications: CISA – Certified Information Systems Auditor.
- Certifications: ISO 27001 Lead Auditor / Implementer.
- Certifications: PCI ISA – Internal Security Assessor.
Technical Stack
- GRC Platforms: Vanta, Drata
- Cloud: GCP, AWS, Azure
Work Mode
This role is global.
Eltropy is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.





