Remote (Global)

Ethos is hiring a Sr. Cyber Security Analyst

About the Role

At TaxValet, we are looking for a Sr. Cyber Security Analyst to join our team. This is a Governance, Risk, and Compliance (GRC) role where you will support and improve our security compliance and risk management program. You will work closely with security, engineering, legal, and customer teams to ensure our security posture remains strong, transparent, and audit-ready.

What You'll Do

  • Assist in the preparation and execution of third-party audits and assessments, including SOC 2, PCI-DSS, NIST CSF, and ISO 27001.
  • Support the development and maintenance of our GRC program, ensuring alignment with business and regulatory requirements through policies, controls, and risk processes.
  • Respond to customer security questionnaires and due diligence requests.
  • Conduct and manage vendor security assessments, maintain risk tracking, and ensure third-party compliance.
  • Perform risk assessments across systems, tools, and business processes; manage mitigation plans and maintain an exceptions register.
  • Contribute to access governance, including quarterly access reviews, enforcement of least privilege, and identity and access documentation.
  • Draft, review, and update security policies, standards, and procedures to reflect current risk posture and best practices.
  • Lead or support security awareness programs to promote a risk-conscious culture among staff and end users.
  • Contribute to the development and testing of incident response and disaster recovery plans.
  • Monitor and analyze cybersecurity threats, trends, and technologies, and recommend enhancements to security posture.
  • Help ensure the security of IT infrastructure by supporting the implementation and maintenance of measures against unauthorized access, cyber threats, and vulnerabilities.
  • Track and report on compliance status, audit readiness, and risk trends to key stakeholders.

What We're Looking For

  • 3–5 years of experience in cybersecurity or IT risk/compliance, with a focus on GRC.
  • Familiarity with major frameworks like SOC 2, PCI-DSS, ISO/IEC 27001, and NIST CSF.
  • Experience supporting third-party audits or certifications.
  • Knowledge of risk management processes and frameworks.
  • Ability to respond to security due diligence questionnaires and document technical and organizational controls.
  • Understanding of access governance and identity lifecycle best practices.
  • Excellent communication, documentation, and stakeholder coordination skills.
  • Comfort with tools like Vanta, Drata, or similar GRC platforms.

Nice to Have

  • Experience in a SaaS, FinTech, or regulated technology environment.
  • Familiarity with cloud environments such as GCP, AWS, or Azure.
  • Understanding of security operations, incident response, or DevSecOps concepts.
  • Certifications: CISA – Certified Information Systems Auditor.
  • Certifications: ISO 27001 Lead Auditor / Implementer.
  • Certifications: PCI ISA – Internal Security Assessor.

Technical Stack

  • GRC Platforms: Vanta, Drata
  • Cloud: GCP, AWS, Azure

Work Mode

This role is global.

Eltropy is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Required Skills
VantaDrataGCPAWSAzureSOC 2ISO 27001NISTIncident ResponseVulnerability ManagementSIEMCloud SecurityCompliance FrameworksRisk AssessmentSecurity Auditing
Earn more as a remote developer

Performance pay that rewards your skills

Iglu's revenue-sharing model means top performers earn significantly more than traditional salaries. Choose your projects, deliver great work, and see it reflected in your pay.

Revenue-sharing compensation
Project choice & autonomy
International client base
Career growth support
Check compensation
Top earners exceed market rate
About company
Ethos

Ethos is a leading life insurance technology company on a mission to protect families by democratizing access to life insurance and empowering agents at scale. It offers instant, accessible life insurance products with a seamless online process requiring no medical exams.

Visit website
Job Details
Category security
Posted a month ago