Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
FINRA

Senior Cyber Governance, Risk, Compliance Analyst

FINRA

. Create and maintain cybersecurity policies, procedures, standards, system hardening guidelines, and security baselines .

Posted 10/7/2026full-timeUnited StatesSenior💰 $112,300 - $202,500 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity policy development, risk management, and compliance with NIST, SOC, and PCI frameworks. Proficient in conducting risk assessments, managing vulnerabilities, and supporting security control assessments within AWS environments.

Highest-signal resume keywords
Cybersecurity Policy DevelopmentNIST Risk Management Framework (RMF)AWS Security ControlsGovernance, Risk, and Compliance (GRC)Vulnerability Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentThreat ModelingVulnerability AnalysisSystem Security PlansSecurity Control AssessmentsContinuous MonitoringRisk Treatment StrategiesAudit CoordinationRemediation TrackingMetrics and Dashboards
Soft Skills
CollaborationCommunication
Tools & Technologies
Governance, Risk, and Compliance (GRC) ToolsNIST SP 800-37AWS
Industry Keywords
NISTSOCPCIFINRACybersecurity

Tech Stack

Tools & technologies
AWSCyber Security

About the role

Key responsibilities & impact
  • Create and maintain cybersecurity policies, procedures, standards, system hardening guidelines, and security baselines
  • Maintain enterprise risk registers in Governance, Risk, and Compliance tools
  • Provide regular risk reporting to stakeholders and senior leadership
  • Develop risk treatment strategies, control implementation roadmaps, risk acceptance justifications, and prioritized remediation plans
  • Conduct enterprise IT and cybersecurity risk assessments, including threat modeling, vulnerability analysis, likelihood and impact evaluation, and NIST methodologies
  • Develop, update, and maintain System Security Plans for organizational systems
  • Coordinate and support internal and external audits, assessments, and regulatory examinations
  • Collect audit artifacts from cross-functional teams and source systems
  • Manage end-to-end vulnerability management, including scanning, triage, prioritization, remediation tracking, mitigation validation, metrics, dashboards, and closure of security weaknesses
  • Maintain and update Plan of Action and Milestone documentation through remediation closure
  • Ensure compliance with NIST, SOC, and PCI security frameworks
  • Perform authorization and continuous monitoring activities for information systems
  • Participate in security control assessments and prepare authorization packages and supporting documentation
  • Facilitate Authority to Operate processes and implement continuous monitoring strategies
  • Track and report security control effectiveness, identify deficiencies, and coordinate ongoing assessments
  • Demonstrate FINRA’s values and collaborate in person and virtually in furtherance of FINRA’s investor protection and market integrity mission

Requirements

What you’ll need
  • Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, or equivalent training and/or work experience preferred
  • Minimum of 7 years of professional experience in the design, operation, and monitoring of IT systems, with substantial emphasis on cybersecurity
  • Minimum of 3 years designing, operating, monitoring, and assessing security controls for AWS-based systems
  • Hands-on experience applying the NIST Risk Management Framework (RMF), per NIST SP 800-37, across the full system lifecycle
  • Experience with the Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor RMF steps
  • Experience building, operating, and maintaining an enterprise cyber risk register within a GRC platform from risk identification through closure
  • Knowledge of NIST, SOC, and PCI security frameworks
  • Ability to support security control assessments, authorization packages, Authority to Operate (ATO) processes, and continuous monitoring
  • Ability to collaborate in person and virtually
  • Must comply with FINRA investment, securities account disclosure, confidentiality, invention assignment, and nepotism policies

Benefits

Comp & perks
  • Discretionary bonus eligibility
  • Overtime pay eligibility for non-exempt employees
  • Comprehensive health, dental and vision insurance
  • Basic life, accidental death and dismemberment, supplemental life, spouse/domestic partner and dependent life insurance
  • Spouse/domestic partner and dependent accidental death and dismemberment insurance
  • Short- and long-term disability insurance
  • Long-term care insurance
  • Business travel accident insurance
  • Legal insurance
  • Immediate participation and vesting in a 401(k) plan with company match
  • Eligibility for an additional FINRA-funded retirement contribution
  • Tuition reimbursement
  • Commuter benefits
  • Adoption assistance
  • Backup family care
  • Surrogacy benefits
  • Employee assistance
  • Wellness programs
  • 15 days of paid time off, increasing with years of service up to 25 days
  • 5 personal days
  • 9 sick days
  • 2 volunteer service days
  • Military leave
  • Jury duty leave
  • Bereavement leave
  • Voting and election official leave
  • Care of a family member leave after 90 days of employment
  • Childbirth and parental leave after 90 days of employment
  • 9 paid holidays for full-time employees