Junior Information Security & Compliance Analyst

🏢 Veracity Insurance · all 7 jobs
📍 United States
💰 USD 55,000 - 70,000 / annual
📅 Posted Sep 20, 2026 · via Himalayas
🏷 Infosec, Compliance Analyst, Security Operations, It Compliance, Cybersecurity, It Security And Compliance Analyst +8 more
Apply on original site ↗

At Veracity, we aim to be a different kind of insurance partner – one that is free from outside investors, venture capital, or the pressures of a corporate parent.

Ours is a culture of empowerment – one that believes in effort, results, and accountability. We believe that transparency fosters trust, trust fosters growth, and that growth drives innovation. Our commitment to rigorous evaluation and relentless execution lead to rapid evolution.

We answer only to the small business owners we serve, and this independence allows us to stay focused on what matters most: helping their businesses thrive by providing expert guidance and best-in-class insurance policies.

We’re growing fast and want you to be a part of it!

We're seeking a precise, persistent, and coachable Junior Information Security & Compliance Analyst to join our team. Reporting to the Information Security & Compliance Analyst, this role is the execution engine of Veracity's security and compliance program – carrying the recurring, deadline-driven work that keeps the program credible and audit-ready across Veracity, Insurance Canopy, and InsCipher.

This is a deliberately structured entry-level role – the incumbent is not expected to arrive with deep security experience, but is expected to be precise, persistent, and coachable, and to build real technical and audit depth on the job. Over time, this person should take full ownership of the recurring compliance calendar and become the company's second line of security response.

Key Responsibilities

- Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and escalate per established runbooks

- Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow-up with system owners, and verify and close findings within defined SLAs

- Serve as first-line triage for employee-reported phishing and security questions – escalating confirmed issues promptly with context already gathered

- Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post-incident summary and lessons learned for senior review

- Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps

- Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same-day removal of access for departures

- Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence

- Enforce least-privilege and role-based access practices in day-to-day requests – flagging standing privileges and orphaned accounts for remediation

- Maintain accurate records of privileged accounts, service accounts, and third-party access across business units

- Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently

- Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff

- Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking

- Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review

- Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff

- Draft responses to customer and carrier security questionnaires and diligence requests for review by the Information Security & Compliance Analyst

- Maintain the

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote legal role.All remote legal jobs →
Get new legal jobs by email
Daily email, only when there's something new. One click to stop.

Get remote legal jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you