Info Security Process & Controls Advisor - Mid Level
USAAAbout the role
Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
The Opportunity
As a dedicated Info Security Process & Controls Advisor - Mid Level, you will join our dynamic and growing Information Security team and play a vital role in ensuring the security and compliance of Workforce IAM's critical assets. We are passionate about Governance, Risk, and Compliance (GRC) and are looking for a motivated, diligent, teammate with a risk-based approach individual to chip in to a strong security posture.
Provides information assurance capabilities through technical consultation and guidance to the business for the interpretation and assessment of information security risk for projects, technologies, and environments. Aims to identify and handle existing and emerging risks and integrate risk management strategies and educate risk owners across the enterprise on information security requirements and standard methodologies. Ensures risks associated with business activities are effectively identified, measured, monitored and controlled and administers, and implements systems, policies and processes which serve to enhance the mitigation, reporting, and analysis of Information Security risk.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Colorado Springs, CO, Charlotte, NC, Chesapeake, VA or Tampa, FL. Relocation assistance is not available for this position.
What you'll do:
- Creates and chips in to Information Security governance.
- Publishes, maintains, and/or interprets moderately complex Information Security governance requirements (e.g. policies and standards).
- Performs repeatable methods and measurements to resolve Information Security risk and recommends improvements to the process.
- Performs security risk assessments of moderately complex projects, new technologies, business partners, and third parties.
- Consults with individuals and teams (advice, guidance and assistance) on Information Security risk; guides the security direction of USAA technical projects and initiatives.
- Recommends risk treatment options for technical projects and initiatives.
- Responds both verbally and in writing to routine inquiries and periodic exams from internal control partners (e.g. legal, compliance, audit, risk).
- Guides and assists process owners in the identification, development, and testing of Information Security controls for risk mitigation effectiveness.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
- 4 years of work experience in one or more of the eight areas Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and/or Software Development Security.
- 2 years of related experience in conducting risk assessments, recommending risk treatment options and/or developing program governance (e.g. policies and standards).
- Proficient level of business insight in the areas of business operations, risk management, industry practices and emerging trends.
- Solid understanding of security protocols, application security, cryptography, authentication, authorization, and security.
- Knowledge of applicable information security frameworks, standards, regulatory requirements, and controls.
- Knowledge and application of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, and networking environments.
What sets you apart:
- Experience in audit, risk management, compliance, and governance.
- Experience working with First Line of Defense (FLOD), Second Line of Defense (SLOD), and Third Line of Defense (TLOD) teams is a bonus.
- Possession of or working towards obtaining relevant certifications, such as CISA, CISSP, CRISC, or CIA.
- Consistent track record of successfully testing and evaluating controls and ident
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s