Principal IT Security Analyst
NewrezAbout the role
Who We Are
At Newrez, we bring big thinkers and caring doers together to make home happen. We’re a team built on heart and hustle, united by a commitment to show up for our customers, our communities, and each other. We believe that when our people thrive, homeowners thrive - and that’s why we invest in your growth, wellbeing, and ability to make an impact.
Every day, we work to exceed the expectations of our residential mortgage borrowers and business partners through superior service, simple processes, and clear communication. We do this by empowering our employees, encouraging innovative solutions and recognizing great performance.
POSITION SUMMARY
The Principal IT Security Analyst is a senior subject matter contributor within the Information Security organization, serving as a key facilitator for IT and security related audits and compliance activities. This role is a hybrid of auditor, security operations awareness, and security engineering/architecture input, with primary emphasis on audit facilitation, stakeholder communication, and audit readiness rather than hands on tool administration. The position acts as a central liaison between auditors, technical teams, control owners, and leadership, ensuring audit requirements are clearly understood, evidence is well organized, and audit outcomes are communicated effectively.
DESCRIPTION
Essential Functions, Duties, and Responsibilities
- Serve as the primary point of contact for internal and external auditors supporting SOX, SOC, and other regulatory or assurance engagements.
- Facilitate communication between auditors, Information Security, IT, and business stakeholders to ensure consistent understanding of audit scope and expectations.
- Coordinate the end-to-end audit lifecycle, including planning, walkthrough scheduling, evidence collection, follow up, and issue closure.
- Assist in developing, implementing, and executing the organization’s IT and security compliance program.
- Identify audit issues, documentation gaps, and control weaknesses, including approvals, segregation of duties, and evidence sufficiency concerns.
- Support root cause analysis discussions and guide stakeholders toward practical, risk appropriate remediation actions.
- Track audit findings, management responses, and remediation commitments through completion.
- Prepare clear, concise audit status updates, summaries, and executive level communications.
- Support leadership with audit narratives, management responses, and clarification of control intent.
- Assist control owners and performers in understanding compliance expectations and evidence standards.
- Provide input to align Information Security and IT policies, standards, and procedures with audit and regulatory requirements.
- Promote consistency, quality, and repeatability in audit documentation and evidence collection processes.
- Evaluate IT and security controls across on premises and cloud environments to assess audit impact and readiness.
- Apply working knowledge of security architecture, cloud platforms, and security tooling to contextualize audit requirements and discussions.
- Participate in architecture or design discussions as needed to assess control alignment and audit implications, without owning technical implementation.
- Develop and maintain high quality audit documentation, control narratives, and support artifacts.
- Support the development of audit related metrics and reporting to monitor program effectiveness and risk trends.
- Escalate unresolved audit or compliance concerns using established governance processes.
- Ability to effectively and accurately convey information to others.
- Perform related duties as assigned by management.
Qualifications and Education Requirements
- Bachelor’s degree in computer science, Information Systems, Information Assurance, or equivalent professional experience.
- 5–7+ years of experience in IT audit, IT compliance, information security, or regulatory assurance roles.
- Demonstrated experience supporting SOX, SOC, and security related audits in complex environments.
- Strong understanding of IT and security control environments and audit methodologies.
- Professional certifications such as CISA, CISSP, CRISC, CGEIT, GRCP, or similar preferred or in progress.
Skills, Abilities, and Knowledge
- Strong knowledge of IT and security controls, governance concepts, and audit practices.
- Ability to operate effectively as an audit facilitator and liaison, rather than a hands-on security operator.
- Working knowledge of security architectures, cloud environments, and common security technologies sufficient to support audit discus
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s