Jobs and Careers
OP

Senior Security Analyst III

OppFi
UKRemotefull_timeVerifiedPosted 11 Nov 2025
💰 $184,800/yr($123,200/yr$184,800/yr)

About the role

OppFi is a leading tech-enabled digital finance platform that works with banks to provide financial products and services for everyday Americans. Through a transparent and responsible platform, which includes financial inclusion and excellent customer experience, the Company supports consumers who are turned away by mainstream options to build better financial health.

We are a team of caring, innovative, and inclusive individuals who thrive in being immersed in diverse talents, expertise, perspectives, and backgrounds. Our employees approach every new challenge with an unparalleled ability to see what could be rather than settle for what is. Our business principles guide us and create an open and collaborative culture where we improve 1% every day, and the best ideas always win! We welcome individuals who want to make an impact in the financial system by facilitating credit access, expanding financial inclusion, promoting financial health, and delivering exceptional customer service.

A few other fun facts about us. OppFi is one of the top consumer-rated financial platforms online, maintaining a 4.5/5.0-star rating on Trustpilot. We are a 2025 Crain’s Fast 50™ company and were named on Built In's 2025 Best Places to Work in Chicago.

Senior Security Analyst III 

As Senior Information Security Analyst III, you will be a key contributor to our day-to-day security operations, assisting with threat monitoring, incident triage, vulnerability remediation, and GRC activities. This role is an excellent opportunity for someone with security experience who is eager to grow their skills in risk management, cloud environments and security best practices. You will work closely with senior team members and various OppFi internal teams to ensure our environment maintains security, visibility, and compliance standards.

What you get to do:

  • Information Security Risk Management
    • Own the security review and assessment process evaluating the risk associated with introducing new applications/tools into the environment.
    • Assist with security risk management activities, including the analysis, quantification, and tracking of information security risks, plus the review and documentation of risk exception requests.
  • Policy and Compliance Analysis: Identify emerging compliance requirements and assess their impact on our policies. Develop and refresh our policies, procedures, standards, and guidelines to stay compliant and aligned with industry best practices.
  • Governance Visibility: Design and maintain dynamic dashboards or scorecards that offer clear insights into Information Security Governance activities, demonstrating our commitment to security and compliance.
  • Security Operations & Incident Support
    • Monitor security alerts from various tools (SIEM, EDR, cloud logs) and support the triage of potential security incidents by gathering initial data and escalating to senior engineers as needed.
    • Assist in the execution of security incident response playbooks, focusing on initial steps like investigation, basic containment, and documentation.
    • Contribute to the documentation and tracking of security incidents to support audit and compliance requirements.
    • Support the monitoring and logging strategy by assisting with the configuration and tuning of SIEM (Security Information and Event Management) alerts and reports.
    • Perform regular log review and analysis for suspicious activities under the guidance of senior staff.
  • Improvement & Collaboration
    • Contribute to the development and maintenance of operational playbooks and documentation for security processes.
    • Learn to deploy and manage new security tools and assist in the development of basic threat detection logic.
    • Develop basic security performance metrics and assist with reporting to measure the effectiveness of security controls.
    • Performs other related duties as assigned.

What you will bring to the team:

  •  3–5 years of professional experience in Information Security or IT Risk Management, with a background supporting IT compliance programs to meet regulatory requirements and demonstrated expertise in at least one of the following areas: Security Operations, Incident Response, or Vulnerability Management.
  • Experience with
    • Security and control frameworks, such as FFIEC, NIST, COBIT, ITIL, and ISO control framework
    • EDR platforms (e.g., CrowdStrike, Defender for Endpoint, SentinelOne)
    • SIEM/SOAR tools (e.g., Sumo Logic, Splunk, Chronicle, or Azure Sentinel)
    • CSPM tools (e.g., Wiz, Prisma, Orca)
    • Vulnerab

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

OppFi

View company profile →