About this Sr. Information Security Analyst role at Betterment
About Betterment
Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays).
About the Role
We are looking for a Senior Information Security professional with deep experience in governance, risk, and compliance to serve as a senior individual contributor on our Govern & Control team. You will own and mature the risk management processes that underpin the trust we hold with clients, investors, and regulators, and you will raise the bar for the analysts around you.
As a technology-driven financial services company, managing information security risk is critical. This role operates within our Govern & Control team, a small, independent second line-of-defense function integrated with the broader security program. The role reports to the Director of Information Security and partners closely with security teams in engineering, lines of business across the company, and other risk functions including Compliance and Legal. As the senior analyst on the team, you will set standards for how the work is done, mentor other analysts, and act as a trusted advisor to stakeholders and leadership.
This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment's total compensation package for employees.
- New York City: [170,000-185,000]
This job may also be eligible for variable compensation in the form of a company incentive bonus.
A Day in the Life
- Leads major program areas with limited supervision, such as vulnerability management, third-party risk, identity theft oversight, business continuity and disaster recovery, or issues management, and is accountable for their outcomes and Key Results (OKRs).
- Leads risk assessment processes end to end, including the hardest and highest-stakes ones, and documents summarized risk conclusions substantiated by data. Sets the template other analysts follow.
- Designs and documents complex internal controls, which may include building reports or automation. AI and automation tooling is available to scale this work, and you are expected to drive that leverage.
- Provides effective challenge, primarily to partners in Engineering, and partners with Compliance and Security Engineering to mature risk processes and reduce risk (new tools, processes, or reporting practices).
- Uses professional judgment and quantifiable methods to measure risk, and drives decisions on accepting or treating risk within our appetite.
- Independently authors high-quality updates to policies and procedures, and owns program-level and KRI reporting to leadership and governance committees. May serve in a leadership role (Chair or Secretary) for a governance committee.
- Acts as escalation point and reviewer for the work of more junior analysts, raising the consistency and quality of the team's output.
- Follows regulatory changes and industry trends closely, maps them to Betterment's business, and stays engaged in the professional community.
What We're Looking For
We are seeking a senior team member who will be a force multiplier for the security program.
Required:
- 6+ years of experience in security GRC, technology risk, technology audit, or security operations, including demonstrated senior-level ownership.
- Expert-level depth in at least one security domain (for example vulnerability management, SDLC, application security, or cloud computing), paired with broad horizontal skills across the business. This is the "T-shaped" profile we expect at this level.
- Deep, hands-on command of security risk management: the CIA triad, control design and operation, and one or more control governance frameworks (for example SOC 2, ISO 27001, NIST CSF).
- Strong command of security controls for cloud computing and third-party SaaS, including logical access management, third-party due diligence and ongoing monitoring, and vulnerability governance.
- Fluency in the structure and content of audit reports and risk assessments, including audit and assessment control testing with appropriate sampling and results reporting.
- Ability to use professional judgment and quantifiable methods to measure risk, and to drive stakeholders to sound risk acceptance or treatment decisions within appetite ("effective challenge").
- Strong cross-disciplinary communication and relationship building, with a track record of influencing without authority across Engineering, business, Compliance, and Legal.
- Moderate understanding of financial services operations and of Product/Engineering.
- Experience learning and applying new skills quickly, including through research and the use of AI and automation.
Encouraged:
- Professional designations such as CISSP, CISA, CISM, AWS Cloud certifications, or other (encouraged, not required).
- Experience in regulated financial services, and with audits or regulatory examinations.
- Experience mentoring analysts or auditors, or leading a governance committee.
Join a team built on these core values
We change lives
Be a part of a community of innovators working to transform financial outcomes for real people. Your work will make an impact, always laddering up to our mission; to empower people to build wealth with confidence and ease.
We set audacious goals
We set them for the company, our customers, and ourselves, and we won’t stop until we reach them. We don’t just show up; we give our all, then celebrate our wins.
We value all perspectives
When we collaborate, we're at our best. We believe diverse perspectives lead to better outcomes and strive to uphold our supportive and inclusive community.
We simplify financial services
We’re financial services pioneers, always finding new ways to improve, optimize, and enhance. Constant improvement is in our DNA.
Our Commitment to Your Total Well-being:
- We offer a competitive suite of benefits, including medical, dental, and vision coverage; life and AD&D insurance; short- and long-term disability; infertility support and WPATH-aligned transgender health benefits; an Employee Assistance Program (EAP); transit benefits and FSA and HSA options
- Ownership: Equity for all employees, including new hire and refresher grants.
- Time: Flexible paid time off, paid parental leave, and a fully paid four-week sabbatical in your sixth year.
- Growth: Company-paid professional coaching for all employees.
- Wealth: Day-one 401(k) match plus matching on qualified student loan payments.
What happens next
We’ll take a few weeks to review all applications. If we’d like to spend more time with you, we’ll reach out to arrange next steps, which will include 3-4 sets of meetings with your future colleagues.
In the interview process, we’ll look to learn more about your skills, experiences, capabilities, and motivators. Many of our questions will be aimed at understanding how you might operate here at Betterment. Depending on the role, we may ask you to complete a case study exercise or technical assessments, as we want to collect a robust set of data points to better inform our decisions.
On average, it takes us around 3-5 weeks to make a hiring decision, depending on your availability and sense of urgency. As a best practice, we aim to interview at least 2-3 final round candidates before making a hiring decision. Please note that, as we usually receive an overwhelming number of applications for open positions, we’re unable to offer individual feedback during the interview process.
We recognize that interviewing for a new role is a big deal. We appreciate you considering Betterment as the next step in your career, and our Recruiting Team is here to support and advocate for you through the interview process!
Betterment is dedicated to providing accommodations to candidates upon request. If you need accommodations at any point throughout the interview process, please reach out to your recruiter.
Please note that in any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Come join us!
We’re an equal opportunity employer and comply with all applicable federal, state, and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees, applicants, or any other covered persons because of race, color, religion, creed, national origin or ancestry, ethnicity, sex, gender (including gender nonconformity and status as a transgender or transsexual individual), sexual orientation, marital status, age, physical or mental disability, citizenship, past, current or prospective service in the uniformed services, predisposing genetic characteristic, domestic violence victim status, arrest records, or any other characteristic protected under applicable federal, state or local law.