Summary
Veracity Insurance Solutions is an independent insurance partner focused on helping small business owners thrive through expert guidance and insurance policies. The company is seeking an entry-level Information Security & Compliance Analyst to execute recurring security, compliance, audit-readiness, access management, incident response, and vulnerability management activities.
Responsibilities
- Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and escalate per established runbooks
- Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow-up with system owners, and verify and close findings within defined SLAs
- Serve as first-line triage for employee-reported phishing and security questions – escalating confirmed issues promptly with context already gathered
- Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post-incident summary and lessons learned for senior review
- Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps
- Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same-day removal of access for departures
- Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence
- Enforce least-privilege and role-based access practices in day-to-day requests – flagging standing privileges and orphaned accounts for remediation
- Maintain accurate records of privileged accounts, service accounts, and third-party access across business units
- Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently
- Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff
- Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking
- Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review
- Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff
- Draft responses to customer and carrier security questionnaires and diligence requests for review by the Information Security & Compliance Analyst
- Maintain the asset inventory and security awareness training program including completion tracking and follow-up with non-completers
- Build and maintain security and compliance metrics reporting – open vulnerabilities, SLA performance, access review status, and training completion
- Write and maintain runbooks, SOPs, and checklists for recurring work so that it is repeatable and transferable
- Partner with IT, Engineering, Compliance, Legal, and Service teams so that controls are applied consistently without unnecessary friction to the business
- Identify repetitive security and compliance tasks that can be automated or streamlined and propose improvements
- Required to perform other duties as requested, directed, or assigned
Skills
- 0–2 years of professional experience – internships, IT helpdesk or support, systems administration, or audit and compliance support all count; this role is intended to be a first or second job in security
- Bachelor's degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or a relevant certification in lieu of a degree
- Working familiarity with at least one major cloud or productivity platform – AWS, Microsoft 365/Azure, or Google Workspace – including where users, permissions, and logs live
- Demonstrated ability to own recurring, detail-heavy work to completion without reminders
- Comfort with spreadsheets, ticketing systems such as Jira, and documentation tools
- Excellent verbal and written communication skills – able to ask a busy system owner for evidence and actually get it, and to write documentation an auditor will accept
- Sound judgment and discretion handling sensitive, regulated, and confidential information including customer PII and NPI
- Coachability and genuine curiosity about security – willing to be taught and willing to say "I don't know" early rather than let an item quietly slip
- Composure under pressure during audits, incidents, and deadlines
Qualifications
Must Haves
- 0–2 years of professional experience – internships, IT helpdesk or support, systems administration, or audit and compliance support all count; this role is intended to be a first or second job in security
- Bachelor's degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or a relevant certification in lieu of a degree
- Working familiarity with at least one major cloud or productivity platform – AWS, Microsoft 365/Azure, or Google Workspace – including where users, permissions, and logs live
- Demonstrated ability to own recurring, detail-heavy work to completion without reminders
- Comfort with spreadsheets, ticketing systems such as Jira, and documentation tools
- Excellent verbal and written communication skills – able to ask a busy system owner for evidence and actually get it, and to write documentation an auditor will accept
- Sound judgment and discretion handling sensitive, regulated, and confidential information including customer PII and NPI
- Coachability and genuine curiosity about security – willing to be taught and willing to say "I don't know" early rather than let an item quietly slip
- Composure under pressure during audits, incidents, and deadlines
Benefits
- Health, dental, and vision plans
- Amazing work-life balance with 4 weeks of Paid Time Off
- 10 Paid Company Holidays with 2 floating holidays
- 401K Programs with employer match
- Personal assistance programs for support in a healthy personal and work life
- A culture that prioritizes growth and development