Cloud Risk and Management Advisor - Mid Level
About the Role
We are seeking a Mid-Level Risk and Compliance professional with 6+ years of hands-on experience in Cloud Governance, Risk and Controls. In this role, you will work closely with architecture, application development, security, audit, and business teams to identify, assess, and mitigate technology risks impacting USAA’s cloud environments while ensuring compliance with internal policies and industry regulations.
The ideal candidate will have practical experience conducting risk assessments, evaluating cloud controls, maintaining governance frameworks, supporting audits, and integrating cloud control requirements throughout the software development lifecycle. This includes reviewing, assessing, and remediating security and compliance controls across public cloud (AWS, Azure, GCP) and private cloud (OpenShift) environments, as well as evaluating cloud control frameworks and executing control testing for identity and access management, network segmentation, data protection, logging and monitoring, and configuration drift.
You will translate technical findings into business impact, prioritize remediation based on risk, and validate closure of findings through retesting and evidence collection. A strong understanding of industry frameworks and standards such as Cloud Security Alliance’s CCM, NIST, ISO 27001, COBIT, OWASP, and SOC 2 is essential, along with experience supporting compliance and governance initiatives in a complex IT environment. Strong communication, documentation, stakeholder management, and analytical skills are critical for success.
Industry-recognized certifications, including PCCSP, CISSP, CISM, CRISC, CISA, Security+, or similar risk and security certifications, are highly valued. Candidates with experience in cloud security governance, DevSecOps practices, vulnerability management, and secure application development will excel in this role.
This position offers a flexible work environment requiring in-office presence 4 days per week and can be based in Charlotte, NC, San Antonio, TX, Plano, TX, or Tampa, FL. Relocation assistance is not available.
Responsibilities
- Partner with key stakeholders to identify, assess, aggregate, and document risk and compliance controls, including risks associated with new or modified products, services, distribution channels, regulations, and third-party operations.
- Communicate results of risk and compliance work to governance committees, business process owners, and various levels of leadership.
- Contribute to the implementation of new risk and compliance policies, practices, appetites, and solutions to ensure holistic understanding and management of risks according to industry best practices.
- Execute assigned risk or compliance activities in accordance with enterprise policies and procedures.
- Maintain and expand knowledge of the competitive/regulatory landscape and the company's key challenges.
- Review laws and regulations for business impact and propose awareness and action plans.
- Coordinate and respond to regulatory requirements and requests, ensuring the execution of examinations.
- Enhance strategies, tools, and methodologies to measure, monitor, and report risks.
- Apply knowledge to assess data and produce analytical insights to drive business decisions and influence solution strategies.
- Actively contribute in cross-functional teams to identify, assess, aggregate, and mitigate current and emerging risk events.
- Contribute to stress test plans for a line of business or the enterprise, including evaluating results and framing contingency plans in partnership with key business stakeholders.
Requirements
- Bachelor’s degree; OR 4 years of relevant education and/or experience.
- 6+ years of relevant experience in risk, compliance, legal, or audit within the financial services or insurance industry or specialized technical fields directly related to the role.
- Extensive exposure to Cloud Native Application Platforms (CNAPP), such as Prisma, Orca, and Wiz.
- Risk and/or compliance experience in a highly matrixed environment.
- Knowledge of compliance laws, regulations, and regulatory expectations.
- Demonstrated ability to apply regulatory risk and compliance knowledge to consult and provide guidance.
- Ability to effectively challenge in business or team settings.
- Ability to work collaboratively with internal and external partners.
- Demonstrated critical thinking and knowledge of data analysis tools and techniques to recommend data-driven solutions.
- Proactively identify potential concerns and recommend solutions.
- Advanced proficiency with Microsoft Office products including Word, Excel, and PowerPoint.
Preferred Qualifications
- US military experience gained through military service or as a military spouse/domestic partner.
- Industry-recognized certifications, including PCCSP, CISSP, CISM, CRISC, CISA, Security+, or similar cloud controls certifications.
- Experience with cloud security governance and risk management across platforms such as Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform (GCP).
- Familiarity with DevSecOps methodologies, CI/CD security controls, secure code review practices, and vulnerability management processes.
- Experience implementing or supporting Secure Software Development Lifecycle (SSDLC) practices within enterprise technology environments.
- Knowledge of industry-standard frameworks and controls, including CSA CCM, NIST, ISO 27001, COBIT, OWASP, and SOC 2.
- Experience working in highly regulated industries, such as financial services, healthcare, insurance, government, or technology organizations.
- Strong ability to collaborate with cross-functional stakeholders, including engineering, security, audit, compliance, and business teams.
Pay
The salary range for this position is $85,040.00 - $162,550.00. USAA does not provide visa sponsorship for this role.
Benefits
- Comprehensive medical, dental, and vision plans.
- 401(k) and pension plans.
- Life insurance.
- Parental benefits and adoption assistance.
- Paid time off program with paid holidays plus 16 paid volunteer hours.
- Various wellness programs.
- Career path planning and continuing education to support professional goals.