Jobs · Legal · Georgia

Senior Security Risk & Compliance Analyst

APCO Holdings, LLC · Norcross, GA · 2 days ago
On-siteLegalFull-time
APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers. Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve. We are looking for a Senior Security Risk & Compliance Analyst to support and strengthen APCO’s security governance, risk, and compliance (GRC) initiatives. In this role, you will help drive compliance efforts, assess security controls, identify risks, and support the organization’s ongoing commitment to maintaining a strong security posture and regulatory compliance. What You'll Do Audit & Compliance Support the planning, coordination, and execution of compliance audits, including readiness assessments and external audit engagementsPartner with control owners to document, implement, and maintain compliance controls aligned control requirements.Collect, review, and validate audit evidence to ensure completeness and accuracyTrack audit findings, exceptions, and remediation efforts through closureAct as a liaison between internal stakeholders and external auditors Internal Audit Perform internal audits and control assessments to evaluate the effectiveness of security and compliance controlsDevelop audit plans, testing procedures, and audit reportsIdentify control gaps and recommend remediation actionsMonitor and track remediation efforts to ensure timely resolution GRC Platform Management Administer and maintain the organization’s GRC platformConfigure audit workflows and maintain accurate, up-to-date due diligence responses within the GRC platform.Ensure data integrity and accuracy within the systemGenerate dashboards and reports for compliance status, audit tracking, and risk posture Risk Registration & Management Maintain the enterprise risk register, including identification, classification, and documentation of risksFacilitate risk assessments with business and IT stakeholdersEvaluate risk severity based on likelihood and impactTrack risk treatment plans (remediation, acceptance, transfer, avoidance)Provide regular reporting on risk posture to leadership Governance & Cross-Functional Collaboration Collaborate with IT, Security, Legal, and business units to ensure alignment with compliance requirementsAssist in the development and maintenance of security policies, standards, and proceduresSupport other compliance initiatives as needed (e.g., regulatory, customer security questionnaires) Qualifications Bachelor’s degree in Information Security, Information Systems, or related field (or equivalent experience)At least 5 years of experience in security compliance, audit, or GRCHands-on experience with SOC 2 audits and Trust Services Criteria and New York 23 NYCRR 500, or other regulatory compliance.Experience with performing internal audits and control testingFamiliarity with GRC tools (e.g., ServiceNow GRC, Archer GRC)Strong understanding of risk management principles and frameworksKnowledge of common frameworks (e.g., AICPA SOC 2, ISO 27001, NIST)Experience with leading cybersecurity due diligence activities, including responding to customer and partner security questionnaires accurately and in a timely mannerStrong analytical, organizational, and communication skills Preferred Certifications Certified Information Systems Auditor (CISA) orCertified in Risk and Information Systems Control (CRISC) orCertified Information Systems Security Professional (CISSP) This Role Might Be a Great Fit If You… Enjoy identifying risks and improving security processesThrive in cross-functional, collaborative environmentsLike balancing technical security concepts with governance and complianceAre motivated by protecting systems, data, and organizational integrity What We Offer Competitive compensationComprehensive medical, dental, and vision benefits401(k) with company matchPaid time off and company holidaysOpportunities for professional growth and certification supportA collaborative and security-focused work environment At APCO, the way we work matters just as much as the results we deliver. Our values guide how we work, how we partner, and how we deliver results. We C.A.R.E. Committed - We build strong, high-trust relationships with our partners and each other. Accountable - We take ownership of outcomes and hold ourselves to the highest standards of performance and integrity. Results-Driven - We focus on delivering measurable outcomes that create value for our partners and our business. Excellent - We strive for excellence in everything we do while balancing short-term performance with long-term success. If you're excited about joining a team that values collaboration, accountability, and continuous improvement, we'd love to hear from you. By submitting your application, you acknowledge that you have read and understand our Privacy Policy and Terms & Conditions. APCO Holdings may collect personal information (such as name, contact details, and employment history) to evaluate your candidacy. We may share this data with our subsidiaries, affiliates, and service providers. We retain applicant data only as long as necessary for the hiring process or as required by law.

Similar jobs