- Home
- Jobs
- Information Security
- Senior Analyst, Information Security (R14050)

Senior Analyst, Information Security (R14050) at Oportun
Remote - India Full-timeRemoteInformation SecurityPosted 3 days ago
Apply with PipelineAbout the Role
<div class="content-intro"><h3 style="margin: 0in;"><span style="font-size: 12pt;"><strong><span style="font-family: 'Arial',sans-serif; color: black;">ABOUT OPORTUN<br></span></strong></span></h3>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members' financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.</span></p>
<p style="margin: 0in; text-align: justify;"><span style="font-family: Arial, sans-serif; color: black; font-size: 12pt;"> </span></p>
<h3 style="margin: 0in; text-align: justify;"><span style="font-size: 12pt;"><strong><span style="font-family: 'Arial',sans-serif; color: black;">WORKING AT OPORTUN</span></strong></span></h3>
<p style="margin: 0in; text-align: justify;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"><br>Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization's performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.</span></p></div><p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>POSITION SUMMARY</strong></span></p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">The Information Security Governance & Awareness Senior Analyst supports and advances the organization’s information security governance and security awareness programs through policy lifecycle management, governance analysis, regulatory mapping, metrics reporting, and targeted security education initiatives.</span></p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">This role is responsible for coordinating and contributing to the development, maintenance, review, approval, and publication of information security policies, standards, procedures, and related governance documentation. The Senior Analyst applies critical thinking and sound judgment to assess governance documentation against regulatory and framework requirements and helps identify potential gaps, inconsistencies, or improvement opportunities.</span></p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">The ideal candidate possesses strong technical writing and analytical skills, excellent English language comprehension, attention to detail, and the ability to translate complex security and regulatory concepts into clear, actionable governance documentation and awareness communications.</span></p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">This role also supports organizational security culture initiatives through audience-appropriate awareness content, phishing simulation activities, and security education support aligned to organizational risks and business objectives.</span></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>RESPONSIBILITIES</strong></span></p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>Security Governance & Policy Management</strong></span></p>
<ul style="text-align: justify;">
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Manage and support the lifecycle of information security policies, standards, procedures, and related governance documentation.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Coordinate document reviews, stakeholder collaboration, approvals, renewals, attestations, and publication timelines.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Track policy review schedules, exceptions, approvals, versioning, and governance workflow activities.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Interpret and map regulatory and framework requirements to organizational governance documents and controls.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Support governance alignment efforts related to:</span>
<ul>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">PCI-DSS v4.0.1</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">NIST Cybersecurity Framework (CSF) 2.0</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">SOC 2</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">SOX</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">FTC Safeguards Rule and related FTC requirements</span></li>
</ul>
</li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Review governance documentation for clarity, consistency, completeness, enforceability, and alignment with regulatory and organizational requirements.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Identify potential governance gaps, conflicting requirements, outdated language, or process inconsistencies and recommend improvements.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Ensure governance documentation appropriately distinguishes between policies, standards, procedures, guidelines, and supporting controls.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Draft, edit, and maintain governance documentation using concise, professional, and active-voice writing principles.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Support audit, assessment, and compliance activities through governance documentation review and evidence coordination.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Maintain governance repositories, templates, and document management systems.</span></li>
</ul>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>Security Awareness & Education</strong></span></p>
<ul style="text-align: justify;">
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Support the organization’s security awareness and education initiatives for technical and non-technical audiences.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Develop and maintain targeted awareness communications, training materials, and educational content aligned to organizational risks and emerging threats.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Apply adult learning and communication principles to tailor awareness messaging to intended audiences and business contexts.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Coordinate and support phishing simulation campaigns, including reporting, trend analysis, and user follow-up activities.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Assist with measuring awareness participation, phishing resilience, and program effectiveness metrics.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Collaborate with stakeholders to identify awareness gaps and support awareness improvement initiatives.</span></li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>Metrics, Reporting & Program Support</strong></span></p>
<ul style="text-align: justify;">
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Develop and maintain governance and awareness program dashboards, recurring reports, and operational metrics.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Produce reporting related to:</span>
<ul>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Policy lifecycle compliance</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Review and approval timeliness</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Governance exceptions</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Security awareness participation</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Phishing simulation trends</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Governance process effectiveness</span></li>
</ul>
</li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Analyze governance and awareness trends to identify operational risks, recurring issues, or process improvement opportunities.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Build and maintain reusable governance templates, reporting assets, and process documentation.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Support governance committee preparation, leadership reporting, and cross-functional governance initiatives.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Contribute to governance process improvement and operational efficiency efforts.</span></li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>REQUIREMENTS</strong></span></p>
<ul style="text-align: justify;">
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Risk Management, English, Communications, or related field; or equivalent practical experience.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">3–5 years of experience in information security governance, compliance, policy management, technical writing, security awareness, or related areas.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Strong working knowledge of security and regulatory frameworks including PCI-DSS, NIST CSF, SOC 2, SOX, and FTC requirements.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Demonstrated ability to read, interpret, and map regulatory requirements to governance documentation and organizational controls.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Excellent technical writing, editing, and English language comprehension skills.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Strong critical thinking and analytical skills, including the ability to identify governance gaps, inconsistencies, or improvement opportunities.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Strong understanding of the distinctions between policies, standards, procedures, guidelines, and controls.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Experience developing metrics, dashboards, and recurring governance or compliance reporting.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Familiarity with phishing simulation platforms and security awareness practices.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Strong organizational, stakeholder coordination, and project management skills.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Ability to manage multiple priorities and deadlines in a cross-functional environment.</span></li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><strong>Preferred Qualifications</strong></span></p>
<ul style="text-align: justify;">
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Experience supporting governance, risk, and compliance (GRC) programs in regulated industries.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Understanding of adult learning principles and audience-based communication strategies.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Experience supporting audits, assessments, and evidence collection activities.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Familiarity with GRC platforms, workflow management tools, or document management systems.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Experience in financial services, fintech, or highly regulated environments preferred.</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Relevant certifications such as:</span>
<ul>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">Security+</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">CISSP</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">CISA</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">CRISC</span></li>
<li style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">PCI ISA</span></li>
</ul>
</li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span style="color: rgb(255, 255, 255);">#LI-REMOTE</span></p>
<p style="text-align: justify;"><span style="color: rgb(255, 255, 255);">#LI-SS1</span></p><div class="content-conclusion"><p style="margin: 0in; text-align: justify;"><span style="font-family: Arial, sans-serif; font-size: 12pt;">We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.</span></p>
<p style="margin: 0in; text-align: justify;"><span style="font-family: Arial, sans-serif; font-size: 12pt;"> </span></p>
<p style="margin: 0in; text-align: justify;"><span style="font-family: Arial, sans-serif; font-size: 12pt;">California applicants can find a copy of Oportun's CCPA Notice here: <a href="https://oportun.com/privacy/california-privacy-notice/">https://oportun.com/privacy/california-privacy-notice/</a>.</span></p>
<p style="margin: 0in; text-align: justify;"><span style="font-size: 12pt; font-family: Calibri, sans-serif;"> </span></p>
<p style="margin: 0in; text-align: justify;"><span style="font-size: 12pt; font-family: arial, helvetica, sans-serif;">We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).</span></p></div>
Related Roles
Bilingual English and Spanish Member Loyalty Representative (R14052)
Oportun
Austin, TXBilingual English and Spanish Member Loyalty Representative (R14051)
Oportun
Palmdale, CaliforniaBilingual English and Spanish Member Loyalty Representative (R14045)
Oportun
Sacramento, CABilingual English and Spanish Member Loyalty Representative (R14044)
Oportun
Houston, TXBilingual English and Spanish Member Loyalty Representative (R14047)
Oportun
Hawthorne, CASenior Analyst, Risk Management & Analytics (R14040)
Oportun
Remote - MXRemote