Demo

IT Security Associate

SANS
Charlotte, NC Contractor
POSTED ON 3/19/2026 CLOSED ON 4/18/2026

What are the responsibilities and job description for the IT Security Associate position at SANS?

Job Experience Level
Mid (5-7 Years)
Work Location Expectations
Hybrid


Financial Firm is seeking a 1st Line of Defense GRC Specialist at the Associate level who has a strong passion for Information Security risk management and is interested in building a career at a fast-growing reputable bank.

As an Associate within GRC, you will play a vital role in protecting the firm's information assets by conducting comprehensive risk assessments, collaborating with stakeholders, and driving process improvements. Reporting to the Head of Security Risk Assessments, you will help shape the bank s security risk management practices and ensure compliance with internal and external standards.

Core Responsibilities
Perform information security risk assessments for new and existing SaaS and cloud-based solutions, client initiatives, and regulatory-driven requests.
Review and assess thirdparty security postures by analyzing SOC 1 and SOC 2 reports, ISO 27001 certifications, penetration test summaries, SIG responses, and security questionnaires.
Evaluate SaaS architectures, data flows, and hosting models, with particular attention to data protection, encryption, identity and access management, logging, and monitoring.
Identify control gaps, assess both inherent and residual risk, and partner with stakeholders to define practical mitigation strategies or compensating controls.
Translate technical and operational risks into clear, businessfocused language that resonates with both technical and nontechnical audiences.
Collaborate regularly with IT, business, risk, and compliance teams to support timely, wellinformed decision making.
Support remediation efforts by tracking open issues, validating responses, and documenting outcomes through established governance processes.
Stay current with information security policies, standards, and procedures, and help stakeholders understand how changes may impact risk assessments.
Contribute to the ongoing improvement of risk assessment processes, templates, and tooling.

Required Experience and Skills
2 3 years of experience in banking, financial services, or another highly regulated environment.
Hands-on familiarity with cloud service providers such as AWS, Azure, or Google Cloud Platform, and an understanding of how SaaS applications are built on cloud infrastructure.
A solid foundation in information security principles, risk assessment concepts, and control-based evaluations.
Working knowledge of common security and regulatory frameworks, including NIST, NYDFS Cybersecurity Regulation, GLBA, ISO 27001, NIST CSF, and data privacy regulations such as CCPA/CPRA.
Basic understanding of enterprise systems, operating systems, databases, identity and access concepts.
Strong written and verbal communication skills, with the ability to explain security risk clearly and concisely.
Comfortable working independently while also collaborating effectively across technical and business teams.
Well-organized, detail-oriented, and able to manage multiple assessments and competing priorities.
A strong sense of ownership and follow-through.
Ability to track and maintain risk assessment data and metrics using tools such as Microsoft Excel, Jira, or similar platforms.

Preferred / Nice to Have
Experience supporting thirdparty or vendor risk management programs.
Exposure to GRC platforms or security risk assessment tools.
Experience reviewing and interpreting SOC reports.
Current or in progress security certifications (e.g., CompTIA Security , CompTIA Cloud , AWS, Azure, Google Cloud Platform, CCSP, CRISC).

Salary : $56

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a IT Security Associate?

Sign up to receive alerts about other jobs on the IT Security Associate career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
This job has expired.
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at SANS

  • SANS York, NY
  • Kindly DO NOT SEND Resume if you graduated in the recent 3 years. Kindly DO NOT SEND Resume if you graduated in the recent 3 years. Sr. Machine Learning En... more
  • 10 Days Ago

  • SANS Phoenix, AZ
  • PRINCIPAL DUTIES AND RESPONSIBILITIES: Responsible for the application architecture, work with different teams, engineers and third parties as necessary Wr... more
  • 11 Days Ago

  • SANS Jersey, NJ
  • We are seeking an experienced Event Manager to join our team as a contractor for a period of 4 months. The successful candidate will be responsible for pro... more
  • 11 Days Ago

  • SANS York, NY
  • Pay is $140 on W2 or $167/hour corp to corp. required 10 years of experience for this role. Work schedule: Hybrid (2-3 days onsite) Flex C Developer Job de... more
  • 11 Days Ago


Not the job you're looking for? Here are some other IT Security Associate jobs in the Charlotte, NC area that may be a better fit.

  • Associate Staffing Charlotte, NC
  • Elevate Your Career as an IT Audit Manager – Lead Strategic Risk Assurance for Global Enterprises Join a dynamic organization where your expertise in IT au... more
  • 13 Days Ago

  • Amicis Global Technologies Charlotte, NC
  • Job Title: IT Security Associate Job Location: Charlotte, NC, 28202(Hybrid) Job Duration: 6 months Extension Job Summary SMBC is seeking a 1st Line of Defe... more
  • 9 Days Ago

AI Assistant is available now!

Feel free to start your new journey!