Logo for Great Gray

Lead Information Security Analyst

Role overview

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • 5-10+ years of audit, compliance, or technical experience.
  • Excellent knowledge of IT security control trends as well as auditing compliance best practices.
  • Effective communication skills (written and verbal) to properly articulate complicated IT controls and compliance issues to leadership and partners.

Responsibilities

  • Lead and manage GRC functions including compliance monitoring, audit management, and risk assessment.
  • Ensure compliance with relevant regulatory requirements and security frameworks (SOC 2, NIST, industry-specific standards, etc.)
  • Prepare for and manage compliance audits, assessments, and regulatory reviews.
  • Develop, maintain, and enforce information security policies and procedures.

Key facts

Hard skills

Other skills

  • Governance
  • Entrepreneurship
  • Communication
  • Problem Solving
  • Adaptability

About the company

Great Gray logo

Great Gray

At Great Gray® we believe in – and are driven by – growth. In continually expanding and transforming retirement solutions through technology that streamlines, innovation that unlocks potential, and a mindset that reaches far beyond the status quo. Growth that brings new efficiencies, new possibilities, new goals to our customers. And to their customers. From acting as a trustee for CITs, where we transcend oversight by working to ensure assets are not just managed but maximized, to delivering modern approaches like our onboarding tool BoardingPass®, we never stop looking for smart ways to innovate and grow our industry. And ultimately, bring greater value to those we serve. Always listening, learning, applying new concepts on top of a long-standing reputation for fiduciary strength and expertise. Creating what’s next from a critical foundation of discipline and trust. Empowering our industry, customers, and ourselves to grow confidently. Disclosures: Great Gray Trust Company, LLC serves as Trustee for its bank collective investment trusts (“CITs” or “Funds”) and maintains ultimate fiduciary authority over the management of, and investments made in, the Funds. The Funds are not mutual funds as the Funds and their units are exempt from registration under the Investment Company Act of 1940 and the Securities Act of 1933, respectively. See full disclosures here: https://greatgray.com/wp-content/uploads/2025/05/Standard-Great-Gray-Disclosure-4.15.2025-rev5.9.pdf

Company details

Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Why Great Gray? At Great Gray Group, we strive to set the bar for the retirement services industry. Our goal is to deliver advanced retirement solutions that combine our core fiduciary services with robust investment options, innovative technology, and dedicated client service. We focus on making choices clearer, transitions smoother, and the client experience more delightful. Complacency isn't in our vocabulary. Every day, we look for opportunities to better serve our clients, be an excellent business partner, and earn the trust of those who rely on us. 

The Role

Great Gray is seeking a Lead Information Security Analyst to join our Information Security team. This role will lead IT governance, risk assessment, and security compliance activities while supporting enterprise risk management and compliance with regulations and frameworks such as SOC 2 and the NIST Cybersecurity Framework. The analyst will also coordinate the review, development, implementation, and documentation of policies, processes, procedures, and practices that support the information security management system (ISMS).

Location

This position work remote from the United States. Please note that remote employment in this role is restricted to candidates residing in states where Great Gray is currently registered as an employer. These states are limited to: CA, CO, CT, DC, DE, FL, GA, IL, IN, MA, MD, MI, MN, NC, NH, NJ, NV, NY, OH, PA, RI, SC, TN, TX and VA.

Visa sponsorship or transfer of an existing visa is not available for this position. Applicants must be authorized to work directly for any employer in the United States without visa sponsorship or transfer.

Responsibilities 

  • Lead and manage GRC functions including compliance monitoring, audit management, and risk assessment.
  • Ensure compliance with relevant regulatory requirements and security frameworks (SOC 2, NIST, industry-specific standards, etc.)
  • Prepare for and manage compliance audits, assessments, and regulatory reviews
  • Maintain security documentation, evidence, and audit trails for compliance purposes
  • Develop, maintain, and enforce information security policies and procedures
  • Vendor Risk Management security assessments, onboarding, and reviews.
  • Collaborate with cross-functional teams to integrate security and compliance into business processes
  • Mentor and support the Information Security Analysts in both analyst and GRC functions
  • Monitor security posture, identify threats, and recommend remediation measures
  • Conduct vulnerability assessments, penetration testing, and security assessments on systems and applications
  • Participate in incident response activities and conduct post-incident analysis
  • Stay current with security trends, vulnerabilities, and emerging compliance requirements

Qualifications & Experience

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • 5-10+ years of audit, compliance, or technical experience.
  • Excellent knowledge of IT security control trends as well as auditing & compliance best practices.
  • Effective communication skills (written and verbal) to properly articulate complicated IT controls and compliance issues to leadership and partners.
  • Positive attitude and a strong commitment to delivering quality work.
  • Relevant training and/or industry certifications in auditing, compliance, or IT security.
  • Ability to thrive in a fast-paced, dynamic environment and manage multiple priorities effectively.
  • Comfortable navigating ambiguity.
  • Entrepreneurial mindset to bring best practice ideas to the team.
  • Your standards reflect our core values: Growth Mindset, Disciplined Curiosity, Grit, Results Ownership, Collaboration.

Base Pay Range*

$120,000-$150,000

*This base pay range is subject to change and may be modified in the future.

The pay range displayed above is the base pay compensation range that Great Gray expects to pay for this position at the time of this posting.  Individual compensation within this range, or that may warrant a provision for pay beyond this range, depends on multiple factors, including, but not limited to, candidate’s prior education and relevant work experience and training as well as position location and local market demands.  Our pay-for-performance culture also includes participation in an annual incentive bonus plan for this position which is not included in the ‘Base Pay Range’ noted above.

Benefits We have a comprehensive and competitive benefits package at Great Gray. Some of the highlights are: ·         Be an integral part of a high-growth organization! ·         Competitive compensation package ·         Group medical, dental and vision insurance ·         Employer-paid life and disability insurance ·         Annual well-being stipend ·         Eligible employees may also contribute to a 401(k) plan with an advantageous employer contribution model, upholding our mission to support our employees in retirement   Company Background  Great Gray is the leading independent provider of trustee and administrative services to Collective Investment Trusts (“CITs”), with over $385 billion in CIT assets under management, across more than 1,045 funds. We proudly work with more than 80 subadvisors, including leading firms such as AllianceBernstein, American Funds, BlackRock, Franklin Templeton, MetLife, Neuberger Berman, PGIM, PIMCO and Raymond James.    CITs are more than just an investment vehicle. They represent a forward-thinking approach to retirement planning. These tax-exempt, pooled investment vehicles are offered to employer-sponsored retirement plans, like 401(k)s. CITs are comparable to mutual funds, but, because they are tailored for the institutional retirement market, they can offer distinct advantages, including efficient administration and cost-effectiveness. CITs have a history dating back over 90 years; but they have gained favor over the past decade, driven by innovations, and Great Gray has been at the forefront.   Great Gray has consistently delivered year-over-year growth at an above market rate and is investing in the continued development of its core CIT business as well as complementary administrative services and technology solutions for the retirement market.   Madison Dearborn Partners (“MDP”) purchased Great Gray from Wilmington Trust in April 2023. As a result, Great Gray is an independent company owned by funds affiliated with MDP.   Investor Background  MDP is a leading private equity investment firm based in Chicago. Since MDP's formation in 1992, the firm has raised aggregate capital of over $37 billion and has completed over 160 platform investments across nine flagship funds. MDP invests across five dedicated industry verticals, including financial services, healthcare, technology and government services.   Equal Employment Opportunity Policy Great Gray Group, LLC is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status or other non-merit factor.   Accommodation Statement Great Gray is committed to ensuring individuals with disabilities and/or those who have special needs participate in the workforce and are afforded equal opportunity to apply and compete for jobs. If you would like to contact us regarding the accessibility of our website, need assistance completing the application process, or need to request an accommodation for any part of our application or interview process, please contact us at: TalentAcquisition@GreatGray.com

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Information Security Analyst Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.