Security Risk Manager

Intuit Credit Karma · Charlotte, NC

Company

Intuit Credit Karma

Location

Charlotte, NC

Type

Full Time

Job Description

Credit Karma is a mission-driven company, focused on championing financial progress for our more than 110 million members in the U.S., Canada and U.K.  While we're best known for pioneering free credit scores, our members turn to us for tips as they work on their  financial goals, including helping them monitor their credit, identity monitoring, searching for credit cards, shopping for loans (car, home and personal), and growing their savings* -- all for free. Credit Karma has grown significantly through the years: we've added more than 70 million members in the last five years alone and now have more than 1,100 employees across our offices in Oakland, Charlotte, Los Angeles and London. 

*Banking services provided by MVB Bank, Inc., Member FDIC

Security is a core value at Credit Karma. We help millions of people better manage their credit. Safeguarding their sensitive information is critical to our continued success. From the CEO down to each individual engineer, everyone views security as a personal responsibility.

Credit Karma is looking to hire a Manager to join our Security Governance, Risk & Compliance team [Security GRC]. This role will lead the Security Assurance services within GRC, focused on evaluating technology controls, supporting assessments for the companies certification programs and acting as an overall security compliance subject matter expert to the business. This role will work with business at all organizational layers, so it will be important to demonstrate flexibility in approach, communication style and depth of understanding. The candidate must be comfortable working in a very fast-paced and constantly changing environment. This position reports directly to the Director, Security GRC.

What you'll do:
  • Support certification programs and assessments, such as: ISO 27001, SOC, PCI, in close collaboration with audit teams. Hands-on experience leading or working on these programs, including performing gap and readiness assessments, is required. 
  • Review and support maturity updates, to our existing information security policies and procedures
  • Own Security controls testing program execution including planning, coordination with process owners and stakeholder communication.
  • Advise process/control owners with the preparation and on-going maintenance of controls and control documentation (e.g., policies, procedures, narratives, and matrices)
  • Own BCDR compliance program including planning, coordination with process owners, facilitating BIAs, plan reviews, test exercises and stakeholder communication.
  • Proactively identify gaps or improvement opportunities in existing GRC processes and work to develop solutions to enable maturation, through automation or other mechanisms.
  • Assist with and drive remediation of control deficiencies and gaps identified internally and externally
  • Evaluate and advise on new and evolving certification programs and technology.
  • Support Tier 1 Security risk assessment process 
  • Partner with other leaders within Security to collaborate and support both process maturity and staff development.
What we’re looking for:
  • 8+ years of experience in GRC, security assurance or information security risk management fields
  • Experience implementing or building certification programs such as ISO 27k, SOC etc. 
  • Strong knowledge of PCI DSS certification and attestation requirements 
  • Experience working on BCDR compliance initiatives including performing BIAs and facilitating test exercises 
  • Knowledge of Cybersecurity Frameworks such as NIST (800-53, CSF, 800-171), CIS etc.
What we’d like to see:
  • Bachelors or Masters degree with proficiency in Computer Science, Management Information Systems or relevant technical field experience in a security domain
  • Industry recognized certifications such as CISSP,  CCSP, CISM, CRISC, CCSK
  • Fintech, tech, financial services or consulting work history
  • Knowledge of, or experience working with, cloud-services environment (GCP, AWS etc)
  • Strong project management skills, with a track record of having delivered on complex initiatives in a fast-moving environment
What’s great about the role:
  • Carrying out two positive missions at the same time: helping people take back control of their credit and helping to keep their personal information safe.
  • Solving security problems at scale in a highly technology-focused team, with a culture of “how to do this safely”, not a culture of “no”.
  • Spending way less time convincing anyone why security is important and way more time talking about how to manage risk effectively - the importance of security is woven into our DNA already!
Benefits at Credit Karma includes:
  • Medical and Dental Coverage
  • Retirement Plan
  • Commuter Benefits
  • Wellness perks
  • Paid Time Off (Vacation, Sick, Baby Bonding, Cultural Observance, & More)
  • Education Perks
  • Paid Gift Week in December

Pay Transparency Notice: Credit Karma’s mission of championing financial progress for all starts from within. That’s why we implemented role-based compensation, which ensures people who are in the same role receive the same pay with variations for geographic location only. It’s all part of a more comprehensive DEI strategy that helps level the playing field. The base salary range for this role is $193,715 to $207,000 plus equity and benefits.

Equal Employment Opportunity:

Credit Karma is proud to be an Equal Employment Opportunity Employer. We welcome all candidates without regard to race, color, religion, age, marital status, sex (including pregnancy, childbirth, or related medical condition), sexual orientation, gender identity or gender expression, national origin, veteran or military status, disability (physical or mental), genetic information or other protected characteristic. We prohibit discrimination of any kind and operate in compliance with applicable fair chance laws. 

Credit Karma is also  committed to a diverse and inclusive work environment because it is the right thing to do. We believe that such an environment advances long-term professional growth, creates a robust business, and supports our mission of championing financial progress for everyone. We offer generous benefits and perks with a single eye to nourishing an inclusive environment that recognizes the contributions of all and fosters diversity by supporting our internal Employee Resource Groups. We’ve worked hard to build an intensely collaborative and creative environment, a diverse and inclusive employee culture, and the opportunity for professional growth. As part of the Credit Karma team, your voice will be heard, your contributions will matter, and your unique background and experiences will be celebrated.

Please contact [email protected] if you are interested in employment with Credit Karma and need special assistance or an accommodation to either apply or interview for a specific role.

Privacy Policies:

Credit Karma is strongly committed to protecting personal data. Please take a look below to review our privacy policies:

  • GDPR Privacy Policy
  • U.S. Job Applicant Privacy Notice
Apply Now

Date Posted

05/03/2023

Views

9

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8