City Jobs
Full-time

Sr. Information Security Analyst

BettermentNew York, NYPosted September 30, 2026

About Betterment

Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease. We're headquartered in NYC and offer hybrid NY-based positions (four days/week in-office, with no required office days during the summer and winter holidays).

About the Role

We are looking for a Senior Information Security professional with deep experience in governance, risk, and compliance to serve as a senior individual contributor on our Govern & Control team. You will own and mature the risk management processes that underpin the trust we hold with clients, investors, and regulators, and you will raise the bar for the analysts around you.

As a technology-driven financial services company, managing information security risk is critical. This role operates within our Govern & Control team, a small, independent second line-of-defense function integrated with the broader security program. The role reports to the Director of Information Security and partners closely with security teams in engineering, lines of business across the company, and other risk functions including Compliance and Legal. As the senior analyst on the team, you will set standards for how the work is done, mentor other analysts, and act as a trusted advisor to stakeholders and leadership.

This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment's total compensation package for employees.

  • New York City: [170,000-185,000]

This job may also be eligible for variable compensation in the form of a company incentive bonus.

A Day in the Life

  • Leads major program areas with limited supervision, such as vulnerability management, third-party risk, identity theft oversight, business continuity and disaster recovery, or issues management, and is accountable for their outcomes and Key Results (OKRs).
  • Leads risk assessment processes end to end, including the hardest and highest-stakes ones, and documents summarized risk conclusions substantiated by data. Sets the template other analysts follow.
  • Designs and documents complex internal controls, which may include building reports or automation. AI and automation tooling is available to scale this work, and you are expected to drive that leverage.
  • Provides effective challenge, primarily to partners in Engineering, and partners with Compliance and Security Engineering to mature risk processes and reduce risk (new tools, processes, or reporting practices).
  • Uses professional judgment and quantifiable methods to measure risk, and drives decisions on accepting or treating risk within our appetite.
  • Independently authors high-quality updates to policies and procedures, and owns program-level and KRI reporting to leadership and governance committees. May serve in a leadership role (Chair or Secretary) for a governance committee.
  • Acts as escalation point and reviewer for the work of more junior analysts, raising the consistency and quality of the team's output.
  • Follows regulatory changes and industry trends closely, maps them to Betterment's business, and stays engaged in the professional community.

What We're Looking For

We are seeking a senior team member who will be a force multiplier for the security program.

Required:

  • 6+ years of experience in security GRC, technology risk, technology audit, or security operations, including demonstrated senior-level ownership.
  • Expert-level depth in at least one security domain (for example vulnerability management, SDLC, application security, or cloud computing), paired with broad horizontal skills across the business. This is the "T-shaped" profile we expect at this level.
  • Deep, hands-on command of security risk management: the CIA triad, control design and operation, and one or more control governance frameworks (for example SOC 2, ISO 27001, NIST CSF).
  • Strong command of security controls for cloud computing and third-party SaaS, including logical access management, third-party due diligence and ongoing monitoring, and vulnerability governance.
  • Fluency in the structure and content of audit reports and risk assessments, including audit and assessment control testing with appropriate sampling and results reporting.
  • Ability to use professional judgment and quantifiable methods to measure risk, and to drive stakeholders to sound risk acceptance or treatment decisions within appetite ("effective challenge").
  • Strong cross-disciplinary communication and relationship building, with a track record of influencing without authority across Engineering, business, Compliance, and Legal.
  • Moderate understanding of financial services operations and of Product/Engineering.
  • Experience learning and applying new skills quickly, including through research and the use of AI and automation.

Encouraged:

  • Professional designations such as CISSP, CISA, CISM, AWS Cloud certifications, or other (encouraged, not required).
  • Experience in regulated financial services, and with audits or regulatory examinations.
  • Experience mentoring analysts or auditors, or leading a governance committee.

Join a team b

This role is sourced from Betterment's public careers feed. The Apply button opens their site in a new tab.

More jobs in New York

Transportation

ADAS Test Driver

Tsmg

New YorkContract
Posted Oct 1View & apply →