Full-Time

Senior Information Security Specialist

Confirmed live in the last 24 hours

Yodlee

Yodlee

501-1,000 employees

Data aggregation and analytics for finance

Data & Analytics
Fintech
Financial Services

Compensation Overview

$108k - $162kAnnually

Senior

Raleigh, NC, USA

Hybrid role requiring in-office work in Raleigh, NC.

Category
Cybersecurity
IT & Security
Requirements
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field.
  • 5+ years of experience in information security, compliance, or audit roles, with a focus on PCI DSS, SOC2, and similar frameworks.
  • Strong understanding of compliance requirements, control frameworks, and audit methodologies.
  • Relevant security or compliance certifications such as CISA, CISSP, PCI Professional (PCIP), or CompTIA Security+ are highly preferred.
Responsibilities
  • Manage and oversee the organization’s compliance with PCI DSS, SOC2, and other relevant security frameworks such as NIST and ISO 27001.
  • Develop and maintain policies, procedures, and controls to meet audit requirements, ensuring that the organization is prepared for annual compliance assessments.
  • Collaborate with cross-functional teams to communicate regulatory requirements, clarify compliance expectations, and ensure security policies are implemented effectively.
  • Lead and coordinate external and internal audit preparation, managing audit schedules, documentation, and control reviews.
  • Act as the main point of contact for external auditors and customer security reviews with gathering evidence, responding to inquiries, and ensuring timely completion of audit-related tasks.
  • Support internal audit functions by conducting pre-audit assessments, identifying compliance gaps, and implementing corrective actions where necessary.
  • Conduct regular risk and control assessments to ensure compliance with PCI DSS and SOC2 requirements, including periodic review of access controls, data protection measures, and logging/monitoring practices.
  • Collaborate with teams across IT, Engineering, and Operations to ensure controls are effectively implemented, monitored, and documented for audit readiness.
  • Maintain an inventory of IT assets and data flows as required for compliance, supporting documentation for both internal and external assessments.
  • Develop and maintain documentation for security policies, risk management, incident response, and compliance controls, ensuring consistency and clarity.
  • Regularly update documentation to reflect changes in regulatory requirements and compliance standards, especially in line with SOC2 and PCI DSS updates.
  • Identify and implement process improvements in the compliance program to streamline evidence collection, control testing, and audit response.
  • Develop and deliver training programs on compliance and audit standards, focusing on Privacy, PCI DSS, SOC2, and related regulatory requirements.
  • Educate and support teams on compliance-related best practices, ensuring all employees understand their roles in maintaining compliance.
  • Keep the team informed on changes in regulatory requirements, providing guidance on any necessary adjustments to policies or controls.
  • Implement and manage continuous monitoring processes to ensure ongoing compliance with security frameworks, including regular control testing and compliance health checks.
  • Track and report on compliance metrics, identifying trends, improvement areas, and potential risks to senior management.
  • Work closely with SOC and Risk Management teams to review security incidents for compliance implications and support remediation efforts as needed.
  • Assess third-party vendors for compliance with control standards, conducting security assessments as part of the vendor management process.
  • Maintain relationships with vendors and manage documentation of vendor security controls compliance with organizational standards.
  • Adhere to and apply Envestnet legal, compliance, risk, business continuity and administrative policy within the role and department(s) including the timely completion of training & awareness, affirmations and testing as requested.

Yodlee provides data aggregation and analytics services to financial institutions, fintech companies, and retail clients in the financial technology sector. The company collects and organizes financial data from various sources, which is then used to deliver insights and solutions for wealth management, financial wellness, and personalized financial advice. Yodlee's clients include banks, credit unions, investment firms, and fintech startups that need accurate financial data to enhance their offerings. The company operates on a subscription and licensing model, charging fees for access to its data services and analytics platforms. Yodlee also offers specialized products like transaction data enrichment and virtual financial assistants, which add value and customization for clients. The goal of Yodlee is to help its clients turn raw data into actionable insights, improving financial planning and customer experiences.

Company Stage

Acquired

Total Funding

$160.8M

Headquarters

Tredyffrin Township, Pennsylvania

Founded

1999

Simplify Jobs

Simplify's Take

What believers are saying

  • Open banking adoption boosts Yodlee's opportunities for expanding data aggregation services.
  • Machine learning integration in Yodlee's services provides clearer financial insights for consumers.
  • Growing demand for personalized financial management tools expands Yodlee's market potential.

What critics are saying

  • Increased competition from fintech startups in APAC challenges Yodlee's market share.
  • Shift to open banking may reduce demand for traditional data aggregation services.
  • New financial document automation technologies could disrupt Yodlee's data processing methods.

What makes Yodlee unique

  • Yodlee offers comprehensive data aggregation and analytics services for financial institutions.
  • The company provides specialized products like transaction data enrichment and virtual financial assistants.
  • Yodlee's integration with open banking enhances its data aggregation capabilities.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical (High Deductible Health Plan, Kaiser HMO and PPO), Dental, Vision

401(k) Match

On-site Flu Shots

On-site Biometrics Screening

Employee Assistance Program (EAP)

Life Insurance and AD&D

Short and Long Term Disability

On-site Gym

Fully Stocked Kitchen

Tuition Reimbursement

Employee Referral Bonus

Casual Dress Code

Mobile Reimbursement