Junior Security Analyst
Confidential
Posted: February 26, 2026
Interested in this position?
Create a free account to apply with AI-powered matching
Quick Summary
This Junior Security Analyst role involves ensuring the security of a financial services company's data and systems, with a focus on compliance and risk management. The ideal candidate should have strong analytical and documentation skills, with the ability to work in a structured and compliant environment.
Required Skills
Job Description
Junior Security Analyst
Position Overview
NetRoadshow is seeking a detail-oriented and highly organized Junior Information Security Analyst to support the company’s security operations, compliance initiatives, and client assurance program.
The role is ideal for an early-career cybersecurity professional who is process-driven, structured, and capable of managing documentation-heavy workflows in a highly compliance-driven financial services environment. This is a great opportunity for someone trying to break into the Information Security field to learn in a thriving organization.
The primary focus of this role will include:
Completing and managing client security questionnaires and audits.
Tracking and coordinating long-term security and compliance initiatives
Supporting enterprise-wide security governance efforts
Assisting in maintaining security controls aligned to financial industry expectations
Assisting in SOC 2 audit preparation
Key Responsibilities:
1. Security Questionnaire & Client Assurance Management (Primary Function)
Complete client and bank security questionnaires accurately and within deadlines.
Maintain a centralized repository of approved responses and supporting documentation.
Coordinate with Engineering, DevOps, Legal, Security, and Production teams to gather evidence.
Track version history and control narrative consistency across responses.
Identify gaps between current controls and requested controls.
Escalate material findings or high-risk exposure areas to senior security leadership.
Maintain mapping between questionnaire responses and internal control frameworks.
2. Security Governance & Long-Term Initiative Tracking
Maintain and update the security roadmap.
Track remediation items from:
Internal audits
Client assessments
Penetration tests
Vendor assessments
Policy reviews
Provide weekly status updates to security leadership.
Maintain risk register and issue tracking documentation.
Assist in preparation of board- or executive-level security reporting.
The analyst will serve as the operational backbone ensuring that security projects move forward and are documented properly.
3. Policy & Control Maintenance
Assist with drafting and maintaining security policies and procedures.
Map policies to relevant frameworks (SOC 2, ISO 27001, NIST CSF, CIS Controls).
Ensure documentation reflects actual technical implementation.
Track annual review cycles and attestation processes.
Support evidence collection for audits and certifications.
4. Cross-Functional Security Support
Work with Engineering to ensure secure SDLC documentation is maintained.
Assist with tracking security requirements in the CI/CD pipeline.
Support third-party vendor security reviews.
Participate in internal security awareness initiatives.
Help ensure protection of:
MNPI (Material Non-Public Information)
PII
Confidential issuer and investor data
5. Security Operations Support (Exposure & Growth Area)
Monitor and triage low-level security alerts (as assigned).
Support documentation of incident response events.
Assist in tabletop exercises.
Help maintain access review records.
Track remediation for vulnerability scans.
Required Qualifications:
Bachelor’s degree in Cybersecurity, Information Systems, or related field (or equivalent experience)
0-3 years of experience in information security, IT audit, compliance, or risk management
Strong written communication skills
Strong organizational skills with ability to manage multiple parallel initiatives
Self-driven, autonomous and can contribute to the strategy and roadmap of the team. Ability to handle proprietary and sensitive information in a confidential manner
Preferred Skills and Proficiencies:
Experience in fintech, financial services and capital markets
Familiarity with secure software development lifecycle (SDLC)
Understanding of vendor risk management, risk registers, data classification frameworks
Core Competencies
Process-oriented and structured
Strong documentation discipline
Professional client-facing communication
Ability to handle confidential information with discretion
Analytical thinker with attention to detail
Self-starter who takes ownership of assigned initiatives
Performance Metrics
Success in this role will be measured by:
On-time completion rate of security questionnaires
Reduction in duplicate or inconsistent response content
Improved tracking visibility of security initiatives
Successful audit support
Reduction in remediation backlog
Positive internal and external stakeholder feedback