Senior Security Risk & Compliance Analyst

Posted Yesterday
Be an Early Applicant
3 Locations
In-Office
Senior level
Automotive
The Role
Lead and execute security governance, risk, and compliance activities including SOC 2 and regulatory compliance audits, internal control testing, GRC platform administration, enterprise risk register maintenance, remediation tracking, and cross-functional policy and questionnaire support. Produce audit reports, dashboards, and risk reporting to leadership.
Summary Generated by Built In

APCO Holdings partners with dealerships across North America to deliver innovative vehicle protection products and services that enhance the ownership experience for customers and drive growth for our partners. Through our family of brands, we bring together industry expertise, technology, and data-driven insights to help dealers strengthen their finance and insurance performance and build lasting relationships with their customers.

Our teams work collaboratively across operations, technology, risk, finance, marketing, and sales to deliver solutions that create measurable value and support the continued growth of APCO and the partners we serve.

We are looking for a Senior Security Risk & Compliance Analyst to support and strengthen APCO’s security governance, risk, and compliance (GRC) initiatives. In this role, you will help drive compliance efforts, assess security controls, identify risks, and support the organization’s ongoing commitment to maintaining a strong security posture and regulatory compliance.

What You'll Do

    Audit & Compliance

    • Support the planning, coordination, and execution of compliance audits, including readiness assessments and external audit engagements
    • Partner with control owners to document, implement, and maintain compliance controls aligned control requirements.
    • Collect, review, and validate audit evidence to ensure completeness and accuracy
    • Track audit findings, exceptions, and remediation efforts through closure
    • Act as a liaison between internal stakeholders and external auditors

    • Internal Audit

      • Perform internal audits and control assessments to evaluate the effectiveness of security and compliance controls
      • Develop audit plans, testing procedures, and audit reports
      • Identify control gaps and recommend remediation actions
      • Monitor and track remediation efforts to ensure timely resolution

      • GRC Platform Management

        • Administer and maintain the organization’s GRC platform
        • Configure audit workflows and maintain accurate, up-to-date due diligence responses within the GRC platform.
        • Ensure data integrity and accuracy within the system
        • Generate dashboards and reports for compliance status, audit tracking, and risk posture

        • Risk Registration & Management

          • Maintain the enterprise risk register, including identification, classification, and documentation of risks
          • Facilitate risk assessments with business and IT stakeholders
          • Evaluate risk severity based on likelihood and impact
          • Track risk treatment plans (remediation, acceptance, transfer, avoidance)
          • Provide regular reporting on risk posture to leadership

          • Governance & Cross-Functional Collaboration

            • Collaborate with IT, Security, Legal, and business units to ensure alignment with compliance requirements
            • Assist in the development and maintenance of security policies, standards, and procedures
            • Support other compliance initiatives as needed (e.g., regulatory, customer security questionnaires)

Qualifications

    • Bachelor’s degree in Information Security, Information Systems, or related field (or equivalent experience)
    • At least 5 years of experience in security compliance, audit, or GRC
    • Hands-on experience with SOC 2 audits and Trust Services Criteria and New York 23 NYCRR 500, or other regulatory compliance.
    • Experience with performing internal audits and control testing
    • Familiarity with GRC tools (e.g., ServiceNow GRC, Archer GRC)
    • Strong understanding of risk management principles and frameworks
    • Knowledge of common frameworks (e.g., AICPA SOC 2, ISO 27001, NIST)
    • Experience with leading cybersecurity due diligence activities, including responding to customer and partner security questionnaires accurately and in a timely manner
    • Strong analytical, organizational, and communication skills

Preferred Certifications

    • Certified Information Systems Auditor (CISA) or
    • Certified in Risk and Information Systems Control (CRISC) or
    • Certified Information Systems Security Professional (CISSP)

This Role Might Be a Great Fit If You…

  • Enjoy identifying risks and improving security processes
  • Thrive in cross-functional, collaborative environments
  • Like balancing technical security concepts with governance and compliance
  • Are motivated by protecting systems, data, and organizational integrity

What We Offer

  • Competitive compensation
  • Comprehensive medical, dental, and vision benefits
  • 401(k) with company match
  • Paid time off and company holidays
  • Opportunities for professional growth and certification support
  • A collaborative and security-focused work environment

At APCO, the way we work matters just as much as the results we deliver. Our values guide how we work, how we partner, and how we deliver results.
 
We C.A.R.E.
Committed – We build strong, high-trust relationships with our partners and each other.
Accountable – We take ownership of outcomes and hold ourselves to the highest standards of performance and integrity.
Results-Driven – We focus on delivering measurable outcomes that create value for our partners and our business.
Excellent – We strive for excellence in everything we do while balancing short-term performance with long-term success.
 
If you're excited about joining a team that values collaboration, accountability, and continuous improvement, we'd love to hear from you.
 
 
By submitting your application, you acknowledge that you have read and understand our Privacy Policy and Terms & Conditions. APCO Holdings may collect personal information (such as name, contact details, and employment history) to evaluate your candidacy. We may share this data with our subsidiaries, affiliates, and service providers. We retain applicant data only as long as necessary for the hiring process or as required by law.

Skills Required

  • Bachelor's degree in Information Security, Information Systems, or related field (or equivalent experience)
  • At least 5 years of experience in security compliance, audit, or GRC
  • Hands-on experience with SOC 2 audits and Trust Services Criteria and New York 23 NYCRR 500 or other regulatory compliance
  • Experience performing internal audits and control testing
  • Familiarity and hands-on experience with GRC tools (e.g., ServiceNow GRC, Archer GRC) and administering a GRC platform
  • Strong understanding of risk management principles and frameworks (AICPA SOC 2, ISO 27001, NIST)
  • Experience leading cybersecurity due diligence and responding to customer/partner security questionnaires
  • Strong analytical, organizational, and communication skills
  • CISA, CRISC, or CISSP certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Norcross, GA
111 Employees
Year Founded: 1984

What We Do

APCO, established in 1984, is a leading marketer and administrator of extended vehicle service contracts, warranties, and other related products sold primarily by automobile dealers located throughout the United States. APCO has expanded its offerings over the last decade to include leading-edge training for dealership sales and finance teams. The company markets its products using the EasyCare and GWC brands, as well as other private label automobile manufacturer brands, through a network of independent agents and an internal salesforce that specialize in consulting with and servicing the automotive dealership markets. EasyCare and GWC Warranty are the only "Motor Trend Recommended Best Buy" brands in the automotive aftermarket. For further information about APCO, see www.gwcwarranty.com and www.easycare.com.

Similar Jobs

Identity Digital Logo Identity Digital

Staff Devops Engineer

Consumer Web • eCommerce • Internet of Things
Remote or Hybrid
United States
240 Employees
175K-220K Annually

MetLife Logo MetLife

Senior Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
121K-149K Annually

MetLife Logo MetLife

Software Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
210K-210K Annually

PwC Logo PwC

Architect

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
53 Locations
370000 Employees
99K-232K Annually

Similar Companies Hiring

Cox Enterprises Thumbnail
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Atlanta, Georgia
50000 Employees
UL Solutions Thumbnail
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Chicago, IL
15000 Employees
HERE Technologies Thumbnail
Artificial Intelligence • Automotive • Computer Vision • Information Technology • Internet of Things • Logistics • Software
Amsterdam, NL
6000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account