
Information Security Analyst
About AppLovin
AppLovin makes technologies that help businesses of every size connect to their ideal customers. The company provides end-to-end software and AI solutions for businesses to reach, monetize and grow their global audiences. For more information about AppLovin, visit: www.applovin.com.
To deliver on this mission, our global team is composed of team members with life experiences, backgrounds, and perspectives that mirror our developers and customers around the world. At AppLovin, we are intentional about the team and culture we are building, seeking candidates who are outstanding in their own right and also demonstrate their support of others.
Fortune recognizes AppLovin as one of the Best Workplaces in the Bay Area, and the company has been a Certified Great Place to Work for the last four years (2021-2024). Check out the rest of our awards HERE.
Job Description:
The Governance, Risk and Compliance (GRC) information security analyst is a highly respected, influential and in-demand role within the business. This position has a responsibility to the business in supporting and elevating the security posture of the company. The GRC Information Security Analyst role is expected to support the security and compliance strategy as directed by the Head of Information Security in support of the Business. Consequently, the position will require an understanding of Information Security Concepts, Information Risk Management and new technologies. The GRC information security analyst is also responsible for the planning and design of information security policies, procedures and on-going maintenance thereafter. This position will support the company’s Vendor Risk Management Program, Business Continuity Planning, ISO27001 Certification, and Data Privacy Program (as needed).
In tandem with security leadership, the GRC security analyst consistently participates in the assessment and strengthening of the information security program. May act as the primary point of contact for internal and external auditors at the direction of management. The GRC security analyst monitors progress and enforces resolution of outstanding issues that may lead to non-compliance or security threats to the business. As a key member of the security team, the GRC security analyst must focus on strong risk management and corporate resiliency, and not be driven solely by compliance.
Job Responsibilities:
- Coordinate cybersecurity risk assessment program in tandem with key stakeholders.
- Manage the ongoing maintenance and activities using our GRC Platform.
- Identify strengths and weaknesses in the security program as they relate to privacy, security, business resiliency and the supported compliance frameworks.
- Document and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation.
- Maintain strong oversight of third parties, vendors and business partners to safeguard against undue risk presented by external entities.
- Escalate to security management and business unit leads when points of weakness are discovered.
- Analyze findings, and document, recommend and report program gaps to security leadership as needed.
- Support monitoring current and proposed security changes impacting regulatory, privacy and security industry best practice guidance.
- Define qualitative and quantitative metrics to assess the success of the security program and provide regular reports to security and business leadership as needed.
- Act as a key participant in incident response to track occurrence and resolution, with strict documentation and reporting.
- Work in tandem with information security assurance, audit and risk management leadership to perform ongoing security assessments.
- Attend and fully engage in information security management meetings.
- Work across cross functional teams such as legal, privacy, human resources and others as needed.
- Support Client based inquiries from Business Development teams.
Basic Qualifications:
- The ideal candidate will have 1-5 years experience with IT Security Audit, Compliance and Risk Management.
- Familiarity with regulations such as SOX, GDPR, PCI along with an understanding of IT and Cybersecurity Principles, NIST, ISO 27001 and or COBIT, COSO.
- Previous working experience with GRC tools, proficiency in using Excel (pivot tables, formulas) with data analysis or scripting knowledge a plus.
- Strong attention to detail, written and verbal communication skills and the ability to work cross functionally is a must.
- Project management experience is desirable.
- Certifications such as CISA, CRISC, ITIL are desired but not required.
- Bachelor’s degree in any of the following: IT/Information Systems; Business Admin; Risk Management and Compliance related fields is desirable.
AppLovin provides a competitive total compensation package with a pay for performance rewards approach. Total compensation at AppLovin is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Depending on the position offered, equity, and other forms of incentive compensation (as applicable) may be provided as part of a total compensation package, in addition to dental, vision, and other benefits.
CA Base Pay Range
$99,000 - $149,000 USD
Apply for this job
*
indicates a required field