$111K - 162K a year
Develop and maintain security policies, standards, and procedures aligned with compliance frameworks and AWS environment, manage risk and audit readiness, and collaborate across teams to ensure governance clarity and compliance.
Bachelor’s degree in CS or related field, 5-7 years IT/IS GRC experience, strong knowledge of compliance frameworks, AWS security familiarity, audit support experience, and certifications like CISA, CISM, CISSP, or AWS Security Specialty.
Why This Role Matters We’re building something brand new — a secure, scalable business division serving multiple customers under a single AWS tenant. While our engineers design the technical controls, we need someone to ensure that our policies, standards, and procedures (PSPs) align with industry best practices, compliance frameworks, and our unique operating environment. As our Information Security Analyst (GRC Focus), you’ll be the architect of our governance layer. You’ll transform security requirements into actionable, auditable PSPs that set the foundation for how we operate. This role isn’t just about documentation — it’s about creating clarity, driving consistency, and ensuring our security program is always audit-ready. You will need to reside (or have the ability to relocate) within 50 miles of our Corporate Headquarters in Scottsdale, AZ, as this role has the option of hybrid or onsite. What You’ll Be Doing Your day-to-day will blend writing, analysis, and collaboration. Some days you’ll be refining a policy for executive approval, and other days you’ll be working with engineers to translate technical controls into standards and procedures that auditors can follow. • Policy Development & Documentation • Draft, update, and maintain Information Security policies, standards, and procedures tailored to our AWS multi-tenant environment. • Ensure alignment with compliance frameworks (SOC 2, PCI, HIPAA, ISO 27001). • Partner with engineers and business stakeholders to ensure policies reflect practical, real-world workflows. • Risk & Compliance Oversight • Identify, document, and track security risks across our environment. • Support risk assessments and provide recommendations for risk treatment plans. • Assist in readiness for external audits by ensuring documentation and evidence are organized and up-to-date. • Collaboration & Communication • Work directly with leadership, engineers, and vendors to ensure policies are clear, actionable, and understood. • Translate technical requirements into plain-language standards that can be followed by non-technical teams. • Support training and awareness initiatives to drive adoption of policies. • Continuous Governance • Establish document versioning and review cycles to keep policies evergreen. • Recommend improvements based on lessons learned, new regulations, and evolving business needs. • Track key governance metrics and report progress to leadership. On a Typical Day, You Might: • Write or revise a standard on IAM role reviews to align with least privilege practices. • Meet with the cloud engineering team to document the procedural steps for AWS GuardDuty alert response. • Draft a risk statement for leadership related to a newly identified compliance gap. • Prepare evidence documentation for an upcoming SOC2 audit. • Deliver a quick briefing to executives on how a policy change affects daily operations. #TECH2025 What We're Looking For We're looking for someone who can think like both a policymaker and a partner. You'll combine your understanding of compliance frameworks with the ability to translate technical practices into clear documentation. • Bachelor's degree in Computer Science, Management Information Systems or equivalent experience • 5-7 years of experience in IT or IS Governance, Risk, and Compliance. • Demonstrated experience drafting and maintaining security policies, standards, and procedures. • Strong knowledge of compliance frameworks (SOC 2, PCI, DSS, HIPAA, ISO 27001, or similar). • Ability to communicate complex security concepts to both technical and business audiences. • Familiarity with AWS security services (IAM, GuardDuty, Config, Security Hub). • Experience supporting external audits (SOC 2, PCI, HIPAA). • Certifications such CISA, CISM, CISSP, or AWS Certified Security - Specialty. Skills That Make You Stand Out • Strong writing and documentation skills with attention to detail. • Ability to "connect the dots" between compliance requirements and technical controls. • Proven success in building relationships across technical and business teams. • Natural curiosity and drive to improve processes and reduce risk. What Success Looks Like In This Role Within your first year, you'll have: • Built and published a full set of security policies, standards, and procedures aligned to our AWS multi-tenant environment. • Developed a governance calendar to ensure regular policy reviews, audits, and updates. • Provided leadership with risk visibility and clear, actionable recommendations. • Contributed to seamless, low-stress external audits through strong documentation practices. • Become the trusted source for policy clarity, compliance readiness, and governance insights. About Consumer Cellular Founded in 1995, Consumer Cellular is the first wireless provider unapologetically built for Americans 50+. An approved wireless partner of AARP, Consumer Cellular is trusted by more than 4 million subscribers for affordable plans, popular phones and devices, and great nationwide coverage, all backed by top-rated, 100% U.S. based customer support. Based in Scottsdale, AZ, with 3,000 employees in company locations throughout the U.S., Consumer Cellular has earned recognition as the most awarded wireless brand for customer service. The company has been honored as #1 in customer service in its industry numerous times and, in 2024, ranked #1 in network coverage and customer satisfaction among wireless carriers by American Customer Satisfaction Index (ACSI). Additionally, the company has been featured 12 times on the Inc. 5000 list of the fastest-growing privately held U.S. companies. Consumer Cellular phones, devices and plans are available nationwide through more than 50 company-owned neighborhood stores, online at ConsumerCellular.com, by telephone at (888) 345-5509, and at leading retailers including Target and Walmart. Connect with Consumer Cellular on Facebook, Instagram, and Youtube. for tutorials, features, applications, and company news. Pay & Benefits Data (in accordance with the Equal Pay and Opportunities Act) • Minimum Salary:$111,300 • Maximum Salary:$161,700 This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. Our Talent Acquisition team are able to answer any additional questions you may have as you move through the selection process. As part of our Total Rewards package, Consumer Cellular, Inc. offers a broad range of Health, Life, Voluntary Lifestyle and other benefits and perks that enhance your physical, mental, and emotional wellbeing. • Competitive base pay with potential for shift differential, overtime and bonus pay • Medical insurance (98% company-paid for full-time employee only coverage) • Dental and Vision insurance (100% company-paid for full-time employee only coverage) • 401(k) company match of 100% up to 6% of your pay • Discounted Consumer Cellular wireless phone plan for employees • Paid Time Off (PTO) available following a 30-day waiting period* • 6 company-paid holidays plus 16 hours of floating holiday accrual per year • Flexible Spending Accounts (FSA) for health care and dependent care expenses • Life and AD&D insurance equal to 1x your annual earnings (100% company-paid) • Long-Term Disability insurance (100% company-paid) • Employee Assistance Program (100% company-paid) • Education reimbursement • Employee rewards program • Accrue up to 40 hours in 1st year for hourly positions and up to 120 hours for salaried positions. Pre-employment Background Check And Drug Screen Is Required. Primary Location United States-Arizona-Scottsdale Job Corporate Schedule Full-time Travel No Job Posting Sep 25, 2025 Unposting Date Oct 13, 2025
This job posting was last updated on 10/5/2025