Sr. Cyber Assurance Analyst, Finance
Hawthorne, NV - USA
Job Summary
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible with the ultimate goal ofenabling human life on Mars.
SR. CYBER ASSURANCE ANALYST FINANCE
Cyber Assurance is the practice of providing confidence that systems products and processes meet security regulatory and compliance obligations. It bridges governance with technical execution -- validating that controls are in place risks are managed and requirements are met for both internal and customer-facing systems.
As a teammate you will operate within Information Assurance working closely with engineers to understand systems how controls are implemented be hands-on with collecting and reviewing evidence and driving efficiencies and remediation efforts along with providing technical support for finance systems.
As an ideal candidate you love living at the intersection of security compliance finance systems and risk management. You thrive on rolling up your sleeves to dig into configs access controls change logs system designs and evidence packages while making sense of challenging complex or ambiguous requirements. Youre as comfortable explaining ITGCs SOC1/2 and ISO frameworks and risk concepts to non-technical and technical teams as you are reviewing a user access matrix validating a change management control or identifying an insecure default configuration. You are firm when it matters but flexible in finding practical ways to move the ball forward. You excel at handling concurrent complex efforts and flourish in an environment where learning never ceaseswhere the breadth of operations ranges from rockets to financial ledgers and ERP systemsand where teams are laser-focused on mission accomplishment. Excitement guaranteed.
RESPONSIBILITIES:
- Lead and support ITGC testing SOC 1 SOC 2 SOX-related IT controls and other relevant audits/certification efforts.
- Partner with engineers and system owners to gather validate and package technical evidence for security controls (access management change management computer operations system development lifecycle configurations logs etc.).
- Perform technical security and risk assessments of systems supporting IT infrastructure and related networks; identify deviations from security policy standards ITGC requirements or regulatory expectations.
- Identify security controls ITGC and compliance gaps (especially those impacting financial reporting or SOC readiness) advise on remediation and drive timely resolution with engineering and process owners.
- Maintain clear documentation of security controls control processes risk assessments evidence and audit artifacts.
- Identify and drive assessment and audit efficiency through system integration data analytics/utilization GRC tooling automation and process improvement.
- Support third-party risk management efforts for suppliers including onboarding assessments and periodic reviews.
- Identify and propose business-enabling actions by maintaining an up-to-date understanding of emerging information security and IT risks changes in SOC 1/SOC 2 standards ITGC best practices and new compliance/assurance techniques.
- Mentor fellow teammates and take an active role in their development.
BASIC QUALIFICATIONS:
- High school diploma or equivalency certificate.
- 5 years of experience in cybersecurity compliance audit or technical security roles with strong knowledge in security compliance frameworks.
- 5 years of experience with control testing security standards/policy development security audits or security risk management.
PREFERRED SKILLS AND EXPERIENCE:
- Ability to interpret code/configurations access controls change records and system/network designs for ITGC SOC 1/SOC 2 and compliance implications.
- Experience with security and compliance tooling such as vulnerability scanners SIEMs access review platforms change management systems container security and system configuration baseline checks (e.g. CIS Benchmarks STIGs).
- Hands-on experience with finance systems (ERP general ledger payment or related platforms) and supporting ITGC/application control testing or certifications.
- Knowledge of U.S. and international regulatory and assurance requirements relevant to finance and IT (e.g. SOX SOC 1 SOC 2 COSO NIST ISO 27001 GDPR and related frameworks).
- Experience evaluating third-party risk (especially for finance/IT vendors) communicating with external stakeholders/auditors and supporting mitigations.
- Strong communication skills across all organizational levels and ability to build cross-organizational coalitions (Finance Engineering IT Legal External Auditors).
- Direct experience with external audits SOC examinations regulatory compliance reviews and management of audit evidence packages.
- Project and program management experience tooling integration and delivery in highly fluid environments.
- Professional certifications such as CISA CISM CISSP CRISC GSNA ISO 27001 auditor or equivalent (CISA and SOC/ITGC-focused credentials strongly preferred).
ADDITIONAL REQUIREMENTS:
- Must be willing to travel domestically and internationally in support of audit and other assurance activities.
- Must be willing to work extended hours and/or weekends as needed.
- This role requires you to be onsite; remote/hybrid work will not be considered.
COMPENSATION AND BENEFITS:
Pay Range:
Level 3: $130000.00 - $195000.00
Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills education and experience.
Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for long-term incentives in the form of company stock or long-term cash awards as well as potential discretionary bonuses and the ability to purchase additional stock at a discount through an Employee Stock Purchase Plan. You will also receive access to comprehensive medical vision and dental coverage access to a 401(k) retirement plan short and long-term disability insurance life insurance paid parental leave and various other discounts and perks. You may also accrue 3 weeks of paid vacation and will be eligible for 10 or more paid holidays per year. Employees accrue paid sick leave pursuant to Company policy which satisfies or exceeds the accrual carryover and use requirements of the law.
ITAR REQUIREMENTS:
- To conform to U.S. Government export regulations applicant must be a (i) U.S. citizen or national (ii) U.S. lawful permanent resident (aka green card holder) (iii) Refugee under 8 U.S.C. 1157 or (iv) Asylee under 8 U.S.C. 1158 or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit competence and qualifications and will not be influenced in any manner by race color religion gender national origin/ethnicity veteran status disability status age sexual orientation gender identity marital status mental or physical disability or any other legally protected status.
Applicants wishing to view a copy of SpaceXs Affirmative Action Plan for veterans and individuals with disabilities or applicants requiring reasonable accommodation to the application/interview process should reach out to.
Required Experience:
Senior IC
About Company
SpaceX designs, manufactures and launches advanced rockets and spacecraft. The company was founded in 2002 to revolutionize space technology, with the ultimate goal of enabling people to live on other planets.