Veracity Insurance

Junior Information Security & Compliance Analyst

United States full-time Entry $55,000 - $70,000
full-time Entry level Technology & IT Salary listed Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

At Veracity, we aim to be a different kind of insurance partner – one that is free from outside investors, venture capital, or the pressures of a corporate parent.

Ours is a culture of empowerment – one that believes in effort, results, and accountability. We believe that transparency fosters trust, trust fosters growth, and that growth drives innovation. Our commitment to rigorous evaluation and relentless execution lead to rapid evolution.

We answer only to the small business owners we serve, and this independence allows us to stay focused on what matters most: helping their businesses thrive by providing expert guidance and best-in-class insurance policies.

We’re growing fast and want you to be a part of it!

We're seeking a precise, persistent, and coachable Junior Information Security & Compliance Analyst to join our team. Reporting to the Information Security & Compliance Analyst, this role is the execution engine of Veracity's security and compliance program – carrying the recurring, deadline-driven work that keeps the program credible and audit-ready across Veracity, Insurance Canopy, and InsCipher.

This is a deliberately structured entry-level role – the incumbent is not expected to arrive with deep security experience, but is expected to be precise, persistent, and coachable, and to build real technical and audit depth on the job. Over time, this person should take full ownership of the recurring compliance calendar and become the company's second line of security response.

Key Responsibilities

Monitor security dashboards, alerts, and logs across AWS, Microsoft 365, Google Workspace, and Grafana – triage, document disposition, and escalate per established runbooks

Run recurring vulnerability scans across cloud, endpoint, and application surfaces – maintain the remediation tracker, drive follow-up with system owners, and verify and close findings within defined SLAs

Serve as first-line triage for employee-reported phishing and security questions – escalating confirmed issues promptly with context already gathered

Support incident response as first responder and scribe – capture the timeline, preserve evidence, maintain ticket hygiene, and draft the post-incident summary and lessons learned for senior review

Maintain coverage and health of security tooling including MFA enrollment, endpoint agents, logging agents, and email security – and report gaps

Execute user access provisioning, role changes, and deprovisioning tied to onboarding and termination – confirming same-day removal of access for departures

Run quarterly user access reviews end to end – pull system reports, distribute to owners, chase responses, document and route exceptions, and file completed evidence

Enforce least-privilege and role-based access practices in day-to-day requests – flagging standing privileges and orphaned accounts for remediation

Maintain accurate records of privileged accounts, service accounts, and third-party access across business units

Collect, organize, and continuously refresh audit evidence for SOC 2 and PCI DSS – owning the evidence repository so that auditor and customer requests can be answered efficiently

Support SOC 2 and PCI DSS audit cycles – track requests, meet internal due dates, and prepare materials for auditor communications led by senior staff

Maintain the policy and procedure library including version control, the annual review calendar, approval records, and employee attestation tracking

Support vendor risk assessments – collect SOC 2 reports, DPAs, and security questionnaires, maintain the vendor inventory, and flag gaps for senior review

Perform assigned internal control testing and document results with evidence that supports audit requirements, under the guidance of senior staff

Draft responses to customer and carrier security questionnaires and diligence requests for review by the Information Security & Compliance Analyst

Maintain the asset inventory and security awareness training program including completion tracking and follow-up with non-completers

Build and maintain security and compliance metrics reporting – open vulnerabilities, SLA performance, access review status, and training completion

Write and maintain runbooks, SOPs, and checklists for recurring work so that it is repeatable and transferable

Partner with IT, Engineering, Compliance, Legal, and Service teams so that controls are applied consistently without unnecessary friction to the business

Identify repetitive security and compliance tasks that can be automated or streamlined and propose improvements

Required to perform other duties as requested, directed, or assigned

Requirements and Qualifications

0–2 years of professional experience – internships, IT helpdesk or support, systems administration, or audit and compliance support all count; this role is intended to be a first or second job in security

Bachelor's degree in Information Systems, IT, Cybersecurity, or a related field – or equivalent practical experience or a relevant certification in lieu of a degree

Working familiarity with at least one major cloud or productivity platform – AWS, Microsoft 365/Azure, or Google Workspace – including where users, permissions, and logs live

Demonstrated ability to own recurring, detail-heavy work to completion without reminders

Comfort with spreadsheets, ticketing systems such as Jira, and documentation tools

Excellent verbal and written communication skills – able to ask a busy system owner for evidence and actually get it, and to write documentation an auditor will accept

Sound judgment and discretion handling sensitive, regulated, and confidential information including customer PII and NPI

Coachability and genuine curiosity about security – willing to be taught and willing to say "I don't know" early rather than let an item quietly slip

Composure under pressure during audits, incidents, and deadlines

Perks

Health, dental, and vision plans

Amazing work-life balance with 4 weeks of Paid Time Off

10 Paid Company Holidays with 2 floating holidays

401K Programs with employer match

Personal assistance programs for support in a healthy personal and work life

Why Veracity?

Here at Veracity, you’ll be part of a team of trailblazers and visionaries. We’re not just revolutionizing the way people “do” insurance; we are creating a whole new paradigm. Here, you will experience a vibrant and inclusive workplace where your ideas matter! With us, you have a chance to:

Engage in groundbreaking projects that are reshaping the insurance landscape

Collaborate with a group of dedicated, like-minded professionals

Experience a culture that prioritizes growth and development

Compensation Range:$55k/yr - $70k/yr

We are proud to be an equal-opportunity employer. We are committed to providing equal opportunities to all qualified applicants, regardless of race, color, religion, sex, national origin, disability, or any other legally protected characteristics. 

If you need accommodation, please let us know during the interview process.

Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Entry
Technology & IT Administration Data Analysis Writing Junior Information Entry level

Likely questions

  1. Tell us about work you have done that is close to the Junior Information Security & Compliance Analyst role.
  2. How would you approach your first 30 days at Veracity Insurance?
  3. Which of Administration, Data Analysis and Writing have you used recently, and what did it help you achieve?
  4. What have you learned quickly in a past role, project, or training experience?
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Administration, Data Analysis and Writing.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Junior Information Security & Compliance Analyst role because I can bring practical experience in Administration, Data Analysis and Writing, learn the team quickly, and contribute to the outcomes Veracity Insurance needs from this hire.

Related jobs.

More roles from this company or category.