Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
We are seeking an IT GRC professional (mid-level) to help strengthen and evolve the organization's technology risk, compliance, and control environment. In this role, you will execute and enhance technology-focused risk management programs, conduct risk assessments, evaluate technology controls, support internal and external audits, and help ensure compliance with regulatory and industry standards. Working closely with technology, security, audit, and business stakeholders, you will leverage your expertise in operational risk, compliance testing, technology audit, and risk and control frameworks to assess risks, identify control gaps, and recommend practical solutions that improve governance, security, and operational effectiveness.
The ideal candidate brings 6+ years of experience in financial services, technology risk, information security, internal/external audit, operational risk, compliance testing, or quality assurance. They will have hands-on experience assessing and testing controls across infrastructure, architecture, identity and access management, network security, data protection, logging and monitoring, configuration management, and cloud. Professional certifications such as CISSP, CISA, CISM, CRISC, CCSP, or similar designations are highly valued. Success in this role requires the ability to partner effectively with engineering and platform teams, translate technical findings into business impact, prioritize remediation activities based on risk, and communicate recommendations clearly to both technical and non-technical stakeholders while supporting the organization's security, compliance, and business objectives.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position will be based in Tampa, FL.
Relocation assistance is not available for this position.
What you'll do:
- Partners with key stakeholders across Technology, Risk Management, Information Security, and Governance functions to identify, assess, aggregate, and document technology risks and controls.
- Partners with key stakeholders in the business to identify, assess, aggregate and document risk and compliance controls, including risks associated with new or modified products, services, distribution channels, regulations, and third-party operations.
- Communicates results of risk and compliance work to governance committees, business process owners and various levels of leadership.
- Contributes to the implementation of new risk and compliance policies, practices, appetites, and solutions to ensure holistic understanding and management of risks according to industry best practice.
- Executes assigned risk or compliance activities in accordance with enterprise policies and procedures.
- Maintains and expands knowledge of the competitive/regulatory landscape and the company's key challenges.
- Reviews laws and regulations for business impact and makes proposals for awareness and action.
- May coordinate and respond to regulatory requirements and requests and ensures the execution of examinations.
- Performs work on risk and compliance processes that focus on enhancing strategies, tools, and methodologies to measure, monitor, and report risks.
- Applies knowledge to assess data and produce analytical insights to understand business objectives, drive business decisions and influence solution strategies.
- Actively contributes in cross-functional teams to identify, assess, aggregate, and mitigate current and emerging risk events.
- Contributes to stress test plans for a line of business or the enterprise including the evaluation of results and framing of contingency plans in partnership with key business stakeholders.
What you have:
- Bachelor's degree; OR 4 years of relevant education and/or experience.
Experiences that will support your success:
- 6+ years of experience in Technology Risk Management, Operational Risk, IT Audit, Information Security, Compliance, Governance, Operational Resilience, or related disciplines.
- Experience supporting technology risk management programs, governance processes, operational risk frameworks, and control environments.
- Knowledge of Availability Management, Capacity Management, Major Incident Management, Problem Management, Operational Resilience, Service Management, or Cloud Operations.
- Experience participating in risk assessments, RCSAs, control assessments, governance reviews, audit engagements, or compliance reviews.
- Understanding of Risk Appetite Metrics (RAMs), KRIs, KPIs, executive reporting, and risk monitoring practices.
- Experience evaluating technology controls, governance frameworks, control testing activities, and monitoring practices.
What sets you apart:
- Experience performing Second Line of Defense oversight, Technology Risk Management, Operational Risk, Technology Audit, or Information Security assessments.
- Experience reviewing technology governance programs involving Availability Management, Capacity Management, Operational Resilience, Major Incident Management, or Service Management.
- Knowledge of RAMs, KRIs, KPI governance, and executive risk reporting practices.
- Experience supporting RCSA challenge activities, governance reviews, control testing programs, or audit readiness efforts.
- Familiarity with PRCI governance, control architecture concepts, risk simplification initiatives, and enterprise control frameworks.
- Ability to analyze major technology incidents and articulate risks in business-focused terms.
Compensation range: The salary range for this position is: $85,040.00 - $162,550.00.
USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.