Fully remote GRC, compliance, or IAM analyst role at a SaaS or fintech company preparing for or maintaining SOC 2 Type II or ISO 27001. Remote is a hard requirement. I want a small or mid-sized security team where I can own end-to-end workstreams from day one and grow into a full certification cycle within 12 to 18 months. Not interested in compliance-as-theater.
Lety Hernandez
@ahyletyh
GRC analyst with 5+ yrs across finance and federal. Targeting remote GRC, compliance, or IAM roles at SaaS or fintech firms building toward SOC 2.
What I'm looking for
I'm a GRC and compliance analyst with 5+ years of experience across financial services and federal environments, currently at a Big 4 consulting firm. My background is a mix of financial crimes compliance (KYC, EDD, BSA/AML, SAR investigations) and federal audit work, and over the past year I've moved deeper into access governance and identity security through a SailPoint Identity Security Cloud engagement at a Fortune 500 pharmaceutical distributor, where I run quarterly User Access Reviews and recertification operations aligned to SOX ITGCs.
A few wins I'm proud of: I cut audit findings from 39 to 28 across two consecutive review cycles at the U.S. Treasury, and at my current firm I built a week-long internal cybersecurity training program for analysts covering Third-Party Risk Management, Identity and Access Management, GRC fundamentals, and Managed Application Security Testing. The program includes interactive sessions, knowledge checks, and final exams, and it's now part of how the team levels up on security delivery work.
What I want next is a remote GRC, compliance, or IAM analyst role at a SaaS or fintech company, ideally one building toward SOC 2 Type II or ISO 27001 certification. I'm strong on the foundational pieces of any certification program: risk registers, audit evidence collection, third-party risk reviews, policy authoring, access governance, and cross-functional coordination across Engineering, Legal, HR, and Sales. I haven't owned a full SOC 2 cycle yet but I've executed every component piece, and I'd ramp fast.
Certifications: ServiceNow Certified System Administrator (CSA), Certified Scrum Master (CSM), Asana Workflow Specialist. In progress: CompTIA Security+ and SailPoint Identity Security Cloud. Outside of work I'm interested in identity security, fintech compliance, and the operational side of building lean security programs at high-trust companies.
Experience
Work history, roles, and key accomplishments
Gathered and packaged audit evidence for external auditors and federal examiners, delivering on-time results for 19 of 20 engagements. Ran quarterly SailPoint Identity Security Cloud access recertifications and built Power BI dashboards, cutting unauthorized-access violations from 22 to 18 per quarter.
Completed a 12-week enterprise ITSM program covering platform administration, access workflow automation, and structured digital delivery. Built a Service Portal application and configured automated provisioning/routing workflows, reducing average request processing time from 4 days to about 2 and tightening SLA adherence.
Management & Program Analyst
U.S. Department of the Treasury
Apr 2020 - Aug 2022 (2 years 4 months)
Monitored federal payment systems and enforced access controls to maintain BSA/FinCEN reporting accuracy at 99%. Performed control testing for modernization initiatives and reduced audit findings from 39 to 28 across two review cycles, while building Power BI dashboards that cut monthly leadership reporting time from 5 days to 2.
Administrative Analyst
Social Detection
Aug 2019 - Nov 2019 (3 months)
Coordinated operational risk assessments and access control gap reviews with cross-functional teams. Wrote standardized operating procedures and improved escalation workflows, tightening audit documentation practices and reducing rework and turnaround time on operational reviews.
Education
Degrees, certifications, and relevant coursework
Temple University
Bachelors of Art , Spanish
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Salary expectations
Social media
Job categories
Interested in hiring Lety?
You can contact Lety and 90k+ other talented remote workers on Himalayas.
Message LetyFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
