Sr. Cyber Assurance Analyst, Finance

SpaceX
Hawthorne, CA
On-site

Who this role is best for

Strong fit for mid-level professionals who bridge cybersecurity and finance domains and thrive in hands-on, onsite environments.

Best fit for

  • Mid-level professionals with 5+ years in cybersecurity compliance and finance systems testing
    — “5+ years of experience in cybersecurity compliance, audit or technical security roles
  • Candidates who can interpret technical configurations and compliance frameworks
    — “Ability to interpret code/configurations, access controls, change records, and system/network designs
  • Individuals who can mentor and collaborate across engineering, finance, and legal teams
    — “Mentor fellow teammates and take an active role in their development

Things to consider

  • Onsite presence is mandatory, with no remote/hybrid options available
    — “This role requires you to be onsite; remote/hybrid work will not be considered.
  • Travel commitments may be significant, both domestically and internationally
    — “Must be willing to travel domestically and internationally

How to stand out

  • Highlight experience with SOC 1/SOC 2 and ITGC frameworks in your resume and interviews
    — “Strong knowledge in security compliance frameworks
  • Showcase your ability to validate access controls and system configurations
    — “Partner with engineers to gather, validate, and package technical evidence
  • Emphasize your hands-on experience with finance systems and related compliance testing
    — “Hands-on experience with finance systems and supporting ITGC/application control testing
  • Demonstrate your ability to communicate with both technical and non-technical teams
    — “Ability to explain ITGCs, SOC1/2 and ISO frameworks to non-technical and technical teams
  • Demonstrate your capability to manage audit evidence packages and external audits
    — “Direct experience with external audits, SOC examinations, and management of audit evidence packages
Pace · SteadyCollaboration · HighAutonomy · MediumDecision Impact · CompanyLevel · Senior

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • lead ITGC testing
  • validate security controls
  • identify and drive remediation
  • maintain documentation
  • support third-party risk management
Typical background
securitycompliancefinance systems

Skills & requirements

Required

ITGC TestingSOC 1, SOC 2, Sox-related IT ControlsSecurity Controls ValidationRisk AssessmentsThird-party Risk ManagementAudit Efficiency

Preferred

ERP SystemsFinancial LedgersGRC ToolingAutomationProcess Improvement

Stack & domain

ITGC TestingSOC 1SOC 2Sox-related IT ControlsSecurity ControlsRisk AssessmentsTechnical EvidenceAccess ManagementChange ManagementSystem DesignsEvidence PackagesIT InfrastructureNetworksSecurity PolicyStandardsRegulatory ExpectationsThird-party Risk ManagementSuppliersOnboarding AssessmentsPeriodic ReviewsEmerging Information SecurityIT RisksSOC 1/soc 2 StandardsITGC Best PracticesNew Compliance/assurance TechniquesCommunicationProblem-solvingTeamworkLeadershipMentorshipFinanceRisk ManagementComplianceSecurity

About the role

Original posting from SpaceX via Greenhouse

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.

SR. CYBER ASSURANCE ANALYST, FINANCE

Cyber Assurance is the practice of providing confidence that systems, products and processes meet security, regulatory and compliance obligations. It bridges governance with technical execution -- validating that controls are in place, risks are managed, and requirements are met for both internal and customer-facing systems.

As a teammate you will operate within Information Assurance, working closely with engineers to understand systems, how controls are implemented, be hands-on with collecting and reviewing evidence, and driving efficiencies and remediation efforts, along with providing technical support for finance systems.

As an ideal candidate, you love living at the intersection of security, compliance, finance systems, and risk management. You thrive on rolling up your sleeves to dig into configs, access controls, change logs, system designs, and evidence packages while making sense of challenging, complex, or ambiguous requirements. You’re as comfortable explaining ITGCs, SOC1/2 and ISO frameworks, and risk concepts to non-technical and technical teams as you are reviewing a user access matrix, validating a change management control, or identifying an insecure default configuration. You are firm when it matters, but flexible in finding practical ways to move the ball forward. You excel at handling concurrent complex efforts and flourish in an environment where learning never ceases—where the breadth of operations ranges from rockets to financial ledgers, and ERP systems—and where teams are laser-focused on mission accomplishment. Excitement guaranteed.

RESPONSIBILITIES:

Lead and support ITGC testing, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits/certification efforts.

Partner with engineers and system owners to gather, validate, and package technical evidence for security controls (access management, change management, computer operations, system development lifecycle, configurations, logs, etc.).

Perform technical security and risk assessments of systems, supporting IT infrastructure, and related networks; identify deviations from security policy, standards, ITGC requirements, or regulatory expectations.

Identify security controls, ITGC, and compliance gaps (especially those impacting financial reporting or SOC readiness), advise on remediation, and drive timely resolution with engineering and process owners.

Maintain clear documentation of security controls, control processes, risk assessments, evidence, and audit artifacts.

Identify and drive assessment and audit efficiency through system integration, data analytics/utilization, GRC tooling, automation, and process improvement.

Support third-party risk management efforts for suppliers, including onboarding assessments and periodic reviews.

Identify and propose business-enabling actions by maintaining an up-to-date understanding of emerging information security and IT risks, changes in SOC 1/SOC 2 standards, ITGC best practices, and new compliance/assurance techniques.

Mentor fellow teammates and take an active role in their development.

BASIC QUALIFICATIONS:

High school diploma or equivalency certificate.

5+ years of experience in cybersecurity compliance, audit or technical security roles with strong knowledge in security compliance frameworks.

5+ years of experience with control testing, security standards/policy development, security audits, or security risk management.

PREFERRED SKILLS AND EXPERIENCE:

Ability to interpret code/configurations, access controls, change records, and system/network designs for ITGC, SOC 1/SOC 2, and compliance implications.

Experience with security and compliance tooling such as vulnerability scanners, SIEMs, access review platforms, change management systems, container security, and system configuration baseline checks (e.g., CIS Benchmarks, STIGs).

Hands-on experience with finance systems (ERP, general ledger, payment, or related platforms) and supporting ITGC/application control testing or certifications.

Knowledge of U.S. and international regulatory and assurance requirements relevant to finance and IT (e.g., SOX, SOC 1, SOC 2, COSO, NIST, ISO 27001, GDPR, and related frameworks).

Experience evaluating third-party risk (especially for finance/IT vendors), communicating with external stakeholders/auditors, and supporting mitigations.

Strong communication skills across all organizational levels and ability to build cross-organizational coalitions (Finance, Engineering, IT, Legal, External Auditors).

Direct experience with external audits, SOC examinations, regulatory compliance reviews, and management of audit evidence packages.

Project and program management experience, tooling integration, and delivery in highly fluid environments.

Professional certifications such as CISA, CISM, CISSP, CRISC, GSNA, ISO 27001 auditor, or equivalent (CISA and SOC/ITGC-focused credentials strongly preferred).

 ADDITIONAL REQUIREMENTS:

Must be willing to travel domestically and internationally in support of audit and other assurance activities.

Must be willing to work extended hours and/or weekends as needed.

This role requires you to be onsite; remote/hybrid work will not be considered.

COMPENSATION AND BENEFITS:

Pay Range:

Level 3: $130,000.00 - $195,000.00

Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience.

Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for long-term incentives, in the form of company stock or long-term cash awards, as well as potential discretionary bonuses and the ability to purchase additional stock at a discount through an Employee Stock Purchase Plan. You will also receive access to comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short and long-term disability insurance, life insurance, paid parental leave, and various other discounts and perks. You may also accrue 3 weeks of paid vacation and will be eligible for 10 or more paid holidays per year. Employees accrue paid sick leave pursuant to Company policy which satisfies or exceeds the accrual, carryover, and use requirements of the law.

ITAR REQUIREMENTS:

To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.  

SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

Applicants wishing to view a copy of SpaceX’s Affirmative Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to EEOCompliance@spacex.com. 

Source: SpaceX careers (Greenhouse)

Similar roles