> Markdown version of [/jobs/ext/1448736-lead-info-security-analyst-issue-and-regulatory-support](https://www.wearedevelopers.com/jobs/ext/1448736-lead-info-security-analyst-issue-and-regulatory-support). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Info Security Analyst - Issue and Regulatory Support - **Company:** TIAA - **Location:** Frisco, TX, United States - **Experience:** Expert - **Salary:** $121,000.0 - $149,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Fraud Prevention and Detection, Information Technology Audit, Information Technology - **Published:** July 26, 2026 - **Apply:** https://www.careerjet.com/job/us333275c1247dd297b3518f1d580180c3/eaa ## About the Role * University (Degree) Preferred, * 5 or more years of working experience in Cybersecurity/Information Security, IT/Technology Risk Management, IT/Technology Compliance, IT/Technology Audit, or Information Technology. * Experience with Cybersecurity/Information Security-related laws, regulations, and control frameworks, such as NIST CSF, and experience with control testing of technology risks, controls, policies, and standards. Preferred Qualifications * Experience independently evaluating and/or performing risk and control assessments and audits across Cybersecurity/Information Security domains. * Professional certifications including CISSP, CISA, CRISC, CISM, and/or CCSP. ## Description The Lead Information Security Analyst (Cybersecurity) is responsible for strengthening Global Cybersecurity and Fraud Management (GCFM) control programs by implementing and supporting assessment readiness activities, as well as monitoring, escalating, reporting, and influencing the prioritization of significant risks and control weaknesses. The GCFM organization is responsible for keeping pace with the ever-changing cybersecurity and fraud management landscape, safeguarding the company's assets from threats and attacks, and managing information technology and security risks and incidents. The Lead Information Security Analyst serves as the primary interaction point between GCFM Control and Control Program owners and line of defense partners, as well as external assessors and auditors., * Relationship Management - Build and maintain effective relationships with key stakeholders across all three lines of defense and with internal and external business partners to successfully address current regulatory examinations, audits, and inquiries, and prepare for future ones. * Issue Management - Support the Holistic Issue Management enterprise program and provide appropriate governance and oversight for the GCFM Issue Portfolio. Ensure the execution of program requirements and support activities required to document and report on risk remediation activities. * Regulatory Support - Communicate the schedule of regulatory exams that impact IT, assess readiness, and provide support for interactions with regulators and assessors. Track information requests, perform preliminary reviews of artifacts prior to submission to legal and compliance partners, and schedule meetings with regulators as needed. Govern regulatory findings as they are documented and tracked as formal issues. * Assessment Readiness - Maintain and develop the GCFM evidence catalog to support ongoing assessment readiness. ## Related Videos - [Fireside Chat: AI and Sustainability - Thorsten Jonas](https://www.wearedevelopers.com/videos/1769-fireside-chat-ai-and-sustainability-thorsten-jonas) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Making Interactions Accessible to All Users](https://www.wearedevelopers.com/videos/649-making-interactions-accessible-to-all-users) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)