The Role:
Wpromote is looking for a driven IT Security Analyst to strengthen our overall security framework. In this position, you will partner with external security vendors to support SOC 2 compliance efforts and enhance our CIS CSC controls. Working closely with the IT Operations and Infrastructure teams, you will help create scalable security and data protection procedures. You will also serve as a key contributor during security assessments requested by both prospective and current clients. The ideal candidate has hands-on experience with SOC 2 audits, application security best practices, penetration test remediation, and security program evaluations. Experience with security auditing and documentation aligned to industry standards is strongly preferred.
At Wpromote, we believe exceptional work begins with exceptional people. Our mission is to build a more inclusive workplace and support employees throughout their careers by promoting work-life balance through the benefits and policies listed below. As a company recognized by Ad Age and Glassdoor as a Best Place to Work and named Adweek’s Fastest Growing Digital Agency, we are rapidly expanding and seeking new talent to help push the limits of what marketing can achieve.
We offer:
– A remote-first work environment
– Unlimited PTO
– A winter holiday break
– Flexible scheduling
– Work-from-anywhere options*
– Fully paid parental leave
– 401(k) matching
– Medical, dental, vision, life, and pet insurance
– Company-sponsored life insurance
– Short-term disability and additional voluntary insurance options
– Annual ClassPass credits and more
The expected annual salary for this role ranges from $85,000 to $110,000, depending on various factors such as skills, experience, education, certifications, job scope, market conditions, location, and state-specific exempt employee thresholds. Wpromote’s salary ranges may change and are based on market medians for comparable positions using third‑party benchmark surveys. Individual compensation within the range may differ based on experience, skill level, and budget. The full compensation package includes the benefits listed above.
*This role may be performed remotely in most U.S. states, with some exceptions.
Although this position offers remote flexibility, we maintain office hubs in Los Angeles, Chicago, and New York where employees can collaborate, take part in learning opportunities, attend events, or simply use the workspace.
This role is not eligible for immigration sponsorship.
Important Notice: Beware of Job Scams
Wpromote will only contact candidates through official communication channels using email addresses associated with wpromote.com. If you find job postings elsewhere that do not appear on wpromote.com/careers, they may be fraudulent. We will never request payments, fees, Social Security numbers, or banking information during the hiring process. Please remain cautious and notify us of any suspicious contact.
You Will:
– Work with security consulting vendors on SOC 2 compliance, penetration testing, and CIS CSC controls
– Improve SOC 2 engagements by automating audit controls with SaaS tools
– Oversee security assessments from prospective and existing clients
– Review and update internal policies and procedures to meet security standards
– Recommend and implement company-wide security best practices, policies, and processes
– Provide guidance on application security standards for in‑house development
– Manage the vulnerability management system and the security awareness training platform
– Implement measures to prevent data breaches, data loss, and service disruptions
– Assess updates to data privacy and security regulations and identify required organizational adjustments
You Must Have:
– 3–4 years of experience in cybersecurity and data privacy
– Experience partnering with security vendors on SOC 2 audits and penetration test remediation
– Experience evaluating processes and policies for alignment with CIS CSC controls and SOC 2 requirements
– Experience using GCP Command Center
– Experience securing Google Workspace
– Knowledge of OWASP and application security best practices
– Experience addressing vulnerabilities via a vulnerability management tool (e.g., Rapid7)
– Strong understanding of Mac OS security
– A bachelor’s degree in computer science or a related field, or equivalent experience
– Excellent written and verbal communication skills
– Ability to work both independently and as part of a team
– Security certifications such as CISSP are strongly preferred
Wpromote is dedicated to cultivating a workplace that brings together diverse backgrounds and perspectives. We are committed to providing a safe, inclusive environment free from discrimination or harassment. As an equal opportunity employer, we do not tolerate unlawful discrimination based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, parental or family status, disability*, age, veteran status, or any other protected category. We comply with all EEOC guidelines and strive to exceed expectations in promoting diversity within our organization.
Applicants with disabilities may request reasonable accommodations under the Americans with Disabilities Act and applicable state or local laws. A reasonable accommodation modifies standard procedures to ensure equal employment opportunity without creating an undue hardship for Wpromote.
This employer participates in E‑Verify and will provide the federal government with Form I‑9 information to confirm work authorization. If E‑Verify cannot verify eligibility, individuals will receive instructions and the opportunity to contact DHS or the SSA before any employment action is taken. E‑Verify is only used once a job offer is accepted and the Form I‑9 is completed. For more information or to report potential E‑Verify violations, please contact DHS.
To find out more about this job, please visit this link

