Lead Info Security Analyst - Issue and Regulatory Support
TIAA · Charlotte, NC
$121,000–$149,000from the description
Jul 23, 2026
Charlotte, NC
Jul 25, 2026
What this job asks for AI summary
This role sits within a cybersecurity and fraud management organization, focused on control program governance rather than hands-on technical security work. Day-to-day responsibilities include managing regulatory exam readiness, tracking and reporting on risk remediation issues, liaising with internal audit and compliance partners, and maintaining an evidence catalog for ongoing assessments. It suits candidates with a background in information security risk, compliance, or IT audit who are comfortable working across multiple stakeholder groups.
Senior level · 5+ years · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
Why we read it this way (7)
No specific work location or city is mentioned in the posting; the CBSA is left blank. The posting references an in-office collaborative environment at TIAA but does not name a city.
The title 'Lead Information Security Analyst' carries no standard seniority level word (Junior/Senior/Staff/etc.), so advertised seniority is Unspecified. The 5+ years required and 7+ years preferred, combined with the lead/primary-interaction-point scope, support a Senior classification.
A university degree is listed as 'Preferred,' not required, so the degree requirement is set to None.
NIST CSF is explicitly called out by name under Required Qualifications alongside broader control framework experience, making it the one concrete named technology that gates the role.
Cloud Computing Security and Network Security appear in the 'Related Skills' list — a contextual section, not a hard-requirements block — so they are marked preferred.
Professional certifications (CISSP, CISA, CRISC, CISM, CCSP) are listed under Preferred Qualifications; CISSP is used as the primary with the others as alternatives since they are presented as interchangeable options in the same bullet.
The broader requirements reference IT/Technology Risk Management, IT/Technology Compliance, IT/Technology Audit, and cybersecurity laws/regulations, but these are domain experience descriptions rather than named tools or technologies and are therefore not emitted as skills.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.