Back to all jobs

About the role
<div class="content-intro"><p><strong>Who We Are</strong></p>
<p>Finance leaders choose Billtrust to get paid faster, control costs, and maximize customer satisfaction. As the leader in B2B accounts receivable workflow and payment software, we provide the world’s leading brands with AI-powered solutions across the full AR lifecycle—from invoice presentment and payment processing to cash application and collections. With over 2,600 global customers, more than $1 trillion in invoice dollars processed, and a proprietary network of 13 million buyers, Billtrust delivers business value through deep industry expertise and a culture relentlessly focused on meaningful customer outcomes.</p>
<p>We’re an AI-first company, not just in what we build for our customers, but in how we work. Across every function, our teams use AI tools daily to work faster, make better decisions, and deliver higher-quality outcomes. We hire exceptional people, give them cutting-edge AI capabilities, and measure success by the impact they create. If you want to do the best work of your career at the frontier of AI and fintech, Billtrust is the place to do it.</p>
<p><strong>Our Values</strong></p>
<p><strong>Customers</strong></p>
<p>We relentlessly increase value for customer and do the right thing for them.</p>
<p><strong>Action</strong></p>
<p>We make ‘thoughtfully fast’ decisions, act quickly, cut through red tape, deliver progress not perfection, take ownership and accountability.</p>
<p><strong>Team Spirit</strong></p>
<p>We put the team ahead of ourselves, foster trust and respect, collaborate with passion, despise toxic politics, value our differences, and celebrate together.</p>
<p><strong>Innovation</strong></p>
<p>We challenge the status quo, experiment thoughtfully, and are novel and brilliant in what we create.</p>
<p><strong>Excellence</strong></p>
<p>We love to win, but we hate losing even more. We aspire to be the best and take pride in our work. When we fall short, we own it and come back stronger.</p></div><p><strong><span data-contrast="auto">Information Security Analyst</span></strong><span data-ccp-props="{"335551550":6,"335551620":6,"335557856":16777215,"335559739":300}"> </span></p>
<p><span data-contrast="auto">Information Security Analyst will support Billtrust's compliance and assurance programs across our key security frameworks, contribute to risk assessment activities, and help protect the systems that power our business payments platform. You'll work closely with cross-functional teams and report to the Information Security Manager.</span> <br> <br><strong><span data-contrast="auto">Assurance Frameworks</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":320,"335559739":120}"> </span></p>
<p><span data-contrast="auto">This role directly supports Billtrust's compliance posture across the following frameworks:</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":40,"335559739":40}"> </span></p>
<p><span data-contrast="auto"> </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":60,"335559739":60}"> </span></p>
<table data-tablestyle="MsoNormalTable" data-tablelook="1696">
<tbody>
<tr>
<td data-celllook="69905">
<p><strong><span data-contrast="none">Framework</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
<td data-celllook="69905">
<p><strong><span data-contrast="none">Scope</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
</tr>
<tr>
<td data-celllook="69905">
<p><strong><span data-contrast="none">SOC 1 / ISAE 3402</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
<td data-celllook="4369">
<p><span data-contrast="none">Financial reporting controls & service organization attestation</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
</tr>
<tr>
<td data-celllook="69905">
<p><strong><span data-contrast="none">SOC 2 Type 2</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
<td data-celllook="4369">
<p><span data-contrast="none">Security, Availability, Confidentiality trust service criteria</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
</tr>
<tr>
<td data-celllook="69905">
<p><strong><span data-contrast="none">ISO 27001</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
<td data-celllook="4369">
<p><span data-contrast="none">Information security management system (ISMS)</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
</tr>
<tr>
<td data-celllook="69905">
<p><strong><span data-contrast="none">PCI DSS</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
<td data-celllook="4369">
<p><span data-contrast="none">Payment card industry data security standards</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
</tr>
<tr>
<td data-celllook="69905">
<p><strong><span data-contrast="none">HIPAA BAA</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
<td data-celllook="4369">
<p><span data-contrast="none">Health information privacy and security requirements</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></p>
</td>
</tr>
</tbody>
</table>
<p><span data-ccp-props="{"335551550":6,"335551620":6,"335557856":16777215,"335559739":300}"> </span></p>
<p><strong><span data-contrast="none"><span data-ccp-parastyle="heading 3">Key Responsibilities</span></span></strong> <br> <br><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 3">Compliance & Audit Support</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":6,"335551620":6,"335559738":200,"335559739":80}"> </span></p>
<ul>
<li><span data-contrast="auto">Assist in the preparation and execution of SOC 1/ISAE 3402 and SOC 2 Type 2 audits, including evidence collection, control walkthroughs, and liaising with external auditors</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Support ISO 27001 surveillance and certification audits; maintain ISMS documentation and control evidence</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Assist with PCI DSS assessments, including scope validation, control testing, and QSA coordination</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Support HIPAA BAA obligations, including risk analysis activities and documentation of safeguards </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Risk & Controls</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":200,"335559739":80}"> </span></p>
<ul>
<li><span data-contrast="auto">Participate in information security risk assessments and help maintain the risk register</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Evaluate and test internal controls over Billtrust information systems</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Review and provide input on policies, procedures, and standards to ensure alignment with applicable frameworks</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Assist in vendor security reviews and third-party risk assessments</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<p><span data-contrast="auto"> </span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":60,"335559739":60}"> </span></p>
<p><strong><span data-contrast="auto">Security Operations & Advisory</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":200,"335559739":80}"> </span></p>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Support vulnerability assessment activities and help track remediation progress</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="10" data-aria-level="1"><span data-contrast="auto">Assist with the review and maintenance of incident response and business continuity documentation</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="11" data-aria-level="1"><span data-contrast="auto">Monitor the security and compliance landscape for emerging risks relevant to Billtrust's frameworks</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="12" data-aria-level="1"><span data-contrast="auto">Contribute to internal awareness and training initiatives</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Reporting & Documentation</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":200,"335559739":80}"> </span></p>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="13" data-aria-level="1"><span data-contrast="auto">Prepare accurate and thorough work papers documenting scope, procedures, and results</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="14" data-aria-level="1"><span data-contrast="auto">Assist in drafting findings summaries and remediation recommendations for internal stakeholders</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="29" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="15" data-aria-level="1"><span data-contrast="auto">Maintain compliance evidence repositories and audit-ready documentation</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Qualifications</span></span></strong> <br> <br><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Required:</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":6,"335551620":6,"335559738":200,"335559739":80}"> </span></p>
<ol>
<li><span data-contrast="auto">1–3 years of experience in information security, GRC, compliance, or a closely related role</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Working knowledge of at least two of Billtrust's assurance frameworks: SOC 1/2, ISO 27001, PCI DSS, or HIPAA</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Familiarity with common security frameworks and standards (e.g., NIST CSF, CIS Controls, ISO 27001)</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Strong written and verbal communication skills; ability to document findings clearly and concisely</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
<li><span data-contrast="auto">Bachelor's degree in Information Systems, Computer Science, Business, or a related field — or equivalent experience</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ol>
<p><strong><span data-contrast="auto">Preferred:</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559738":200,"335559739":80}"> </span></p>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="30" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Exposure to GRC tools or audit management platforms</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="30" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Experience supporting external audit engagements (SOC, PCI QSA, ISO certification body)</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="30" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Relevant certification in progress or obtained (e.g., CompTIA Security+, CISA, CISSP, ISO 27001 Lead Implementer)</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<ul>
<li data-leveltext="•" data-font="Aptos" data-listid="30" data-list-defn-props="{"335552541":0,"335559685":720,"335559991":360,"469769242":[65533,0],"469777803":"left","469777804":"•","469777815":"hybridMultilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Basic familiarity with vulnerability assessment tools or security monitoring platforms</span><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559685":600,"335559737":0,"335559738":0,"335559739":0,"335559991":300}"> </span></li>
</ul>
<p><span data-ccp-props="{"134233117":false,"134233118":false,"335551550":6,"335551620":6,"335559737":0,"335559738":0,"335559739":0}"> </span></p>
<p> </p>
747,000+ hidden jobs like this
billtrust1 and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites