Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing.
We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.
Rather than build on top of broken legacy systems, we took a different approach: we built and operate our own mortgage servicing business managing $110+ billion in loans. This wasn't the end goal, it was how we deeply understood the complexity needed to build software that actually works in regulated industries.
The results speak for themselves. We've transformed mortgage servicing from a 0% margin business into 60%+ margins while dramatically improving customer experience. Major enterprise contracts are now deploying across the industry.
ValonOS is our unified platform that makes every process structured and programmable and it is perfectly positioned for the AI era. When everything flows through one system with rich data, AI agents don't just automate tasks, they continuously improve entire operations. Mortgage servicing is just the beginning of our vision to transform regulated industries and beyond.
Our customers entrust us with some of their most sensitive and personal financial information, and it is the ultimate mission of Valon’s Security team to ensure we have sound programs, processes, and automation in place to safeguard our customers’ data. The Security team protects the infrastructure and data for processing billions of dollars of mortgage loans. We work cross-functionally with product, engineering, IT, legal, and more to enable security throughout the organization and engage with internal and external assessors to continuously evaluate Valon’s security posture.
We are seeking a motivated Information Security Analyst to join our growing team! As a key security member at Valon, you will play a critical role in ensuring the security of our organization's systems, cloud infrastructure, products and data. This role will be working closely with the CISO and the Security team, and is responsible for ensuring the company’s technical controls meet security compliance requirements, managing risks and remediation, supporting operational and monitoring efforts, and driving program management activities. The ideal candidate has a strong foundation in security principles, an eye for detail, a proactive approach to problem-solving, and the ability to collaborate with cross-functional teams to ensure we protect our most critical assets to uphold trust with our customers and stakeholders.
Assist in implementing and maintaining compliance with frameworks (SOC 2, NIST CSF, CIS) and regulatory requirements (NYDFS, GLBA, Safeguards, CCPA and related)
Support internal and external security audits and exams, including evidence gathering and remediation tracking
Review, manage, and monitor security policies for compliance
Manage and coordinate remediation for vulnerability, security, and compliance issues across stakeholders
Conduct security risk assessments and monitoring
Support on-call and operational security activities including monitoring security alerts, investigating incidents, vendor security reviews, security awareness and training, and other tasks
Manage and track security metrics, KPIs and reporting
Manage security policies, standards, and procedures
Maintain customer facing security documentation and informational assets
Proven experience in a security analyst related role, with a focus on security compliance, issue management, vulnerability management, and/or security program management.
Experience with security and compliance frameworks and requirements (OWASP, SOC 2, NIST, ISO, CIS, etc.)
Basic knowledge of cloud security and public cloud environments
Ability to work autonomously, be agile, and balance multiple projects and operational efforts
Self-starter that is eager to learn and support across diverse areas
Ability to foster strong relationships and partner with stakeholders to drive results
Excellent communication and collaboration skills, with the ability to explain security concepts to technical and non-technical stakeholders
Strong organization and project management skills
Experience or exposure to startup environments is a plus
Experience or exposure to financial services, banking or fintech organizations is a plus
Minimum of 2-3 years as a security analyst or security program manager with relevant responsibilities and background
Bachelor's degree in Computer Science, Information Security, Technology, or a related field
Relevant security certifications based on career experience (CompTIA Security+, CC, SSCP or related), or seasoned career level (CISSP, CISM, CRISC or related)
Experience with security compliance frameworks and risk assessments
Experience with operational activities including issue management, security reviews, control monitoring, incident management, and reporting
Base Compensation Band: $100,000-$125,000. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills
This Base Compensation pay range applies to our New York City located staff and may differ according to location.
Compensation: Competitive salary with a meaningful stake in the company via equity, and 401k plan
Health & well-being: We’ll invest in your physical and mental well-being with comprehensive medical, dental, & vision benefits
Commuter benefits: We offer pre-tax deductions for public transportation, rideshare services, and parking expenses to make your commute more affordable and convenient
Grow together: Company wide orientation for you to successfully onboard and other learning & development opportunities including regular review cycles that feature 360 degree feedback
Play together: Quarterly budgets for team and company outings. Use it for team swag, cooking classes, or team dinners!
Generous time off: Flexible paid time off, sick days, and 11 company holidays
Baby bonding time!: 12 weeks off for both birthing and non-birthing parents - fully paid so you can focus your energy on your newest addition
Location: US (Remote) or NYC office (Hybrid - onsite)
Throughout the interview process, please remember that emails will only be from valon.com emails. We won't ever be asking for any personally identifiable information during the interview process itself. Please reach out to [email protected] if you have any requests to verify the authenticity of an outreach.
Valon is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws. Valon makes hiring decisions based solely on qualifications, merit, and business needs at the time.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
An early-career Software Engineer role at Valon to help build scalable, regulation-aware systems for mortgage servicing within a fast-moving, AI-focused fintech environment.
Valon is looking for a full-stack data analyst to own analytics end-to-end—building SQL models, dbt pipelines, dashboards, and data products that inform business and operational decisions.
HPD is hiring a Business Analyst to lead requirements, process and data design for Section 8 and housing subsidy system modernization within HPD Tech.
FISA is hiring a PeopleSoft Business Analyst to drive PeopleSoft HCM maintenance, integrations, and enhancements for NYC's HR, Benefits, and Payroll systems.
Mercor is hiring a Security Engineer to own infrastructure and application security, threat detection, and compliance as we scale rapidly in the AI training space.
Experienced IT support professional needed to lead day-to-day support operations, optimize processes, and serve as the primary escalation point for complex desktop and Microsoft 365 issues at WestEd's hybrid office in California.
AHEAD is hiring an Onboarding Engineer to configure, document, and validate client infrastructure for managed monitoring and act as a technical escalation point for Managed Services.
Versant's Cyber team seeks an experienced Directory Services Engineer to design, operate, and secure enterprise Active Directory, Entra/Azure AD, and LDAP environments across hybrid and cloud ecosystems.
Be part of SoFi's IT Internal Audit team evaluating technology and security controls to help manage risk and strengthen the company’s technology environment.
Support and improve utility-scale load forecasting processes using Python, Oracle SQL, and basic ML/AI concepts to deliver reliable demand forecasts for grid operations on a 12-month contract.
Platinum Technologies is hiring an Integration Engineer (Level II) to implement Radiant Logic and SailPoint at MacDill AFB and advance the organization's ICAM and Zero Trust posture.
Senior Cloud Infrastructure Engineer to lead and execute InfoTrack's cloud infrastructure strategy, building secure, scalable AWS-based systems and driving automation, observability, and compliance.
Agile Defense is hiring a SOC Operations Lead to direct enterprise SOC operations and incident response across hybrid on-premises and cloud environments while driving alignment with NIST CSF.
Lead and grow Agile Defense's Security Operations Center, overseeing enterprise incident response and SOC operations under an active Top-Secret clearance.
KBR is hiring an onsite IT Business Process Analyst in Jacksonville to support MCPP operations by developing SQL/Access databases, managing GCSS-MC functional requirements, and producing operational metrics and reports.
Valon’s mission is to champion homeowners on their financial journey as the partner they can trust with their home and future.
19 jobs