2

Remote Credit Risk Review Jobs in Pennsylvania (NOW HIRING)

Fractional CISO This is a fully remote (work-from-home) position. Work from anywhere in the United ... Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh ...

Showing results 41-60

Remote Credit Risk Review information

What are the key skills and qualifications needed to thrive as a remote credit risk review analyst, and why are they important?

To thrive as a Remote Credit Risk Review Analyst, you need a solid understanding of credit risk assessment, financial analysis, and regulatory compliance, typically supported by a degree in finance, accounting, or a related field. Familiarity with risk management software, credit scoring tools, and data analytics platforms is essential, and certifications like FRM or CFA can be advantageous. Strong attention to detail, analytical thinking, and effective communication skills help you interpret data and present findings clearly to stakeholders. These skills and qualities are crucial for identifying potential risks, ensuring sound lending decisions, and maintaining the financial health of the organization.

How does a remote credit risk review professional typically collaborate with other departments to ensure comprehensive risk assessments?

Remote Credit Risk Review professionals frequently work closely with teams such as lending, compliance, and internal audit to gather the necessary data and insights for thorough risk evaluations. While much of the analysis is conducted independently, regular virtual meetings and shared documentation platforms are used to discuss findings, clarify data discrepancies, and recommend improvements. This collaborative process ensures that the risk review is well-rounded and aligns with organizational policies and regulatory requirements. Building strong remote communication skills and a proactive approach to cross-functional teamwork are essential for success in this role.

What is a remote credit risk review?

A Remote Credit Risk Review is an evaluation process conducted by financial professionals to assess the creditworthiness of borrowers or the effectiveness of a company's credit risk management practices, all done remotely rather than in person. These reviews typically analyze loan portfolios, credit policies, and risk controls to ensure compliance with regulations and to identify potential areas of risk. By leveraging technology, remote reviews allow for efficient, flexible, and thorough assessments without the need for on-site visits, making them ideal for organizations with geographically dispersed operations.

What is the difference between Remote Credit Risk Review vs Remote Credit Analyst?

AspectRemote Credit Risk ReviewRemote Credit Analyst
Primary FocusAssessing credit risk and reviewing existing credit portfoliosAnalyzing credit data to evaluate loan applications
CertificationsTypically requires risk management or financial certificationsOften requires finance or banking certifications
Work EnvironmentMostly independent review, often in risk management teamsCollaborative analysis within lending or banking teams
Industry UsageCommon in banking, finance, and lending institutionsWidely used in banking, credit unions, and financial services

While both roles involve financial analysis, Remote Credit Risk Review focuses on evaluating existing credit portfolios and managing risk, whereas Remote Credit Analyst primarily assesses new loan applications. Understanding these differences helps job seekers target the right position based on their skills and career goals.

What cities in Pennsylvania are hiring for Remote Credit Risk Review jobs? Cities in Pennsylvania with the most Remote Credit Risk Review job openings:
Infographic showing various Remote Credit Risk Review job openings in Pennsylvania as of August 2026, with employment types broken down into 81% Full Time, 10% Part Time, and 9% Contract. Highlights an 100% Remote job distribution.

Fractional CISO

Reflexion

Lancaster, PA โ€ข Remote

Contractor

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Fractional CISO

This is a fully remote (work-from-home) position. Work from anywhere in the United States.

Contract / fractional ยท ~15โ€“25 hrs in the first 60 days, then ~5โ€“10 hrs per quarter

About Reflexion

Reflexion Interactive Technologies builds neuro-cognitive and physiological sensing technology โ€” vision-performance training and respiration-waveform sensing โ€” used by athletes, teams, and now a global consumer-eyewear partner. We are a ~10-person, AWS-hosted company based in Lancaster, PA, closing enterprise partnerships that bring enterprise-grade vendor-security requirements with them.

The role

We are hiring a fractional CISO to be the accountable security executive behind our compliance program as we finalize a major enterprise deal. This is not a build-a-SOC, hire-a-team role: our application-layer security is strong (bcrypt, encrypted sessions, CSRF, parameterized SQL, strict CSP, MFA/RBAC, AES-256 at rest, TLS 1.2+), our compliance calendar and evidence pipeline are run day-to-day by an internal compliance system, and engineering is handled by our CTO. What we need is the credentialed human who signs, validates, and represents.

You will work directly with the CEO (deal owner) and CTO (implementation owner). Our internal compliance agent drafts the documents, tracks the obligations register, and maintains the evidence locker โ€” you review, correct, and put your name on what is true.

What you will do โ€” first 60 days
  • Review and harden our Statement of Applicability + evidence package (ISO 27001/NIST-mapped) responding to an enterprise customer\'s Information Security Addendum โ€” built largely from an existing, customer-reviewed evidence base.
  • Sign the risk assessment and SoA as the named security officer; be the security contact enterprise vendor-risk teams can call.
  • Sit on 2โ€“3 customer security-diligence calls (enterprise vendor-risk / InfoSec reviewers) alongside the CEO.
  • Validate what we attest against reality with the CTO (controls verification and gap triage: centralized logging, admin RBAC/audit trail, secrets management).
  • Advise on a security-exception / compensating-controls request and, if required, scope a right-sized SOC 2 Type I path (RFQs prepared; you would manage auditor selection and the engagement).
  • Scope and manage our first external penetration test (vendor shortlist ready) and own findings triage with the CTO.
Ongoing โ€” a few hours a quarter
  • Quarterly review of the compliance-calendar output (access reviews, risk-assessment refresh, training, phishing simulations, BC/DR and restore tests).
  • Annual re-attestation support; named contact for customer audits under contractual audit rights.
  • Incident readiness: review our breach-notification runbook (24โ€“72h contractual clocks) and advise if an incident ever triggers it.
  • Tell us when a new deal\'s requirements genuinely change our posture โ€” versus when to negotiate them down. We optimize for minimum-viable compliance and want a partner who respects that philosophy rather than gold-plating.
What we are looking for
  • Prior CISO / vCISO / security-lead experience at a company that sold to large enterprises โ€” you have personally survived enterprise vendor-risk review (security questionnaires, information-security addenda, right-to-audit clauses) from the vendor side.
  • Hands-on fluency with ISO 27001 / NIST CSF control mapping, SOC 2 (readiness through audit), and pragmatic compensating-controls / security-exception practice.
  • Comfortable being the named, accountable individual โ€” signing SoAs and risk assessments, taking customer calls, standing behind attestations.
  • Technical enough to verify controls in an AWS + Cloudflare stack with the CTO (IAM, KMS, CloudTrail/logging, network posture) โ€” you do not implement, but you cannot be bluffed.
  • Working knowledge of HIPAA applicability analysis (we maintain a no-PHI / not-a-business-associate posture and need it defended, not expanded) and GDPR-adjacent vendor obligations (we have EU counsel; you coordinate, not own).
  • Plain-spoken, fast, allergic to compliance theater. You will be asked "is this actually required, or negotiable?" constantly โ€” we want the honest answer.
  • Bonus: consumer wellness / health-adjacent data classification; EU AI Act awareness; prior work with AI-assisted compliance tooling.
What this is not
  • Not full-time, and no conversion pressure โ€” genuinely fractional.
  • Not a program-build from zero: policies (v1.0), an evidence base, an obligations register, a DPA/SCC pack, and counsel relationships already exist.
  • Not an implementation role: engineering changes belong to the CTO; you verify and advise.
Engagement & compensation

Hourly contract (rate DOE) or an equivalent small monthly block. Front-loaded first 60 days (~15โ€“25 hours), then ~5โ€“10 hours per quarter. Direct line to the CEO and CTO. NDA required; the work references a Fortune-Global-500-scale counterparty under confidentiality.

How to apply

Send a short note covering: (1) an enterprise vendor-security review you got a small company through โ€” what you accepted and what you pushed back on; (2) your hourly rate and availability over the next 60 days. Resume/LinkedIn welcome; the note matters more.