Security GRC Analyst
Job description
About the role
This role is integral to Protective's mission of ensuring the safety and compliance of our systems and processes, thereby protecting our customers. As a Security GRC Analyst, you will be responsible for evaluating risks, fostering security awareness, and overseeing third-party relationships to uphold a robust security framework. Your contributions will be vital in enhancing our security posture and ensuring adherence to regulatory standards.
Key facts
What you'll do
- Conduct comprehensive enterprise risk assessments utilizing established frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, documenting findings and guiding necessary mitigation strategies.
- Analyze vulnerability assessment reports to assist in troubleshooting, remediation efforts, and overall risk reduction.
- Design and implement security awareness programs, which may include training sessions and simulated phishing exercises, aimed at influencing employee behavior and minimizing risks.
- Generate clear and insightful reports on risk status, control effectiveness, and program maturity through the use of metrics, dashboards, and executive summaries.
- Oversee the entire lifecycle of third-party cyber risk assessments, from vendor onboarding to offboarding, with a focus on managing high-risk engagements effectively.
- Enhance Governance, Risk, and Compliance (GRC) processes and tools, contributing to platform design and standardizing workflows for improved consistency and scalability.
- Support governance and control management by developing and maintaining policies and standards that align with regulatory requirements and best practices.
- Facilitate audit readiness by managing evidence collection and standardizing responses for external audits and inquiries.
- Stay updated on evolving regulations, frameworks, and industry trends, integrating relevant changes into current practices.
- Utilize Agile methodologies to manage tasks and progress, ensuring effective tracking of assignments, issue resolution, and status reporting.
Requirements
- A Bachelor's degree in Cybersecurity, Information Systems, or a related discipline is required.
- A minimum of 1 to 3 years of experience in Governance, Risk, and Compliance (GRC), risk management, or cybersecurity compliance is essential.
- A solid understanding of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk terminology.
- Knowledge of third-party risk management (TPRM) and enterprise risk concepts, with the ability to assist in risk identification, assessment, and mitigation.
- General familiarity with security tools and controls across various domains, including network security, endpoint protection, email security, vulnerability management, access controls, and log management.
- A foundational understanding of cloud service models such as IaaS, SaaS, and PaaS is beneficial.
- Proven ability to track, measure, and report on the effectiveness of information security GRC programs using tools like ServiceNow, Archer, SharePoint, and Power BI, translating metrics into actionable insights.
- Experience in contributing to the continuous improvement of GRC programs, identifying areas for enhancement, and presenting recommendations effectively.
- Strong written and verbal communication skills, with experience in developing and delivering training materials for diverse audiences.
- Excellent organizational, analytical, and multitasking skills, with the ability to manage competing priorities and collaborate effectively with team members.
Nice to have
- Experience with cloud security compliance, particularly in Azure or AWS environments.
- Familiarity with Microsoft Office Suite and tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer.
- Relevant certifications such as CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+ would be advantageous.
Skills & tools
Proficiency in frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS is essential. Familiarity with tools including ServiceNow, Archer, SharePoint, Power BI, UpGuard, and Agile methodologies is also important.
Practical notes
Protective provides a comprehensive benefits package aimed at supporting employee well-being, which includes health, dental, and vision insurance, mental health resources, and an employee assistance program. Employees also enjoy various paid time off benefits, a pension plan, and a 401(k) plan with company matching. Programs like ProHealth Rewards promote financial and physical well-being. Eligibility for specific benefits may vary depending on the position.
If you require assistance to complete the application process due to a disability, please reach out via email to eric.hess@protective.com. This email is designated solely for accommodation requests.
Protective is an equal opportunity employer that values diversity and inclusion in the workplace.
About the company
Measures exist to shield people and systems from outside harm. Insurance guards finances, clothing reduces injury, locks and alarms secure property. Such actions, whether for persons, structures, or rights, all share one purpose: preventing loss. Customers seek this safety in daily life. Work here involves understanding these needs and designing responses. Consistent focus on defense guides products and services, meeting this demand through practical solutions that adapt to changing risks.