Security GRC Analyst
Job description
Security GRC Analyst at Protective
About the role
This position supports the company's commitment to safeguarding customers by ensuring the security and compliance of our systems and processes. You will play a key role in assessing risks, developing security awareness, and managing third-party relationships to maintain a strong security posture.
Key facts
What you'll do
Conduct and enhance enterprise risk assessments using frameworks like NIST CSF, NIST 800-53, SOC 2, and CIS, documenting findings and guiding mitigation efforts.
Analyze vulnerability assessment reports to aid in troubleshooting, remediation, and risk reduction.
Develop and implement security awareness initiatives, including training and simulated phishing campaigns, to influence behavior and lower risk.
Provide clear reports and insights on risk status, control effectiveness, and program maturity through metrics, dashboards, and executive summaries.
Manage the complete lifecycle of cyber third-party risk assessments, from vendor onboarding to offboarding, focusing on high-risk engagements.
Improve GRC processes and tools, contributing to platform design and standardizing workflows for better consistency and scalability.
Support governance and control management by creating and maintaining policies and standards aligned with regulations and best practices.
Facilitate audit readiness by managing evidence collection and standardizing responses for external audits and inquiries.
Keep abreast of evolving regulations, frameworks, and industry trends, integrating them into current practices.
Manage tasks and progress using Agile methodologies, tracking assignments, resolving issues, and reporting status.
Requirements
Hold a Bachelor's degree in Cybersecurity, Information Systems, or a related field.
Possess 1-3 years of experience in GRC, risk management, or cybersecurity compliance.
Demonstrate a working knowledge of regulatory frameworks, audit procedures, and control environments, including industry standards and risk terminology.
Understand third-party risk management (TPRM) and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation.
Have general knowledge of security tools and controls across network security, endpoint protection, email security, vulnerability management, access controls, and log management.
Possess a foundational understanding of cloud service models (IaaS, SaaS, PaaS).
Show a proven ability to track, measure, and report on IS GRC program effectiveness using tools like ServiceNow, Archer, SharePoint, and Power BI, translating metrics into actionable insights.
Have experience contributing to the ongoing improvement of GRC programs, identifying enhancements, and presenting recommendations.
Possess experience developing and delivering training materials, with strong written and verbal communication skills for engaging diverse stakeholders.
Exhibit strong organizational, analytical, and multitasking abilities, with the capacity to manage competing priorities and collaborate effectively.
Nice to have
Experience with cloud security compliance in Azure or AWS.
Familiarity with Microsoft Office Suite and tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer.
Hold certifications such as CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+.
Skills & tools
NIST CSF, NIST 800-53, SOC 2, CIS, ServiceNow, Archer, SharePoint, Power BI, UpGuard, Microsoft Office Suite, Agile methodologies.
Practical notes
Protective offers a comprehensive benefits package designed to support employee wellbeing, including health, dental, and vision insurance, mental health support, and an employee assistance program. We also provide various paid time away benefits, a pension plan, and a 401(k) with company matching. Financial and physical wellbeing are encouraged through programs like ProHealth Rewards. Eligibility for certain benefits may vary by position.
If you require an accommodation to complete the application process due to a disability, please email eric.hess@protective.com. This email is for accommodation requests only.
Protective is an equal opportunity employer committed to diversity and inclusion.