Security GRC Analyst

1 month, 1 week ago
Full-time
Junior
Cybersecurity
Protective Life

Protective Life

Protective Life Insurance Company offers financial security through insurance and investment products, serving people and protecting families for over a century.

Insurance
1K-5K
Founded 1907

Description

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS.
  • Document risk findings and drive mitigation strategies across systems, processes, and infrastructure.
  • Analyze vulnerability assessment reports to support troubleshooting, remediation, and risk reduction.
  • Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications.
  • Deliver reporting and insights, including assessment results, GRC metrics, dashboards, and executive presentations.
  • Perform cyber third-party risk assessments, including vendor onboarding and offboarding reviews.
  • Support governance and control management by maintaining policies, standards, and control libraries.
  • Enable audit readiness and due diligence by managing evidence collection and external audit responses.
  • Stay current on regulations, frameworks, and industry trends and incorporate updates into controls and practices.
  • Manage priorities using Agile methods, including task tracking, issue resolution, risk escalation, and status updates.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, or a related field.
  • 1–3 years of experience in GRC, risk management, or cybersecurity compliance.
  • Working knowledge of regulatory frameworks, audit processes, and control environments.
  • Understanding of third-party/vendor risk management (TPRM) and enterprise risk concepts.
  • General knowledge of security tools and controls across network security, endpoint protection, email security, vulnerability management, access controls, and log management.
  • Foundational understanding of cloud service models, including IaaS, SaaS, and PaaS.
  • Experience tracking and reporting IS GRC program effectiveness using ServiceNow, Archer, SharePoint, and Power BI.
  • Experience developing training materials and communicating with technical and business stakeholders.
  • Strong organizational, analytical, multitasking, written, and verbal communication skills.
  • Preferred experience with cloud security compliance in Azure or AWS.
  • Experience with Microsoft Office Suite and familiarity with SharePoint, Power BI, ServiceNow, UpGuard, or Archer.
  • Preferred certifications include CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+.

Benefits

  • Comprehensive health, dental, and vision insurance.
  • Mental health benefits and an employee assistance program.
  • Paid time off, paid parental leave, short-term disability, and a cultural observance day.
  • 401(k) plan with company matching.
  • Pension plan.
  • Contributions to healthcare accounts.
  • ProHealth Rewards cash rewards program for wellbeing.
  • Equal opportunity, inclusive employer environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Investigator

Stripe 5K-10K Diversified Financial Services

Stripe is hiring an Abuse Operations professional to investigate and lead response to product abuse and fraud incidents, helping protect merchants and strengthen fraud prevention across its financial infrastructure platform.

Apache Spark Databricks Network Security Pandas Python Scikit-learn SQL Trino
15 hours, 28 minutes ago

Senior Incident Responder

Dragos 251-1K Professional Services

Dragos is hiring a Senior Incident Responder in Singapore to support APAC customers by investigating and coordinating responses to high-impact incidents across complex OT environments.

1 day, 15 hours ago

Senior SOC Analyst | MDR

UltraViolet Cyber 501-1000 Computer and Network Security

UltraViolet Cyber is seeking a Senior Security Analyst to join its 24/7 shared-services Cyber Defense team, investigating security incidents and strengthening protection for client infrastructure and data.

Cybersecurity Linux Network Security
1 day, 16 hours ago

Security GRC Specialist

SAP Fioneer 1K-5K Internet Software & Services

SAP Fioneer is seeking a Security GRC Specialist to strengthen and scale security governance, risk, and compliance practices across its financial services software products and operations.

2 days, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers