Security GRC Analyst

1 month, 1 week ago
Full-time
Junior
Cybersecurity
Protective Life

Protective Life

Protective Life Insurance Company offers financial security through insurance and investment products, serving people and protecting families for over a century.

Insurance
1K-5K
Founded 1907

Description

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS.
  • Document risk findings and drive mitigation strategies across systems, processes, and infrastructure.
  • Analyze vulnerability assessment reports to support troubleshooting, remediation, and risk reduction.
  • Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications.
  • Deliver reporting and insights, including assessment results, GRC metrics, dashboards, and executive presentations.
  • Perform cyber third-party risk assessments, including vendor onboarding and offboarding reviews.
  • Support governance and control management by maintaining policies, standards, and control libraries.
  • Enable audit readiness and due diligence by managing evidence collection and external audit responses.
  • Stay current on regulations, frameworks, and industry trends and incorporate updates into controls and practices.
  • Manage priorities using Agile methods, including task tracking, issue resolution, risk escalation, and status updates.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, or a related field.
  • 1–3 years of experience in GRC, risk management, or cybersecurity compliance.
  • Working knowledge of regulatory frameworks, audit processes, and control environments.
  • Understanding of third-party/vendor risk management (TPRM) and enterprise risk concepts.
  • General knowledge of security tools and controls across network security, endpoint protection, email security, vulnerability management, access controls, and log management.
  • Foundational understanding of cloud service models, including IaaS, SaaS, and PaaS.
  • Experience tracking and reporting IS GRC program effectiveness using ServiceNow, Archer, SharePoint, and Power BI.
  • Experience developing training materials and communicating with technical and business stakeholders.
  • Strong organizational, analytical, multitasking, written, and verbal communication skills.
  • Preferred experience with cloud security compliance in Azure or AWS.
  • Experience with Microsoft Office Suite and familiarity with SharePoint, Power BI, ServiceNow, UpGuard, or Archer.
  • Preferred certifications include CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+.

Benefits

  • Comprehensive health, dental, and vision insurance.
  • Mental health benefits and an employee assistance program.
  • Paid time off, paid parental leave, short-term disability, and a cultural observance day.
  • 401(k) plan with company matching.
  • Pension plan.
  • Contributions to healthcare accounts.
  • ProHealth Rewards cash rewards program for wellbeing.
  • Equal opportunity, inclusive employer environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

GRC Analyst

Coretelligent 251-1K Internet Software & Services

Coretelligent is seeking a GRC Analyst to support client cybersecurity and compliance programs through security awareness initiatives, vendor risk assessments, controls framework maintenance, and governance activities across multiple environments.

Cybersecurity HIPAA
7 hours, 29 minutes ago

Security GRC Analyst

Pinterest 5K-10K Internet Software & Services

Pinterest is seeking a Security Engineer (GRC Senior Analyst) to strengthen its security governance, risk, compliance, audit, and assurance programs while helping cross-functional teams manage security risk effectively.

Cybersecurity
7 hours, 44 minutes ago

Data Governance Analyst

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a Data Governance Analyst to support client engagements involving data security, privacy, regulatory compliance, and responsible AI governance.

Python
2 days, 7 hours ago

SOC L1 Analyst

Lion Hires Recruitment / staffing / talent acquisition

The client is seeking a SOC Analyst to monitor fintech infrastructure, detect and respond to threats, and strengthen security operations protecting sensitive financial data.

AWS Azure Cybersecurity ELK Stack SIEM Splunk
2 days, 8 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers