Security GRC Analyst

3 hours, 30 minutes ago
Full-time
Junior
Cybersecurity
Protective Life

Protective Life

Protective Life Insurance Company offers financial security through insurance and investment products, serving people and protecting families for over a century.

Insurance
1K-5K
Founded 1907

Description

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS.
  • Document risk findings and drive mitigation strategies across systems, processes, and infrastructure.
  • Analyze vulnerability assessment reports to support troubleshooting, remediation, and risk reduction.
  • Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications.
  • Deliver reporting and insights, including assessment results, GRC metrics, dashboards, and executive presentations.
  • Perform cyber third-party risk assessments, including vendor onboarding and offboarding reviews.
  • Support governance and control management by maintaining policies, standards, and control libraries.
  • Enable audit readiness and due diligence by managing evidence collection and external audit responses.
  • Stay current on regulations, frameworks, and industry trends and incorporate updates into controls and practices.
  • Manage priorities using Agile methods, including task tracking, issue resolution, risk escalation, and status updates.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, or a related field.
  • 1–3 years of experience in GRC, risk management, or cybersecurity compliance.
  • Working knowledge of regulatory frameworks, audit processes, and control environments.
  • Understanding of third-party/vendor risk management (TPRM) and enterprise risk concepts.
  • General knowledge of security tools and controls across network security, endpoint protection, email security, vulnerability management, access controls, and log management.
  • Foundational understanding of cloud service models, including IaaS, SaaS, and PaaS.
  • Experience tracking and reporting IS GRC program effectiveness using ServiceNow, Archer, SharePoint, and Power BI.
  • Experience developing training materials and communicating with technical and business stakeholders.
  • Strong organizational, analytical, multitasking, written, and verbal communication skills.
  • Preferred experience with cloud security compliance in Azure or AWS.
  • Experience with Microsoft Office Suite and familiarity with SharePoint, Power BI, ServiceNow, UpGuard, or Archer.
  • Preferred certifications include CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+.

Benefits

  • Comprehensive health, dental, and vision insurance.
  • Mental health benefits and an employee assistance program.
  • Paid time off, paid parental leave, short-term disability, and a cultural observance day.
  • 401(k) plan with company matching.
  • Pension plan.
  • Contributions to healthcare accounts.
  • ProHealth Rewards cash rewards program for wellbeing.
  • Equal opportunity, inclusive employer environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

RASP Cyber Force | Професійна програма для ветеранів у сфері кібербезпеки

Raiffeisen Bank’s RASP Cyber Force is a six-month cybersecurity development program for veterans and service members, combining training and part-time work in one of the bank’s information security teams.

Cybersecurity Encryption Network Security Penetration Testing SOC
2 hours, 45 minutes ago

Governance, Risk and Compliance Specialist

AvePoint 1K-5K Internet Software & Services

AvePoint is hiring an IT security operations professional to support system security, access control, compliance, and lifecycle management across enterprise environments.

3 hours ago

Digital Forensics SME

Lever 251-1K Professional Services

AnaVation is hiring a Senior Digital Forensics professional to support federal law-enforcement investigations, cybercrime cases, and operational missions through advanced forensic analysis and capability development.

Cybersecurity PowerShell Python
3 hours ago

Web3 Security Senior Operations Specialist

Binance 5K-10K Capital Markets

Binance is hiring a Web3 security and fraud operations specialist to analyze complex cases, strengthen defenses, and improve detection and knowledge-sharing across the team.

Blockchain
3 hours, 15 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers