
Security GRC Analyst
Protective
Completely RemoteFull TimeInformation Technology
Posted Today
Job description
Responsibilities
- Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS
- Analyze vulnerability assessment reports to support remediation and risk reduction
- Develop and execute security awareness programs, including training and phishing simulations
- Deliver actionable reporting and GRC metrics via dashboards and executive presentations
- Perform end-to-end cyber third-party risk assessments and vendor onboarding/offboarding
- Drive process and tooling optimization for GRC platforms
- Support governance and control management by maintaining policies and standards
- Enable audit readiness through evidence collection and repository maintenance
- Manage priorities using Agile methodologies
Requirements
- Bachelor's degree in Cybersecurity, Information Systems, or related field
- 1–3 years of experience in GRC, risk management, or compliance within cybersecurity
- Working knowledge of regulatory frameworks and audit processes
- Understanding of third-party/vendor risk management (TPRM) processes
- General knowledge of security tools (network security, endpoint protection, vulnerability management)
- Foundational understanding of cloud service models (IaaS, SaaS, PaaS)
- Ability to track and report on GRC effectiveness using tools like ServiceNow, Archer, or Power BI
- Strong organizational and analytical skills
Preferred Qualifications
- Experience with cloud security compliance (Azure/AWS)
- Familiarity with UpGuard, SharePoint, or Power BI
- Certifications such as CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+
About the Company
Protective helps protect customers against life's uncertainties, providing protection and peace of mind when it is needed most.
Skills & tools
GRCNISTCybersecurity
What the team is looking for
Use this list as a quick fit check before you apply.
- 01Bachelor's degree in Cybersecurity or related field
- 021-3 years GRC or compliance experience
- 03Knowledge of NIST, SOC 2, or CIS frameworks
- 04Understanding of TPRM processes
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches
Protective
Job details
- Work model
- Completely Remote
- Commitment
- Full Time
- Category
- Information Technology
- Posted
- Today
AdWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matches