Security GRC Analyst

Protective

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS
  • Analyze vulnerability assessment reports to support remediation and risk reduction
  • Develop and execute security awareness programs, including training and phishing simulations
  • Deliver actionable reporting and GRC metrics via dashboards and executive presentations
  • Perform end-to-end cyber third-party risk assessments and vendor onboarding/offboarding
  • Drive process and tooling optimization for GRC platforms
  • Support governance and control management by maintaining policies and standards
  • Enable audit readiness through evidence collection and repository maintenance
  • Manage priorities using Agile methodologies

Requirements

  • Bachelor's degree in Cybersecurity, Information Systems, or related field
  • 1–3 years of experience in GRC, risk management, or compliance within cybersecurity
  • Working knowledge of regulatory frameworks and audit processes
  • Understanding of third-party/vendor risk management (TPRM) processes
  • General knowledge of security tools (network security, endpoint protection, vulnerability management)
  • Foundational understanding of cloud service models (IaaS, SaaS, PaaS)
  • Ability to track and report on GRC effectiveness using tools like ServiceNow, Archer, or Power BI
  • Strong organizational and analytical skills

Preferred Qualifications

  • Experience with cloud security compliance (Azure/AWS)
  • Familiarity with UpGuard, SharePoint, or Power BI
  • Certifications such as CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, or Security+

About the Company

Protective helps protect customers against life's uncertainties, providing protection and peace of mind when it is needed most.

Skills & tools

GRCNISTCybersecurity

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Bachelor's degree in Cybersecurity or related field
  2. 021-3 years GRC or compliance experience
  3. 03Knowledge of NIST, SOC 2, or CIS frameworks
  4. 04Understanding of TPRM processes
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches