Business Wire Logo

Business Wire

Principal GRC Analyst

Reposted 15 Days Ago
Remote
Hiring Remotely in United States
175K-182K Annually
Senior level
Remote
Hiring Remotely in United States
175K-182K Annually
Senior level
The Principal GRC Analyst will manage cybersecurity risks, automate controls, conduct compliance assessments, and collaborate with stakeholders to enhance risk management processes.
The summary above was generated by AI
Business Wire, a Berkshire Hathaway company, is the global market leader in press release distribution and regulatory disclosure. We are on a mission to redefine how organizations connect with their audiences - and that’s just the beginning!

Organizations, large and small, depend on us to accurately publicize market-moving news and multimedia, and generate social engagements that develop interactions with their target audiences.

About the Role
The Principal Governance, Risk, and Compliance (GRC) Analyst will identify, assess, and mitigate cybersecurity risks, focusing on automating and optimizing cybersecurity controls. This role will evaluate the effectiveness of security controls, ensure compliance with relevant frameworks, and streamline risk management processes. The ideal candidate will possess deep cybersecurity risk management, regulatory compliance knowledge, and hands-on experience in Integrated Risk Management and Third-Party Risk Management (TPRM) tools.    
 
The Analyst will partner with the business, IT, and security organizations to coordinate the mitigation of identified risks and automate the controls to achieve a higher compliance level of mandated regulations, standards, and policies within the organization.   

What You'll Do

  • Automate and manage cybersecurity controls across the organization, ensuring they are appropriately implemented and effectively mitigate risks.
  • Evaluate, implement, and administer ITRM and TPRM tool(s).
  • Coordinate and participate in managing the risk register and risk mitigation efforts, including managing the risk exception process. 
  • Conduct internal cybersecurity and third-party risk assessments.
  • Develop and maintain an inventory of cybersecurity controls mapped to industry standards (e.g., NIST, ISO 27001, CIS, SOC 2) and regulatory requirements (e.g., GDPR, CCPA, PCI-DSS, and SOX). 
  • Develop assessment questionnaires and conduct compliance assessments to identify gaps in existing controls and recommend mitigation strategies, leveraging automation and assessment tools. 
  • Collaborate with key stakeholders (IT, InfoSec, Compliance, and Legal) to ensure that risks are understood, assessed, and appropriately addressed. 
  • Generate risk and control assessment reports and dashboards for senior leadership, identifying key risks, mitigation progress, and controls effectiveness metrics. 
  • Collaborate to document and maintain up-to-date policies and procedures related to cybersecurity risk management and control automation. 

What You'll Need

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or related field(s).  
  • 8+ years of experience using risk management and GRC platforms to automate control testing, conduct risk assessments, and track compliance. 
  • A strong understanding of cybersecurity controls, risk mitigation strategies, and their application for data protection and privacy compliance. 
  • Ability to analyze complex cybersecurity risks, identify control weaknesses, and recommend actionable mitigation strategies. 
  • Security and compliance certifications, such as CISSP, CISA, CISM, CGEIT, or CRISC, are preferred. Candidates with CISSP will be given preference.  

  • Technical Knowledge 
    Must possess solid working knowledge of/experience in: 
  • Identity and access management and governance concepts and technologies, such as Microsoft Entra, Active Directory, PAM, etc. 
  • Vulnerability management platforms such as Rapid7. 
  • IT asset management, Configuration Management Databases (CMDB), and network asset discovery tools.  
  • Control frameworks and objectives (e.g., NIST CSF, NIST RMF, PCI-DSS, SOX, SOC 2, GDPR, CCPA, etc.). 
  • Operating systems, databases, and middleware components. 
  • Conducting compliance and risk assessments. 
  • Management of IT and security projects.  
  • Office 365 tools (Word, Excel, SharePoint, OneDrive, Teams, and PowerPoint). 

  • Work Environment Characteristics 
  • Self-motivated and results-oriented, including the ability to prioritize conflicting assignments. 
  • Exceptional organizational skills to balance work and lead projects. 
  • Strong verbal and written skills.  
  • Ability to collaborate and build consensus and strong relationships with various internal and external stakeholders (business, development, security, auditors, legal, etc.). 
  • Ability to adapt and apply information to new scenarios and technologies.
  • Business Wire will not sponsor a new applicant for employment authorization for this position.
    #LI-DNI

    What We Offer
    The base salary range for this position is $175K to $182K/year.  Offered salary will be determined by several factors, including but not limited to: applicant’s education, experience, knowledge, skills and abilities, as well as internal equity and alignment with geographic market data.  Business Wire reserves the right to modify this salary range at any time.

    Business Wire’s total rewards include:
  • Ability to work remotely
  • Excellent health benefits that begin on your first day of employment
  • $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
  • 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
  • PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!

A pre-employment background check will be required after the acceptance of an offer. Business Wire is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Business Wire will also consider for employment qualified applicants with arrest and conviction records.

Top Skills

Active Directory
Ccpa
Gdpr
Microsoft Entra
Nist Csf
Nist Rmf
Office 365
Pam
Pci-Dss
Rapid7
Soc 2
Sox

Similar Jobs

52 Minutes Ago
Remote or Hybrid
22 Locations
135K-215K
Senior level
135K-215K
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
As a Manager of Network Reliability Engineering, you will enhance network efficiency, develop monitoring tools, and lead network incident resolution while managing a sustaining engineering team.
Top Skills: AWSBgpEvpnGCPGoMplsPerlPythonVxlan
55K-139K Annually
Mid level
Machine Learning • Payments • Security • Software • Financial Services
The IT Observability and Support Specialist ensures system reliability through monitoring, incident management, and collaboration with IT teams to enhance observability and troubleshoot issues.
Top Skills: AnsibleAWSAzureBashDatadogDockerElastic StackGCPGrafanaKubernetesLinuxPowershellPrometheusPythonSplunkTerraformWindows
17 Hours Ago
Remote or Hybrid
IL, USA
80K-117K Annually
Mid level
80K-117K Annually
Mid level
Artificial Intelligence • eCommerce • Information Technology • Internet of Things • Automation
As a Identity Governance and Administration Engineer, you will implement and manage IAM and IGA solutions, collaborating across teams to enhance security and compliance processes.
Top Skills: Azure Active DirectoryEntra IdForgerockIamIgaOktaPeoplesoftSailpointWorkday

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account