Business Wire Logo

Business Wire

Senior GRC Analyst

Posted 3 Days Ago
Remote
Hiring Remotely in United States
155K-165K
Senior level
Remote
Hiring Remotely in United States
155K-165K
Senior level
The Senior GRC Analyst will manage cybersecurity governance, ensure compliance with frameworks, develop security policies, and assess security controls.
The summary above was generated by AI
Business Wire, a Berkshire Hathaway company, is the global market leader in press release distribution and regulatory disclosure. We are on a mission to redefine how organizations connect with their audiences - and that’s just the beginning!

Organizations, large and small, depend on us to accurately publicize market-moving news and multimedia, and generate social engagements that develop interactions with their target audiences.

About the Role
The Senior Governance, Risk, and Compliance (GRC) Analyst will handle cybersecurity governance tasks, including creating and maintaining policies, standards, and procedures (documents) for cybersecurity controls and processes. This role will evaluate the effectiveness of security controls, ensure compliance with relevant frameworks, and improve risk management practices. The ideal candidate will have a strong knowledge of cybersecurity risk management and regulatory compliance, along with practical experience in integrated risk management (including third-party risk), policy, and document management tools.    
 
The analyst will collaborate with the business, IT, and security teams to develop, review, and approve new and existing documents while assessing compliance to enhance adherence to the organization's mandated regulations, standards, and policies.   

What You'll Do

  • Review the current documents to identify and prioritize the requirements for revisions.
  • Create new security policies, standards, and responsibility models to clearly define the organization's security practices and responsibilities.
  • Assess, deploy, and manage the GRC tool to streamline the GRC processes.
  • Establish and oversee the policy and standards attestation process involving all stakeholders.
  • Establish and oversee the process for policy and standards exceptions.
  • Develop and oversee a Cybersecurity Awareness Training program.
  • Facilitate document development and revision through meetings and workshops with SMEs, and secure consensus from their leadership.
  • Develop questionnaires to evaluate the compliance of existing cybersecurity policies and standards and identify gaps in the organization’s Cybersecurity Risk Register.
  • Oversee the management of cybersecurity controls and framework implementation, along with continuous maintenance.
  • Develop and maintain an inventory of cybersecurity controls aligned with industry standards (e.g., NIST, SOC2, ISO 27001, CIS) and regulatory requirements (e.g., GDPR, CCPA, and SOX).

What You'll Need

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or a related field.  
  • 5+ years of experience in information technology or information security, including over 3 years of experience authoring security policies, standards, and procedures. 
  • A strong understanding of cybersecurity controls, risk mitigation strategies, and their application for data protection and privacy compliance. 
  • Security and compliance certifications, such as CISSP, CISA, CISM, CGEIT, or CRISC, are preferred.
  • Prior experience leading the evaluation, implementation, and administration of a GRC tool is highly preferred.

  • Technical Knowledge 
    The candidates MUST possess a solid working knowledge of: 
  • Identity and access management and governance concepts and technologies, such as Microsoft Entra, Active Directory, PAM, etc. 
  • Vulnerability management platforms such as Rapid7 and Wiz. 
  • IT asset management, Configuration Management Databases (CMDB), and network asset discovery tools.  
  • Control frameworks and objectives (e.g., NIST CSF, NIST RMF, PCI-DSS, SOX, SOC 2, GDPR, CCPA, etc.). 
  • Operating systems, databases, and middleware components. 
  • Performing compliance and risk assessments. 
  • Management of IT and security projects.  
  • Jira, Slack, and Office 365 tools (including Word, Excel, SharePoint, OneDrive, Teams, and PowerPoint). 

  • Work Environment Characteristics 
  • Self-motivated and results-oriented, with the ability to prioritize conflicting tasks. 
  • Exceptional organizational skills for balancing work and leading projects. 
  • Strong verbal and written communication skills.  
  • The candidate must build consensus, collaborate, and establish strong relationships with various internal and external stakeholders (business, development, security, auditors, legal, etc.). 
  • Ability to adapt and apply information to new situations and technologies.
  • Business Wire will not sponsor a new applicant for employment authorization for this position.
    #LI-DNI

    What We Offer
    The base salary range for this position is $155K to $165K/year.  Offered salary will be determined by several factors, including but not limited to: applicant’s education, experience, knowledge, skills and abilities, as well as internal equity and alignment with geographic market data.  Business Wire reserves the right to modify this salary range at any time.

    Business Wire’s total rewards include:
  • Ability to work remotely
  • Excellent health benefits that begin on your first day of employment
  • $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
  • 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
  • PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!

A pre-employment background check will be required after the acceptance of an offer. Business Wire is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Business Wire will also consider for employment qualified applicants with arrest and conviction records.

Top Skills

Active Directory
Ccpa
Cybersecurity
Gdpr
Grc Tools
Iso 27001
JIRA
Microsoft Entra
Nist
Office 365
Rapid7
Slack
Soc2
Sox
Wiz

Similar Jobs

4 Days Ago
Remote
United States
95K-135K Annually
Senior level
95K-135K Annually
Senior level
Healthtech • Other • Software
The Senior GRC Analyst develops GRC strategies, manages risks, oversees audits, and ensures compliance with regulatory standards, mentoring other analysts in the process.
Top Skills: Cloud-Based SolutionsGrc FrameworksHipaaIso 27001NistOwaspPci-Dss)Regulatory Compliance (GdprRisk ManagementWeb Technologies
23 Days Ago
Remote
United States
Senior level
Senior level
Software
The Senior GRC Analyst will lead compliance strategies, assist in FedRAMP certification, maintain SOC 2 compliance, and manage vendor security assessments.
Top Skills: AWSAzureCcpaCompliance Automation ToolsFedrampGCPGdprIso 27001Soc 2
25 Days Ago
Remote
USA
153K-180K Annually
Senior level
153K-180K Annually
Senior level
Security • Cybersecurity
Lead the SOx IT compliance program, coordinating audits, managing controls, documentation, and improving operational effectiveness while ensuring communication with stakeholders.
Top Skills: Cloud InfrastructureDrataIt General ControlsSaas ApplicationsServicenow

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account