Security GRC Analyst

Overview

The job opening is for a Security GRC Analyst with Protective, a company focused on providing valuable protection and peace of mind to its customers. As part of this organization, employees contribute to a mission that impacts millions of lives. This particular role ensures compliance with information security risk management protocols.

Job Description

Primary Responsibilities

The Security GRC Analyst will execute several important functions that contribute to the organization’s Information Security Risk Management program, particularly in areas such as regulatory compliance, third-party risk assessments, and security awareness. Key responsibilities include:

  • Performing and refining enterprise risk assessments using established frameworks like NIST CSF, NIST 800-53, SOC 2, and CIS. This involves documenting findings and developing mitigation strategies across systems and processes.

  • Analyzing vulnerability assessment reports and supporting troubleshooting and remediation initiatives to reduce risks.

  • Developing and executing security awareness programs with training sessions, phishing simulations, newsletters, and communications to influence behavioral changes.

  • Delivering insightful reports on program performance, including GRC metrics and executive summaries that detail risk posture and effectiveness.

  • Conducting thorough third-party risk assessments, including vendor onboarding and lifecycle management, with a focus on high-risk engagements.

  • Optimizing processes and tools related to Governance, Risk, and Compliance (GRC) platforms, which includes designing workflows for better operational consistency.

  • Supporting governance and control management by developing and maintaining policies that align with regulatory requirements.

  • Staying updated on evolving regulations and trends within the cybersecurity landscape.

Required Skills & Expertise

To excel in this role, candidates must possess a bachelor's degree in Cybersecurity, Information Systems, or a related field, along with a minimum of 1-3 years of experience in GRC or compliance within the realm of cybersecurity. Key competencies required include:

  • Working knowledge of regulatory frameworks, audit processes, and control environments.
  • Understanding of third-party risk management processes.
  • General knowledge of security tools and controls across various domains, coupled with foundational knowledge of cloud services (IaaS, SaaS, PaaS).
  • Proficiency in tracking and reporting on IS GRC program effectiveness using various tools including ServiceNow, Archer, and Power BI.
  • Ability to develop and deliver engaging training materials and communicate effectively with stakeholders.
  • Strong organizational, analytical, and multitasking capabilities to manage competing priorities efficiently.

Preferred qualifications include experience with cloud security compliance within platforms like Azure or AWS, as well as any relevant security certifications such as CISA, CISM, CISSP, or Security+.

Employee Benefits

Protective prioritizes the wellbeing of its employees and their families by offering a robust structure of employee benefits. These highlights include:

  • Comprehensive health, dental, and vision insurance.
  • Support for emotional wellbeing through mental health benefits and an employee assistance program.
  • Generous paid time-off options, including paid parental leave and short-term disability insurance.
  • Financial wellbeing benefits such as contributions to healthcare accounts, a pension plan, and a 401(k) plan with company matching arrangements.
  • ProHealth Rewards program allowing employees to improve their wellbeing while earning cash rewards.

Eligibility for specific benefits may vary according to the position in accordance with company policies.

Application Process and Accommodations

Potential applicants who require assistance due to a disability can contact Protective at the provided email address, which ensures privacy and focuses solely on the accommodation needs during the application process. All other employment inquiries should not be directed to this email address.

Equal Opportunity Employment

Protective values diversity and strives to cultivate an inclusive workforce by actively promoting equal opportunities for all candidates.

The Security GRC Analyst position at Protective represents a thrilling opportunity for those passionate about cybersecurity and compliance, particularly those looking to help secure systems and processes in a way that affects countless lives positively.



This job offer was originally published on himalayas.app

Protective

United States

Software testing

Full-time

July 26, 2026

0 views

0 clicks on Apply Now


Similar job offers


This job offer summary has been generated using automated technology. While we strive for accuracy, it may not always fully capture the nuances and details of the original job posting. We recommend reviewing the complete job listing before making any decisions or applications.