Senior Cybersecurity GRC Analyst
Core
Lead governance, risk management, and compliance (GRC) initiatives to ensure adherence to regulatory mandates and industry standards while managing security investigations and audits.
Role type
Senior GRC Analyst
Builds
Security policies, compliance frameworks, risk registers, and audit reports
Domain
Cybersecurity, Regulatory Compliance, Information Security
Deliverable
dashboards & analysis
Required skills
Regulatory frameworks (NIST CSF, ISO 27001, ISO 42001, DORA, SOC 2, CIS Controls), Privacy regulations (GDPR, CCPA), Risk management, Policy writing, Audit management, Security investigations, Data analysis, DLP concepts
Preferred skills
AI/ML risk assessment, AI governance
Technologies
GRC tools, Automation platforms, AI capabilities
Responsibilities
Lead development and enforcement of security policies and processes; Oversee implementation and administration of GRC tools; Lead internal audits and drive remediation; Coordinate responses to customer security questionnaires; Manage complex security investigations; Develop data workflows and metrics for GRC status; Handle personal data requests and privacy compliance; Manage security risk processes including risk registers and treatment plans; Support implementation of DLP controls; Assess and manage AI/ML related risks.
Seniority
Senior, hands-on IC
