Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity GRC Analyst

$65k - $75k

University of Maine

The University of Maine System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join our Information Security team. This position plays an important role in protecting the information, systems, and data that support Maine's public universities. The GRC Analyst will help advance the University of Maine System's cybersecurity governance framework, risk management processes, regulatory compliance efforts, and security awareness program. Working across Information Technology, academic departments, administrative units, and with external partners, the Cybersecurity GRC Analyst will coordinate cybersecurity risk and compliance activities, support audit readiness, develop and maintain policies and controls, and help strengthen a culture of shared responsibility for cybersecurity throughout the University of Maine System. This is an excellent opportunity for a cybersecurity professional who enjoys connecting technical security requirements with policy, risk management, compliance, communication, and organizational strategy. This is a fully remote position, open to candidates who live and are authorized to work in the United States. Standard hours are Monday through Friday, 8:00 AM to 4:30 PM ET, with occasional evening or weekend work as needs arise. What You'll Do: Manage and support the institutional cybersecurity risk program, including maintaining the risk register, documenting risks, developing and tracking Plans of Action and Milestones (POA&Ms), and coordinating corrective actions with systems and data owners. Manage the cybersecurity risk review process for new solutions, services, and technology acquisitions, including intake and triage of risk review requests, conducting or coordinating security risk assessments (including third-party and vendor reviews using the Higher Education Community Vendor Assessment Toolkit (HECVAT), Standard and Organization Controls (SOC) 2 reports, and similar assurance documentation), documenting findings and recommendations, and routing risk acceptance and approval decisions to the appropriate authority. Map and maintain cybersecurity controls against applicable frameworks and regulatory requirements, including National Institute of Standards and Technology Special Publication (NIST SP 800-171), Center for Internet Security (CIS) Controls, Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS), Payment Card Industry (PCI), the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, and other relevant standards. Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines. Monitor compliance with cybersecurity policies and regulatory obligations and coordinate audit readiness activities, including evidence collection and documentation. Serve as a liaison with internal and external auditors and regulatory entities. Manage cybersecurity exception and risk acceptance processes, including documentation, approvals, and periodic reviews. Facilitate periodic risk reviews with risk and system owners, including re-review of accepted risks and expiring exceptions, and escalate overdue items for decision. Coordinate remediation of findings identified through audits, risk assessments, and compliance reviews. Develop cybersecurity metrics, dashboards, and reports that support operational monitoring, executive decision-making, and governance. Lead the development and administration of cybersecurity awareness and training initiatives, including phishing simulations, enterprise-wide campaigns, onboarding and annual education, and role-based training. Support cybersecurity engagement and outreach efforts, including a cybersecurity champions network and other initiatives that promote shared responsibility for security. Prepare reports, briefings, and presentations for executive leadership and governance bodies regarding cybersecurity risks, compliance posture, and program effectiveness. Leverage artificial intelligence and automation to improve analysis, reporting, workflows, and cybersecurity program operations. What We Are Looking For: The successful candidate will bring knowledge of cybersecurity governance, risk management, and compliance principles along with the ability to translate complex security requirements into practical policies, processes, recommendations, and communications. Required Qualifications Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or an equivalent combination of education and experience. Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support. Experience with audit preparation and evidence documentation practices. Knowledge of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and applicable regulatory requirements. Knowledge of cybersecurity risk assessment methodologies and security control frameworks. Experience maintaining risk registers, POA&Ms, or corrective action tracking, and supporting risk acceptance or exception processes. Ability to analyze cybersecurity risks and develop practical mitigation recommendations. Ability to develop policies, procedures, and governance documentation. Ability to develop reports, dashboards, and metrics for leadership and governance audiences. Strong written communication skills, including policy documentation and executive-level reporting. Ability to collaborate effectively with both technical and nontechnical stakeholders. Demonstrated use of AI-assisted tools or automation to improve security workflows, processes, or reporting. Familiarity with the responsible use of artificial intelligence and automation in professional environments, including appropriate data protection considerations. Preferred Qualifications Relevant governance, risk, compliance, audit, or privacy certifications, such as: CISA - Certified Information Systems Auditor CRISC - Certified Risk and Information Systems Control CGRC - Certified in Governance, Risk, and Compliance CISM - Certified Information Security Manager CIPP - Certified Information Privacy Professional CIPM - Certified Information Privacy Manager Certification or professional development related to artificial intelligence, automation, or emerging technologies. Experience working in higher education, the public sector, a multi-campus organization, or another complex enterprise IT environment. Experience supporting cybersecurity governance, risk management, and compliance programs. Experience with GRC platforms such as ServiceNow GRC, Isora GRC, OneTrust, or Archer, and familiarity with HECVAT for vendor security reviews. Experience coordinating internal and external cybersecurity awareness and training programs. Experience designing or implementing automation solutions that improve workflows, reporting, or operational efficiency. What We Offer: Our comprehensive benefits package can be worth up to 50% of your annual salary and is designed to support your health, financial well-being, professional growth, and work-life balance. Benefits include: Competitive salary: $65,000–$75,000 commensurate with education and experience. This is a fixed range set within a predefined wage band; therefore, we are unable to negotiate a starting salary above the posted range. Comprehensive health benefits , including medical, dental, vision, flexible spending accounts (FSA), and Health Savings Account (HSA) options Employer-paid benefits , including basic life insurance and long-term disability coverage, with additional voluntary coverage options available Retirement plan through TIAA with 10% employer contribution and opportunities for additional tax-deferred retirement savings Generous paid time off , including vacation and sick leave, plus 13 paid holidays each year Tuition waiver program for employees, including graduate courses and Maine Law, plus substantial tuition discounts for eligible spouses and dependent children Employee Assistance Program (EAP) and wellness programs supporting your health and well-being Professional development and opportunities to grow your career within Maine's public university system Additional voluntary benefits, including pet insurance, home and auto insurance discounts, and supplemental disability and life insurance options Why Join the University of Maine System? At the University of Maine System, technology plays a vital role in advancing education, research, and public service. As part of Information Security team, you'll have the opportunity to work on meaningful, system-wide initiatives that impact thousands of students, faculty, and staff across Maine. Apply Today! Materials must be submitted via “Apply Now” below. You will need to complete an application and upload the following: A cover letter that describes your experience, interests, and suitability for the position. A resume or curriculum vitae. Important items to know about the recruitment process: Review of applications will begin immediately. The position will remain open until filled. For full consideration, applications must be submitted by September 13, 2026. Incomplete application materials cannot be considered. Candidates selected to proceed to the final stages of the search process will be requested to provide three (3) names and contact information for references. The successful applicant is subject to appropriate background screenings. ⚠️ Work authorization: This position requires U.S. work authorization that does not require employer sponsorship now or in the future. We are unable to consider applicants who require visa sponsorship or OPT extensions at any point. EEO Statement The University of Maine System (the System) is an equal opportunity institution committed to fostering a nondiscriminatory environment and complying with all applicable nondiscrimination laws. Consistent with State and Federal law, the System does not discriminate on the basis of race, color, religion, sex, sexual orientation, transgender status, gender, gender identity or expression, ethnicity, national origin, citizenship status, familial status, ancestry, age, disability (physical or mental), genetic information, pregnancy, or veteran or military status in any aspect of its education, programs and activities, and employment. The System provides reasonable accommodations to qualified individuals with disabilities upon request. If you believe you have experienced discrimination or harassment, you are encouraged to contact the System Office of Equal Opportunity and Title IX Services at 5713 Chadbourne Hall, Room 412, Orono, ME 04469-5713, by calling View phone number on click.appcast.io, or via TTY at 711 (Maine Relay System). For more information about Title IX or to file a complaint, please contact the UMS Title IX Coordinator at About the University of Maine System The University of Maine System (UMS), established in 1968, consists of seven universities and the University of Maine School of Law, spread across various locations in Maine. UMS provides system-wide services and governance from these locations, leveraging the distinct strengths and collaborations among its institutions to advance strategic priorities for UMS and the state of Maine. Choosing UMS means opting for a high quality of life supported by excellent benefits such as tuition waivers, robust retirement contributions, and comprehensive insurance coverage including medical, dental, vision, life, and disability. Maine's diverse landscapes, from accessible wilderness and rugged coastline to urban centers and rural communities, offer numerous cultural activities, strong public schools, safe neighborhoods, and high-quality healthcare. Discover more about Maine's exemplary lifestyle on the Maine Office of Tourism website. University Of Maine System

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity GRC Analyst in New York, NY vacancy
  • A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has... 
    Suggested

    UGI Utilities, Inc.

    New York, NY
    5 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    6 hours ago
  •  ...The contractor/cybersecurity analyst would have the following credentials, organizational capability, and/or experience: A bachelor...  ...assessment methodologies. Governance, Risk, and Compliance (GRC) and vendor risk management technical IT expertise in... 
    Suggested
    For contractors
    Remote work

    3B Staffing LLC

    New York, NY
    4 days ago
  • $80k - $90k

     ...Responsibilities Related Companies is seeking an experienced and motivated Cybersecurity/SOC Analyst I with at least three years of security operations center experience. The SOC Analyst I will be focused on Threat Monitoring, Detection, Response, Analysis, and Cyber... 
    Suggested
    Work experience placement
    Remote work
    Night shift
    Afternoon shift

    Related Company

    New York, NY
    2 days ago
  • $22.5 - $25 per hour

     ...Agency Cybersecurity Entry-Level Role Agency Cybersecurity is a fast growing venture backed startup that provides best-in-class cybersecurity...  ...If you make it through and stay, the trajectory is real. Analysts who put in 3+ years in this role routinely move into full... 
    Suggested
    Hourly pay
    Full time
    Work at office

    Agency.com

    New York, NY
    1 day ago
  • To support the enterprise's IT and Cyber risk management efforts, the full-time salaried Cybersecurity Risk Analyst will identify, assess, and mitigate cybersecurity risks associated with third-party vendors while working remotely. Key responsibilities Conduct information... 
    Full time
    Work at office
    Remote work

    Virtual Vocations Inc

    New York, NY
    2 days ago
  • Protective is seeking a Security Risk Analyst to strengthen our Information Security program in the United States. The role focuses on regulatory compliance, risk assessments, and vendor risk management while collaborating with legal, compliance, and technology teams. You... 

    Protective

    New York, NY
    3 days ago
  • Why Rogo At Rogo, we are building Wall Street's first true AI analyst. Our mission is to empower finance professionals at the world’s top...  ...finance, we invite you to join us. The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and compliance... 

    Rogo

    New York, NY
    1 day ago
  • $134k - $202k

     ...customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Visa Hunt

    New York, NY
    2 days ago
  • A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls, developing... 
    Remote job

    Hotman Group, LLC

    New York, NY
    5 days ago
  • Senior IT GRC Analyst The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance...  ...qualifications: Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered). 5+... 
    Work at office
    Remote work

    CMG Financial

    New York, NY
    3 days ago
  • Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence,...  ...security requirements. Assess and assist in the development of cybersecurity plans and procedures to ensure compliance with FAR and DFARS.... 
    Contract work
    Temporary work
    Work experience placement
    Immediate start

    Quantexa

    New York, NY
    1 day ago
  •  ...enhance the security posture of the organization, the full-time GRC Analyst will design, implement, and manage control and risk workflows...  ...qualifications Bachelor's degree in information security, cybersecurity, computer science, or a related field, or equivalent... 
    Full time

    Virtual Vocations Inc

    New York, NY
    2 days ago
  •  ...new information technology (IT) systems meet the organization's cybersecurity and risk requirements. QUALIFICATIONS Education Bachelor's in...  ...operational compliance metrics General Governance, Risk, and Compliance (GRC) Support • Leads process analysis, development, & improvement... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Relocation

    Blue Cross and Blue Shield of Louisiana

    New York, NY
    2 days ago
  • $70k - $88k

     ...comprehensive managed IT solutions, specializing in areas like cybersecurity, private cloud services, IT planning and strategy, and backup...  ...as well. Job Overview Coretelligent is seeking a diligent GRC Analyst to join our team. This role will serve as a key contributor to... 
    Remote work
    Flexible hours

    Coretelligent

    New York, NY
    2 days ago
  • $60k - $70k

     ...also help businesses identify and reduce cybersecurity and non-compliance risks. Their...  ...requirements. Role Overview The Security Analyst plays a critical role in assessing and protecting...  ...-tenant environment • Familiarity with GRC (Governance, Risk, and Compliance) tools... 
    Work at office
    Remote work

    Rhodian Group

    New York, NY
    3 days ago
  •  ...possible extension Job Responsibilities: Conduct comprehensive cybersecurity assessments to identify vulnerabilities and risks Develop and...  ...field Proven experience as a Cyber Consultant, Cybersecurity Analyst, or similar role Strong knowledge of cybersecurity principles,... 
    Contract work
    Remote work

    Dfwsolution

    New York, NY
    1 day ago
  •  ...people to meet tomorrow's challenges. At FedSync, our people matter—both our employees and our clients. Position Overview The Cybersecurity Analyst proactively monitors, detects, and responds to security threats across networks, systems, and cloud environments to ensure... 
    Immediate start
    Remote work

    FEDSYNC

    New York, NY
    2 days ago
  • $85k - $115k

     ...technical and non-technical stakeholders Requirements 3+ years in cybersecurity, SOC, or IR roles Hands‑on experience with EDR (CrowdStrike,...  ...Send your resume to ****@*****.*** with "Cybersecurity Analyst" in the subject line. #J-18808-Ljbffr InterDataLink, Inc.
    Flexible hours

    InterDataLink, Inc.

    New York, NY
    1 day ago
  • Claytoncountyga is looking for a Cybersecurity Operations Analyst to design and manage security solutions, summarize trends, and implement processes that protect its information assets. This role requires collaboration with various stakeholders to resolve security incidents... 

    Claytoncountyga

    New York, NY
    5 days ago
  • $72.8k - $130k

     ...technologies for reports of security incidents Perform analysis on cybersecurity alerts in both On-Premises or Cloud environments Strong...  ...Hold stakeholders accountable for remediation actions Mentor analysts, providing training and guidance through complex incidents Produce... 
    Minimum wage
    Full time
    Work experience placement
    Local area
    Remote work
    Shift work
    Night shift
    Weekend work

    UnitedHealthcare

    New York, NY
    3 days ago
  • $90k - $120k

    Join our cybersecurity team to protect our clients' digital assets. You will monitor security systems, investigate incidents, and implement security measures to safeguard against cyber threats. Hybrid / New York, NY Full-time 3+ years $90,000 - $120,000 Department... 
    Full time

    Techhorizontx

    New York, NY
    3 days ago
  • $75k - $100k

    The Incident Response Analyst is responsible for monitoring, investigating, and responding to security alerts and incidents across the...  ...and thrives in a collaborative, fast-paced environment. Cybersecurity Incident Response Analyst Role Type Full-time Requirements 2-4... 
    Full time

    MFI Technologies Incorporated

    New York, NY
    1 day ago
  • Job Description Job Description Protects computer systems and networks from cyber threats and security breaches.

    Team 653 INT

    New York, NY
    27 days ago
  • Working remotely in a full-time capacity, the CyberSecurity Analyst will provide proactive support to clients by monitoring and analyzing security alerts, administering security measures, and collaborating with key stakeholders to enhance overall security posture. Key responsibilities... 
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    2 days ago
  • $80k - $135k

     ...Never considered the insurance industry before? We think you should. We are seeking a highly accountable and experienced Senior Cybersecurity Analyst who will serve as a senior-level technical leader within the cybersecurity team. This role provides daily analysis and... 
    Temporary work
    Remote work

    MedPro Group

    New York, NY
    2 days ago
  • To enhance security operations, the full-time Senior Cybersecurity Analyst will be responsible for advanced threat detection, incident response, and security consultation while working remotely. Key Responsibilities Lead incident response efforts for high-severity security... 
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    2 days ago
  • Working remotely, the full-time Cybersecurity Assurance Analyst will coordinate and execute compliance audit controls, monitor audit activities, and manage vendor relationships to ensure adherence to information security policies and industry standards. Key responsibilities... 
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    2 days ago
  • $67.5k - $115k

     ...choose to take.  Find out more about life at Alter Domus at careers.alterdomus.com   JOB DESCRIPTION: We are seeking cybersecurity expertise to provide operational support to the CISO, coordinating critical initiatives, strategic planning, and cross-... 
    Local area
    Flexible hours

    Alter Domus

    New York, NY
    6 hours ago
  •  ...Role Description At American Express, we empower future technologists to learn, innovate, and make an impact from day one. As a Cybersecurity Intern in Enterprise Technology Services, you’ll join a 10-week Summer Internship Program and contribute to work that helps... 
    Full time
    Internship
    Summer internship

    American Express

    New York, NY
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity GRC Analyst. Be the first to apply!