Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior GRC Analyst

Louisiana Blue

Job Title

Leads the validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements.

Qualifications

Education:

  • Bachelor's in IT, Audit, and/or related fields required
  • Four years of related experience can be used in lieu of a Bachelor's degree.

Work Experience:

  • 4 years of relevant, specialized experience and highly developed proficiency within multiple disciplines including Governance, Risk, and Compliance required

Skills and Abilities:

  • This position does not have any direct reports but is expected to mentor and lead the operational activities of junior team members.
  • Requires excellent analytical, critical thinking, communication, marketing, and consulting skills.
  • Hands-on technical expertise in cybersecurity, IT infrastructure (networking, server management, etc.), cloud technologies, or application development is highly desirable.
  • Works under minimal supervision with latitude for independent judgment in a remote environment. Conducts tasks and assignments as directed or independently.
  • Requires experience in and working knowledge of at least 2 of the following disciplines:
    • Technology Risk Management
    • Governance Documentation Management (i.e. Policies, Processes, and Procedures)
    • Cybersecurity Awareness and Training
    • Management of IT/Security Controls & Ensuring Compliance with Legal and Regulatory Requirements
    • Auditing (Preferably IT Audit)
    • Technical Management of IT Infrastructure (e.g. networking, server administration, cloud technologies, etc.)
    • Cybersecurity Architecture, Incident, and Response

Licenses and Certifications:

  • Multiple Cybersecurity, IT or Security Governance, Information Systems Audit, Compliance, Risk Management, or computer networking trainings and certifications are preferred (e.g. CISA, CRISC, CGEIT, CISM, CISSP, CompTIA Sec+, CIA, CRMA, COSO/ERM, etc., or other relevant certifications from reputable organizations such as GIAC, ISC2, ISACA, or Comp TIA).
Accountabilities and Essential Functions
  • Collaborates and consults with a team of Cybersecurity and IT professionals to accomplish multiple of the following objectives as determined by management.
  • Governance:
    • Collaborates on the development and implementation of the annual strategic plan
    • Develops Board-level reporting
    • Maintains and ensures integration with the company's cybersecurity, control, and risk management frameworks
    • Manages and maintains a functional, accessible, and protected control library and facilitates reviews with control owners
    • Tracks pertinent laws and regulations and maps relationships between various legal, regulatory, and contractual requirements (HIPAA, SOC-2, SOC-1, AFRMR, etc.) and various security cybersecurity and control frameworks (NIST CSF, NIST 800-53, COBIT, etc.)
    • Leads in the design of security controls to ensure alignment with the organization's risk appetite and tolerance levels to support business objectives
    • Develops and maintains IT and Cybersecurity governance documentation assets including charters, policies, standards, processes, procedures, and artifacts
    • Ensures alignment of controls with all supporting governance documentation
    • Facilitates the identification of metrics and key performance indicators to enable the measurement of security controls performance in meeting business objectives
    • Trains and promotes awareness to the workforce on cybersecurity responsibilities and protections through phishing simulations, remote awareness events, computer-based trainings, and frequent communications
    • Develops, maintains, and reports on operational governance metrics
  • Risk Management:
    • Maintains risk alignment to the company's chosen cybersecurity framework
    • Assesses BCBSLA's technical environment for alignment to the chosen Cybersecurity Framework and develops remediation efforts to close gaps and mature the cybersecurity control environment.
    • Collaborates with Security Architecture, SIRT, and IT technical teams to identify and assess risk, perform security reviews, identify gaps in security architecture, and develop a security risk management plan
    • Assesses risk for their inherent, target, and residual likelihood of occurrence and impact to the organization
    • Develops comprehensive risk assessments for reporting to multiple audiences including business leaders, technical personnel, audit personnel, senior management, and the board of directors
    • Applies Cybersecurity architecture concepts in the design of controls to effectively mitigate risk
    • Recommends and coordinates security initiatives to mitigate risks to acceptable levels as defined by corporate appetite tolerances
    • Provides enterprise cybersecurity risk management guidance and education. Integrates risk management with appropriate organizational functions.
    • Participates in the acquisition process as necessary, following appropriate risk management practices
    • Verifies risk management documents, policies, and other governance products
    • Develops, maintains, and reports on operational risk management metrics
  • Compliance:
    • Develops and maintains continuous control monitoring schedules and oversees security control assessments to verify effectiveness and efficiency
    • Monitors controls to ensure controls remain within tolerances, function effectively and efficiently, and are appropriate
    • Provides documentation and training to ensure security controls are effectively performed
    • Serves as liaison to auditors, consultants, IT management, cybersecurity personnel, and other personnel as needed to ensure organizational compliance with applicable rules, laws, and regulations
    • Tracks and manages audit findings for the IT Division to ensure accurate reporting and timely resolution
    • Consults with control experts to provide documentation in support of internal and external audit activities
    • Develops, maintains, and reports on operational compliance metrics
  • General Governance, Risk, and Compliance (GRC) Support:
    • Leads process analysis, development, & improvement efforts
    • Assists in developing, testing, and delivering solutions, support, reporting, information, and relationship management to satisfy client requests
    • Acts as a liaison between clients and others inside or outside of BCBSLA to facilitate solutions, information sharing, and effective communication
    • Contributes to executive and Board-level reporting
    • Provides overall support to all Technology GRC team efforts and serves as a resource to other team members
    • Provides proactive and reactive subject matter expertise to all levels of the organization
    • Interviews process owners and review process design to gain understanding of business requirements

Additional Accountabilities and Essential Functions The Physical Demands described here are representative of those that must be met by an employee to successfully perform the Accountabilities and Essential Functions of the job. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential functions.

  • Perform other job-related duties as assigned, within your scope of responsibilities.
  • Job duties are performed in a normal and clean office environment with normal noise levels.
  • Work is predominately done while standing or sitting.
  • The ability to comprehend, document, calculate, visualize, and analyze are required.

An Equal Opportunity Employer

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior GRC Analyst in United States vacancy
  •  ...to its workforce, Kokosing is the winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on maintaining... 
    Senior
    Full time
    For contractors

    Kokosing

    Westerville, OH
    20 hours ago
  • $130k - $170k

     ...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks...  ...organization.WHOOP is seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing... 
    Senior
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    16 hours ago
  • $80.05k - $165k

     ...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory... 
    Senior
    Full time
    Work at office

    Columbia Bank

    Hillsboro, OR
    2 days ago
  • $138k - $173k

    THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers... 
    Senior
    Temporary work
    Work at office
    Local area
    Worldwide
    Shift work

    FanDuel

    Atlanta, GA
    4 days ago
  •  ...ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)About the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will... 
    Senior
    Full time
    Contract work
    Work experience placement
    H1b
    Remote work
    Visa sponsorship
    Relocation package
    Monday to Friday

    AlixPartners

    Detroit, MI
    2 days ago
  •  ...be a US Citizen or Green Card holder NO THIRD PARTIES Only local candidates will be contacted We are seeking a highly motivated GRC Analyst to support the modernization and transformation of our Governance, Risk, and Compliance (GRC) program. This role is ideal for someone... 
    Senior
    Contract work
    Local area

    Liberty Personnel Services, Inc.

    Wilmington, DE
    4 days ago
  •  ...Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC...  .... What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them... 
    Senior
    Permanent employment
    Full time
    Contract work
    Remote work

    Hotman Group LLC

    United States
    4 days ago
  •  ...Owning and advancing the governance, risk, and compliance program, the full-time Senior GRC Analyst will manage compliance frameworks, conduct risk assessments, and collaborate with cross-functional teams in a remote capacity. Key Responsibilities: Lead the GRC program... 
    Senior
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...Senior GRC Analyst Location: Remote About Compyl Compyl is a high-growth, venture-backed GRC and automated security compliance platform built by security practitioners for security practitioners. Founded in 2020 by two former CISO's, we replace the spreadsheets... 
    Senior
    Local area
    Remote work

    Compyl

    United States
    20 hours ago
  •  ..., friends, and families in providing best-in-class products and services!Job SummaryThe Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance obligations... 
    Senior
    For contractors

    Amerigas

    Denver, PA
    2 days ago
  •  ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    CRG

    Phoenix, AZ
    4 days ago
  • $114k - $163k

     ...Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh Onsite Compensation: $114,000 - $163,000 / year Description Role Summary Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and... 
    Senior
    Full time
    Contract work
    Temporary work

    Wolfe

    Pittsburgh, PA
    3 days ago
  •  ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time,... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    CLAYCO, INC.

    Saint Louis, MO
    4 days ago
  • Wiz is seeking a Remote Senior Governance, Risk, and Compliance Analyst - Governance to join our team. You will report to the Manager, Governance, Risk, & Compliance and collaborate with a cross-disciplinary Wizards group to align governance with business needs and enhance... 
    Senior
    Remote job

    Itlearn360

    New York, NY
    4 days ago
  • Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years... 
    Senior
    Flexible hours

    Crunchyroll

    Dallas, TX
    1 day ago
  • A leading cybersecurity firm is seeking an Experienced or Senior GRC Analyst to join their remote team. The successful candidate will lead audits, design compliance programs, and guide clients in cybersecurity strategies. Applicants should have 5+ years of relevant experience... 
    Senior
    Remote job
    Permanent employment

    Hotman Group

    Fort Worth, TX
    4 days ago
  • Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows... 
    Senior
    Remote job

    Ellenco Estágios e Treinamentos

    New York, NY
    2 days ago
  • Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM... 
    Senior

    Gilder Search Group

    Saint Louis, MO
    2 days ago
  • A staffing agency based in Dallas, Texas is seeking a Senior Security Analyst to identify and mitigate security risks within the IT environment....  ...Information Security or IT and at least 3 years of experience in GRC/risk management. Competitive compensation and benefits... 
    Senior

    Liberty Personnel Services, Inc.

    Dallas, TX
    2 days ago
  • Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management... 
    Senior

    Sky Mavis

    Saint Louis, MO
    4 days ago
  • The Trade Desk in New York, NY seeks a Technology Governance & Risk Senior Analyst to lead global governance, risk, and compliance initiatives across SOX, SOC, CCPA, and PADFAA. You will partner with engineering, legal, and business teams to assess risk, design and test... 
    Senior
    Worldwide

    The Trade Desk

    New York, NY
    2 days ago
  • Illumia is seeking an experienced Business Risk Analyst to support information security compliance, GRC workflow, and risk management initiatives. The role involves risk assessments, business continuity planning, and coordinating audits with external auditors and internal... 
    Senior
    Remote job

    Illumia

    Atlanta, GA
    1 day ago
  • Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant... 
    Senior

    Sky Mavis

    Phoenix, AZ
    4 days ago
  • Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8... 
    Senior

    Gilder Search Group

    Atlanta, GA
    2 days ago
  • Lennox is seeking a seasoned SAP GRC professional to bridge IT and business for a secure, compliant SAP environment. You will support governance, risk assessments, and control implementations across SAP modules including EWM and FI. The role requires deep SAP GRC experience... 
    Senior

    Socket

    Richardson, TX
    3 days ago
  • $110k - $140k

    Senior GRC Analyst - Accounting - $110,000 - $140,000 You get to build the GRC function from scratch at a nationally recognized, PE-backed company in a major growth phase. This is a greenfield opportunity. There is no inherited mess to untangle, no legacy processes holding... 
    Senior

    Saragossa

    Wisconsin
    1 day ago
  • Gilder Search Group is looking for a Sr. GRC Analyst to manage Third-Party & Human Risk while ensuring risks are identified and treated satisfactorily. The role requires 6-8 years in risk assessment, with a bachelor's degree and required certifications expected. You'll... 
    Senior
    Flexible hours

    Gilder Search Group

    Phoenix, AZ
    2 days ago
  •  ...reporting Manage the maintenance of our compliance policies, standards, and procedures Report on our compliance posture to senior leadership Scale our GRC function with AI and automation, building quick wins and scoping requirements for Engineering to fully automate the... 
    Senior

    Jobtailor

    New York, NY
    1 day ago
  • Bloomin' Brands is seeking an experienced information security leader to drive risk management, compliance and governance across the organization. You will develop policies, assess controls, and oversee risk management initiatives to protect data and systems. The role requires...
    Senior

    Bloomin Brands

    Tampa, FL
    4 days ago
  • Bloomin' Brands, Inc. is seeking a Sr. GRC Analyst in Tampa, FL to support governance, risk, and compliance efforts across the organization. The role combines onsite and remote work in a hybrid schedule at the Tampa Restaurant Support Center. You will develop policies,... 
    Senior
    Remote work

    Bloomin' Brands, Inc.

    Tampa, FL
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!