Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity GRC Analyst

$65k - $75k

University Of Maine System

The University of Maine System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join our Information Security team.

This position plays an important role in protecting the information, systems, and data that support Maine's public universities. The GRC Analyst will help advance the University of Maine System's cybersecurity governance framework, risk management processes, regulatory compliance efforts, and security awareness program.

Working across Information Technology, academic departments, administrative units, and with external partners, the Cybersecurity GRC Analyst will coordinate cybersecurity risk and compliance activities, support audit readiness, develop and maintain policies and controls, and help strengthen a culture of shared responsibility for cybersecurity throughout the University of Maine System.

This is an excellent opportunity for a cybersecurity professional who enjoys connecting technical security requirements with policy, risk management, compliance, communication, and organizational strategy.

This is a fully remote position, open to candidates who live and are authorized to work in the United States. Standard hours are Monday through Friday, 8:00 AM to 4:30 PM ET, with occasional evening or weekend work as needs arise.

What You'll Do:

  • Manage and support the institutional cybersecurity risk program, including maintaining the risk register, documenting risks, developing and tracking Plans of Action and Milestones (POA&Ms), and coordinating corrective actions with systems and data owners.
  • Manage the cybersecurity risk review process for new solutions, services, and technology acquisitions, including intake and triage of risk review requests, conducting or coordinating security risk assessments (including third-party and vendor reviews using the Higher Education Community Vendor Assessment Toolkit (HECVAT), Standard and Organization Controls (SOC) 2 reports, and similar assurance documentation), documenting findings and recommendations, and routing risk acceptance and approval decisions to the appropriate authority.
  • Map and maintain cybersecurity controls against applicable frameworks and regulatory requirements, including National Institute of Standards and Technology Special Publication (NIST SP 800-171), Center for Internet Security (CIS) Controls, Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS), Payment Card Industry (PCI), the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, and other relevant standards.
  • Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines.
  • Monitor compliance with cybersecurity policies and regulatory obligations and coordinate audit readiness activities, including evidence collection and documentation.
  • Serve as a liaison with internal and external auditors and regulatory entities.
  • Manage cybersecurity exception and risk acceptance processes, including documentation, approvals, and periodic reviews.
  • Facilitate periodic risk reviews with risk and system owners, including re-review of accepted risks and expiring exceptions, and escalate overdue items for decision.
  • Coordinate remediation of findings identified through audits, risk assessments, and compliance reviews.
  • Develop cybersecurity metrics, dashboards, and reports that support operational monitoring, executive decision-making, and governance.
  • Lead the development and administration of cybersecurity awareness and training initiatives, including phishing simulations, enterprise-wide campaigns, onboarding and annual education, and role-based training.
  • Support cybersecurity engagement and outreach efforts, including a cybersecurity champions network and other initiatives that promote shared responsibility for security.
  • Prepare reports, briefings, and presentations for executive leadership and governance bodies regarding cybersecurity risks, compliance posture, and program effectiveness.
  • Leverage artificial intelligence and automation to improve analysis, reporting, workflows, and cybersecurity program operations. 

What We Are Looking For: The successful candidate will bring knowledge of cybersecurity governance, risk management, and compliance principles along with the ability to translate complex security requirements into practical policies, processes, recommendations, and communications.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or an equivalent combination of education and experience.
  • Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support.
  • Experience with audit preparation and evidence documentation practices. 
  • Knowledge of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and applicable regulatory requirements.
  • Knowledge of cybersecurity risk assessment methodologies and security control frameworks.
  • Experience maintaining risk registers, POA&Ms, or corrective action tracking, and supporting risk acceptance or exception processes.
  • Ability to analyze cybersecurity risks and develop practical mitigation recommendations.
  • Ability to develop policies, procedures, and governance documentation.
  • Ability to develop reports, dashboards, and metrics for leadership and governance audiences. 
  • Strong written communication skills, including policy documentation and executive-level reporting.
  • Ability to collaborate effectively with both technical and nontechnical stakeholders.
  • Demonstrated use of AI-assisted tools or automation to improve security workflows, processes, or reporting.
  • Familiarity with the responsible use of artificial intelligence and automation in professional environments, including appropriate data protection considerations.

Preferred Qualifications

  • Relevant governance, risk, compliance, audit, or privacy certifications, such as:
    • CISA - Certified Information Systems Auditor
    • CRISC - Certified Risk and Information Systems Control
    • CGRC - Certified in Governance, Risk, and Compliance
    • CISM - Certified Information Security Manager
    • CIPP - Certified Information Privacy Professional
    • CIPM - Certified Information Privacy Manager
  • Certification or professional development related to artificial intelligence, automation, or emerging technologies.
  • Experience working in higher education, the public sector, a multi-campus organization, or another complex enterprise IT environment.
  • Experience supporting cybersecurity governance, risk management, and compliance programs.
  • Experience with GRC platforms such as ServiceNow GRC, Isora GRC, OneTrust, or Archer, and familiarity with HECVAT for vendor security reviews.
  • Experience coordinating internal and external cybersecurity awareness and training programs.
  • Experience designing or implementing automation solutions that improve workflows, reporting, or operational efficiency.

What We Offer: Our comprehensive benefits package can be worth up to 50% of your annual salary and is designed to support your health, financial well-being, professional growth, and work-life balance. Benefits include:

  • Competitive salary: $65,000–$75,000 commensurate with education and experience. This is a fixed range set within a predefined wage band; therefore, we are unable to negotiate a starting salary above the posted range.
  • Comprehensive health benefits , including medical, dental, vision, flexible spending accounts (FSA), and Health Savings Account (HSA) options
  • Employer-paid benefits , including basic life insurance and long-term disability coverage, with additional voluntary coverage options available 
  • Retirement plan through TIAA with 10% employer contribution and opportunities for additional tax-deferred retirement savings 
  • Generous paid time off , including vacation and sick leave, plus 13 paid holidays each year 
  • Tuition waiver program for employees, including graduate courses and Maine Law, plus substantial tuition discounts for eligible spouses and dependent children 
  • Employee Assistance Program (EAP) and wellness programs supporting your health and well-being 
  • Professional development and opportunities to grow your career within Maine's public university system 
  • Additional voluntary benefits, including pet insurance, home and auto insurance discounts, and supplemental disability and life insurance options

Why Join the University of Maine System?

At the University of Maine System, technology plays a vital role in advancing education, research, and public service. As part of Information Security team, you'll have the opportunity to work on meaningful, system-wide initiatives that impact thousands of students, faculty, and staff across Maine.

Apply Today!

Materials must be submitted via “Apply Now” below. You will need to complete an application and upload the following: 

  • A cover letter that describes your experience, interests, and suitability for the position. 
  • A resume or curriculum vitae.

Important items to know about the recruitment process:

Review of applications will begin immediately. The position will remain open until filled. For full consideration, applications must be submitted by September 13, 2026.

  • Incomplete application materials cannot be considered.
  • Candidates selected to proceed to the final stages of the search process will be requested to provide three (3) names and contact information for references.
  • The successful applicant is subject to appropriate background screenings.

⚠️  Work authorization:  This position requires U.S. work authorization that does not require employer sponsorship now or in the future. We are unable to consider applicants who require visa sponsorship or OPT extensions at any point.

EEO Statement

The University of Maine System (the System) is an equal opportunity institution committed to fostering a nondiscriminatory environment and complying with all applicable nondiscrimination laws. Consistent with State and Federal law, the System does not discriminate on the basis of race, color, religion, sex, sexual orientation, transgender status, gender, gender identity or expression, ethnicity, national origin, citizenship status, familial status, ancestry, age, disability (physical or mental), genetic information, pregnancy, or veteran or military status in any aspect of its education, programs and activities, and employment. The System provides reasonable accommodations to qualified individuals with disabilities upon request. If you believe you have experienced discrimination or harassment, you are encouraged to contact the System Office of Equal Opportunity and Title IX Services at 5713 Chadbourne Hall, Room 412, Orono, ME 04469-5713, by calling View phone number on click.appcast.io, or via TTY at 711 (Maine Relay System). For more information about Title IX or to file a complaint, please contact the UMS Title IX Coordinator at 

About the University of Maine System

The University of Maine System (UMS), established in 1968, consists of seven universities and the University of Maine School of Law, spread across various locations in Maine. UMS provides system-wide services and governance from these locations, leveraging the distinct strengths and collaborations among its institutions to advance strategic priorities for UMS and the state of Maine.

Choosing UMS means opting for a high quality of life supported by excellent benefits such as tuition waivers, robust retirement contributions, and comprehensive insurance coverage including medical, dental, vision, life, and disability. Maine's diverse landscapes, from accessible wilderness and rugged coastline to urban centers and rural communities, offer numerous cultural activities, strong public schools, safe neighborhoods, and high-quality healthcare. Discover more about Maine's exemplary lifestyle on the Maine Office of Tourism website.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity GRC Analyst in United States vacancy
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  •  ...processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements. Serve as an Information Security...  .... Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows. Conduct evaluations... 
    Suggested
    Permanent employment
    Full time
    Work experience placement
    Remote work

    Request Technology

    Chicago, IL
    2 days ago
  • $15k - $120k

     ...Solutions helps build a diverse collection of print and digital resources to support every student. We are currently hiring for Cybersecurity GRC Analyst. This position is an exempt full-time position located in McHenry, IL or remote for the right person. The pay for this... 
    Suggested
    Full time
    Work experience placement
    Currently hiring
    Work at office
    Remote work
    Worldwide

    Socket.dev

    Mchenry, IL
    1 day ago
  • We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on experience with ISO 27001 , including audit support, policy development,... 
    Suggested

    duvari group

    Fenton, MO
    3 days ago
  • A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has... 
    Suggested

    UGI Utilities, Inc.

    New York, NY
    4 days ago
  •  ...Description: On-site in either King of Prussia, PA or Denver, PA   Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within a critical... 
    Hourly pay
    Permanent employment
    Full time
    Local area
    Remote work

    Eliassen Group

    King of Prussia, PA
    28 days ago
  •  ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory... 
    Full time
    Work experience placement
    Work at office

    Iccu

    Remote
    18 hours ago
  • %PDF-1.6%ÓôÌá1 0 obj /Rotate 0/StructParents 2/Tabs/S/Type/Page/Group endobj2 0 obj streamH‰ìW[—ÓÈ~÷¯èG;ÇÖè.yápÎ2L’IB€Å‡!'Gµm#Á² ~«U—nÉÏ,$yÚ—YêKÕWU_}uöÇuùU=|xöôüò‰ŠÔ£GŸœ«ÙÇYy¡Ê|/ U%žŸ«4_{y® éÙkUÍofg›¯µÙÍ|Ï÷ááZ¾·ÎÕÊW=¦©—ª,ñ½ W›³«ù‡EäÅjþv±Ôüþz¹š_›ÿ™š×Õ?ì»O‹˜-¾¨«¥*õ ­£E‹...

    Covington & Burling

    New York, NY
    1 day ago
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • Job OverviewThe GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through...  ...& Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development... 
    Full time

    Sub-Zero and Wolf

    Madison, WI
    18 hours ago
  • The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance...  ...s degree in Information Security, Cybersecurity, Risk Management, or equivalent... 
    Work experience placement
    Work at office
    Local area

    American Tower

    Boston, MA
    1 day ago
  •  ...environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.The Cybersecurity Governance & Risk Analyst is the second level of the classification hierarchy. Employees at this level solve problems, in single areas of... 
    Full time
    Work experience placement
    Remote work
    Visa sponsorship
    Relocation package

    Duke Energy

    Charlotte, NC
    4 days ago
  •  ...possible for over 150 years. Help us transform our workforce of the future, today.We are currently looking for a Cybersecurity Analyst - Governance Risk Compliance (GRC) to join Zions Bancorporation’s Enterprise Information Security team to drive our enterprise-wide... 
    Temporary work
    H1b
    Work at office
    Work from home
    Flexible hours
    3 days per week

    Zions Bancorporation

    Midvale, UT
    3 days ago
  • $110.18k - $183.63k

     ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia (US-VA), United States (US).Job Summary: The Cybersecurity and Risk Analyst is... 
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Arlington, VA
    2 days ago
  • $119k - $140k

     ...it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences.As a Cybersecurity Risk Analyst II, you'll help strengthen CLEAR's security posture by identifying, assessing, and reducing cyber risk across our products... 
    Casual work
    Work at office
    Flexible hours

    Secure Identity

    New York, NY
    5 days ago
  • $62k - $141k

    GRC AnalystThe Opportunity:Cyber threats evolve constantly. In this role, you’ll turn complex risk into clear action by supporting Risk Management Framework (RMF) activities and driving Assessment and Authorization (A&A) packages through an Authorization to Operate (ATO... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    1 day ago
  • $80.05k - $165k

    About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance...  ..., assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate... 
    Full time
    Work at office

    Columbia Bank

    Hillsboro, OR
    4 days ago
  • $134k - $202k

     ...our customers, growing our community, or shaping our story, you’ll help define what comes next.About the role:We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Vercel

    San Francisco, CA
    4 days ago
  • Position Title: Cybersecurity Risk & Compliance AnalystLocation: HOUSTON, TXFLSA Class: EXEMPTResponsible...  ...a Cybersecurity Risk & Compliance Analyst to help formalize and scale our risk...  ...brings a strong understanding of GRC principles, paired with the ability to translate... 
    Full time
    Local area

    VoltaGrid

    Houston, TX
    18 hours ago
  • $130k - $145k

     ...our journey toward becoming the world's top retail-focused trading platform in the world. What you'll do:We're looking for a mid-level GRC Engineer to help us scale our compliance program through automation and run audits across SOC 2, ISO 27001, and SOX. This is a hands-... 
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    NinjaTrader Group

    Chicago, IL
    1 day ago
  •  ...GorusuCompany: SRI Tech SolutionsTitle: GRC AnalystLocation: Portland,ORDuration: Full...  ...technically proficient Principal GRC Analyst to join our Information Security team, with...  ...of experience in GRC, IT audit, or cybersecurity operations who have supervised IT control... 
    Full time

    SRI Tech

    Portland, OR
    3 days ago
  • $130k - $160k

    Modern Technology Solutions, Inc. (MTSI) is searching for a Cybersecurity Systems Analyst in support of United States Space Force (USSF) Space Systems Command (SSC) and Combat Forces Command (CFC) Defensive Cyber Operations.A Cybersecurity Systems Analyst in this context... 
    Contract work
    Remote work

    Modern Technology Solutions

    Colorado Springs, CO
    18 hours ago
  • $130k - $170k

     ...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated...  ...-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    2 days ago
  • $138k - $173k

     ...seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting...  ...control environmentStay abreast of evolving technology & cybersecurity threats, trends, and regulatory changes to enhance control,... 
    Temporary work
    Work at office
    Local area
    Worldwide
    Shift work

    FanDuel

    Atlanta, GA
    1 day ago
  •  ...that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own the...  ...'s degree in Information Technology, Computer Science, Cybersecurity, or related field, or equivalent work experience.Technical... 
    Full time
    Work experience placement
    Work at office

    Nordstrom

    Seattle, WA
    3 days ago
  •  ...opportunities for growth and development, recognition for your work, and competitive pay and benefits.Job SummaryThe Lead Cybersecurity Threat and Vulnerability Analyst serves as the technical lead for Duke Energy's emerging AI Attack Surface Management capability. This role is... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Visa sponsorship

    Duke Energy

    Cincinnati, OH
    1 day ago
  •  ...validation testing of remediated vulnerabilities from business vulnerability assessments, as needed. Gain foundational knowledge in cybersecurity and apply that knowledge toward remediation initiatives. Build foundational skills in cybersecurity toolsets including... 
    Remote work

    Software Technology Inc

    Houston, TX
    4 days ago
  • $61.9k - $141k

    Cybersecurity Engineer and Risk AnalystThe Opportunity: Are you looking for an opportunity to advance your experience in cybersecurity and security engineering that will safeguard our nation? As a systems security and network security engineer, you can identify the tools... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    San Diego, CA
    18 hours ago
  •  ...duties as assigned. Qualifications • Minimum of a Bachelor’s degree is required. • A minimum of 6 years of experience in cybersecurity, engineering, or QA is required • Ability to create and deliver Product Security awareness campaigns and other communications... 
    Full time

    My3Tech Inc

    Milpitas, CA
    4 hours ago
  • $55 - $60 per hour

     ...Type: 1099, C2CIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: SaaS Engineer ( GRC Analyst with IAM )Location: Phoenix AZ onsite onlyDuration: ContractKey ResponsibilitiesPerform security assessments of SaaS and third‑party... 
    Hourly pay

    SRI Tech

    Phoenix, AZ
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity GRC Analyst. Be the first to apply!