Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Security Analyst II

Essential Utilities Inc

Essential Utilities, Inc. delivers safe, clean, reliable services that improve quality of life for individuals, families, and entire communities.

Operating as the Aqua (water and wastewater services) and the Peoples and Delta (natural gas) brands, Essential serves approximately 5.5 million people across 10 states. We are committed to sustainable growth, operational excellence, a superior customer experience, and premier employer status - including a competitive and comprehensive benefits package as well as a commitment to career growth opportunities.

We are advocates for the communities we serve and are dedicated stewards of natural lands, protecting more than 7,600 acres of forests and other habitats throughout our footprint.

Our company is one of the most significant publicly traded water, wastewater service and natural gas providers in the U.S.

The primary responsibilities of the GRC Security Analyst II ( Governance & Risk) are to ensure the security and integrity of the organization's information systems, with a specific focus on risk & vulnerability management as well as security compliance. The Security Analyst will frequently engage with both technical teams and business process owners to analyze risk, communicate risk posture, and develop effective remediation strategies. Ready to take your career to the next level? Let's talk!

Essential Duties:
  • Manage execution of both enterprise-wide and focused risk, threat, and vulnerability assessments, including but not limited to Security Awareness, Vulnerability, Configuration, and Third-Party Assessments.
  • Analyze and prioritize risk, vulnerability, and compliance findings to define remediation priorities considering all available data sources; partnering with technology and business stakeholders to socialize and implement remediation plans.

    Define and manage qualitative and quantitative metrics and reporting to measure the success of vulnerability, third party, security awareness, security awareness, configuration, and asset management remediations.
  • Ability to lead ongoing vulnerability management processes, including working with IT and business stakeholders to prepare vulnerability remediation plans, track progress, and reduce overall vulnerability exposures.
  • Participate in development, implementation and operation of control/compliance frameworks and security best practices based on ISO 27001/27002, NIST (800-30, Cyber Security Framework/CSF), COBIT, Critical Security Controls, CIS Configuration Benchmarks.
  • Monitor compliance with security configuration standards for servers, endpoints, software, and networking platforms based on CIS Benchmarks.
  • Work closely with IT, development, and operations teams to ensure the integration of security practices into the software development lifecycle (SDLC) and IT operations.
  • Lead or assist with vendor and 3rd party risk assessments.
  • Create/maintain documentation of security solutions, services, configurations, and processes.
  • Work closely with engineers focused on intrusion detection, incident response and security operations to manage risk related to existing and emerging threats.
  • Collaborate with other security engineers to analyze, process, integrate, communicate, and respond to threat intelligence.
  • Ability to participate in or lead development, improvements and updates to continually improve security controls, policies, guidelines, processes and procedures.
  • Develop and deliver security awareness training programs for employees to enhance their understanding of security best practice to ensure that security and risk management continue to be integrated into the corporate culture.
  • Lead development and operation of the security awareness program to ensure that security and risk management continue to be integrated into the corporate culture.
  • Implement and maintain controls for compliance and privacy. Act as liaison to internal and external audit teams as needed.
  • Provide escalation support for the Information Technology Help Desk as required.
  • Ability to work off hours maintenance windows and participate in rotating on call shift periodically.
  • Ability to work alone or function effectively as part of a team.
  • All other duties as assigned by management.
MINIMUM QUALIFICATIONS:

Bachelors in Information Technology, Computer Science, Cyber Security, Security and Risk Analysis, Information Assurance.

3-5 years of previous Governance & Risk experience


Candidates must have a minimum of one of the following certifications or will be required to obtain within the first 12 months: CISSP, GIAC (GSEC, GSNA), CRISC, CISA, CISM, CCSP, SSCP, CAP, CSSLP, CSX Practitioner

KNOWLEDGE, SKILLS, AND ABILITIES:
  • Experience working with assessment tools such as Qualys Policy Compliance and CIS-CAT.
  • Experience developing and using Qualys, or other vulnerability management, platforms with experience in multiple modules and/or areas: Vulnerability Management, Policy Compliance, Continuous Monitoring, Policy Compliance, Web Application Scanning and Asset Management.
  • Experience leading security awareness program development including:
    • Leading regular phishing assessment campaigns.
    • Creating innovative security awareness campaigns using solution provider and custom-developed tools/trainings designed to be flexible and adaptable across a diverse employee population (executives, engineering, marketing and communications, finance, customer service, etc.).
    • Participate in aligning the security awareness program with the enterprise's greatest risks and measure the impact in risk reduction from security awareness efforts.
  • GRC platform experience, with RSA Archer knowledge a strong positive.
  • Strong written and verbal communication skills are required as this position will be responsible for working directly with technical teams and business stakeholders.
  • Demonstrates strong organizational skills and the ability to multi-task, prioritize workload and delegate responsibilities.
  • Strong analytical skills for assessing and prioritizing security risks.
  • Ability to promote a security-conscious culture within the organization.
  • Ability to adapt to evolving threats, technologies, and organizational needs.
  • Ability to understand and integrate security into project and application lifecycles for enterprise IT systems.
  • Minimum of 3 to 5 years experience in Information Technology focusing on information security auditing, risk analysis and vulnerability management.
  • General knowledge of the following technologies from a security perspective: Active Directory, database platforms, web server platforms, Middleware, PKI, cloud computing, Office 365 and Azure.
  • Experience using statistical, quantitative, and qualitative analysis techniques.
  • Proactive approach to staying informed on the latest security threats, vulnerabilities, and industry best practices.
Essential Utilities, Inc., is an Equal Opportunity/Affirmative Action employer. Equal employment opportunity is provided to all employees and applicants for employment without regard to the following legally protected characteristics: race, color, religion, sex, national origin, age, pregnancy (including childbirth and related medical conditions, including medical conditions related to lactation), physical or mental disability, covered-veteran status, genetic information (including testing and characteristics), sexual orientation, gender identity or expression or any other characteristic protected by applicable local, state or federal law.
Essential Utilities is committed to providing reasonable accommodation to individuals with disabilities. If you have a condition that may prevent you from applying for a job online or need to request an accommodation during the interview process, please call View phone number on click.appcast.io).
To maintain the integrity of the recruitment process and to avoid real or perceived conflicts of interest due to employment and/or assignment of family members and personal referrals, specific guidelines apply to the hiring and assignment of these individuals including, but not limited to:
  • Family members cannot result in a supervisor/subordinate reporting relationship
  • Family members cannot work in the same department.
Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the GRC Security Analyst II in Bryn Mawr, PA vacancy
  •  ...IT Security Analyst Come and Save Lives with Us! SERB is a fast-growing specialty pharmaceutical company that equips healthcare providers worldwide with life-saving medicines for patients facing rare conditions and emergencies. For over 30 years we have consistently... 
    Suggested
    For contractors
    Work at office
    Immediate start
    Work from home
    Worldwide
    3 days per week

    SERB Pharmaceuticals

    Conshohocken, PA
    2 days ago
  •  ...other scanning tools. Web application scanning and web application firewalls. Containers. CIS benchmarks, STIGs, or other security hardening standards. Additional Desirable Skills Or Experience SAML, Kerberos, OAuth, OIDC, LDAP. Powershell and... 
    Suggested

    The Dignify Solutions, LLC

    Conshohocken, PA
    16 hours ago
  •  ...Job Title: Financial Analyst II Location: Chesterbrook PA (Web Cam Interview) Duration: Long Term (W2) H1 Transfer/ GC/ Citizen Job Description: Client Support: Ensure every call is answered professionally and promptly and that the highest... 
    Suggested
    Work at office

    Hudson Data

    Wayne, PA
    2 days ago
  • $76.4k - $138.6k

     ...systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950...  ...value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role... 
    Suggested
    Summer holiday
    Local area
    Flexible hours

    EY

    Philadelphia, PA
    5 days ago
  •  ...The Adversarial AI Offensive Security Analyst, Senior Specialst is a senior individual contributor role on the Offensive Security & Fraud Testing (OSFT) team. The mission of this role is to harness AI and automation as force multipliers for red teaming and penetration... 
    Suggested

    Vanguard Group, Inc.

    Malvern, PA
    9 hours ago
  •  ...voice, data, and managed network solutions, supporting customers across markets and geographies. We are excited to be adding a Security Analyst to our growing Information Technology team. In this role, you will support BCM One's security operations by monitoring and... 
    Work at office
    Relocation
    2 days per week
    1 day per week

    BCM One

    Blue Bell, PA
    2 days ago
  •  ...Adversarial AI Offensive Security Analyst Apply ( locations Malvern, PA Charlotte, NC Dallas/Ft. Worth, TX time type Full time posted on Posted Today time left to apply End Date: June 22, 2026 (13 days left to apply) job requisition id... 
    Full time
    Work experience placement

    Vanguard

    Malvern, PA
    2 days ago
  •  ...Join Our Team as an IT Security Analyst I! Are you a proactive and detail-oriented individual with a passion for cybersecurity? Do you thrive on protecting digital assets and ensuring compliance? We're looking for an IT Security Analyst I to join our dedicated team... 

    CMI Media Group

    Philadelphia, PA
    1 day ago
  •  ...Security Analyst (CIP) TYPE: Contract LOCATION: King of Prussia, PA ONSITE/REMOTE/HYBRID: Hybrid, expected on-site Thursdays START DATE: July 2026 We are seeking a Security Analyst to support Critical Infrastructure Protection (CIP) compliance efforts and ensure... 
    Contract work
    Remote work

    RX2 Solutions

    King of Prussia, PA
    2 days ago
  • $76.7k - $85.7k

    A leading insurance provider is looking for a Reporting Analyst II to join their team Nationwide. The role involves responding to regulatory requests, submitting data calls, and ensuring the accuracy of statistical reporting. Candidates should have strong SQL and Excel... 

    First Insurance Company Of Hawaii

    Bala Cynwyd, PA
    1 day ago
  •  ...Actuarial Analyst II Bring your drive for excellence, team orientation and customer commitment to Independence; help us renew and reimagine our business and shape the future of health care. Our organization is looking to diversify, grow, innovate and serve, and we... 
    Work experience placement
    Interim role

    Independence Blue Cross

    Philadelphia, PA
    2 days ago
  •  ...Security Administration Analyst Location: Philadelphia Start: ASAP Interview Process: Video & Onsite Length 6+ Months to Start Open To Conversion Yes The Security Administration Analyst is a key contributor in the Information Security Division. This individual will... 
    Local area
    Immediate start

    Marchon Partners

    Philadelphia, PA
    4 days ago
  •  ...We are looking for a Data Security Analyst to join our Information Security Architecture team in Philadelphia, PA or Overland Park, KS (Hybrid). This is an exciting opportunity to work on cutting-edge data protection and security initiatives leveraging Microsoft Purview... 
    Full time
    Work experience placement
    Work at office
    2 days per week

    Clarivate Analytics US LLC

    Philadelphia, PA
    5 days ago
  •  ...Job Description: About the Role: The Network Security Engineer will design, implement, and manage secure network infrastructure to ensure uninterrupted business operations. Responsibilities: Configure and maintain firewalls, VPNs, and IDS/IPS systems... 

    Vurke

    Philadelphia, PA
    2 days ago
  • $21.36 per hour

    Patrol Officer II Position Title: Patrol Officer II Posting Number: 20260088S Position Type: Staff Location: Villanova, PA Recruitment...  ...oriented techniques and tactics. Assists in providing a safe and secure environment for University community members to work, live, and... 
    16 hours
    Full time
    Flexible hours
    Shift work

    VILLANOVA UNIVERSITY

    Villanova, PA
    4 days ago
  •  ...Compliance Information Security Engineer In today's constantly evolving digital landscape, security is a shared responsibility. At...  ...security and compliance. The Compliance Information Security Analyst will play a meaningful role in attaining and maintaining compliance... 
    Local area
    Worldwide

    Webex Events (formerly Socio)

    Philadelphia, PA
    2 days ago
  • $92k - $114k

     ...Information Security Data Protection Manager Aegon's Global Technology Services - Security (GTS-security) delivers certain information security programs across all Aegon business units. Specifically GTS-security establishes and maintains the information security policy... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area
    Remote work
    Work visa
    Relocation package
    3 days per week

    Transamerica

    Philadelphia, PA
    4 days ago
  • $85k - $100k

     ...The IT Security Analyst is responsible for global cybersecurity operations, risk management, and compliance, ensuring the protection and integrity of enterprise systems and data. Key Responsibilities - Lead and manage global IT cybersecurity strategy and operations... 
    Permanent employment

    Nigel Frank International

    Conshohocken, PA
    5 hours ago
  • A prominent university is seeking a Patrol Officer II to maintain safety and enforce regulations on campus. The role includes responding to emergencies, conducting patrols, and preparing incident reports. Ideal candidates will have a high school diploma and at least one... 
    Full time

    VILLANOVA UNIVERSITY

    Villanova, PA
    4 days ago
  • $95k - $110k

     ...the return on the city’s technology investments; ensuring data security continuity; planning for continuing operations in the event of...  ...department, board, commission and agency. The Network Security Analyst is an integral position within the Network operations group.... 
    Full time
    Part time
    Work experience placement
    Work at office
    Relocation

    City of Philadelphia

    Philadelphia, PA
    24 days ago
  • 1 . Summary of Position: The Financial Analyst II - Plant Operations, Cost Accounting role is responsible for supporting cost accounting, operational financial analysis, budgeting, forecasting, month-end close, inventory reporting, and plant performance management... 
    Work at office

    Leonardo Helicopters

    Philadelphia, PA
    4 days ago
  • $19.24 - $31.04 per hour

     ...Bill Review Analyst II The Bill Review Analyst is responsible for reviewing, auditing and data-entry of medical bills for multiple states and lines of business. This is a Hybrid Role. ESSENTIAL FUNCTIONS & RESPONSIBILITIES: Responsible for auditing medical bills... 
    Hourly pay
    Minimum wage
    Full time
    Work at office
    Local area
    Flexible hours

    CorVel

    Norristown, PA
    2 days ago
  • Actuarial Professional Bring your drive for excellence, teamwork, and customer commitment to Independence. Join us as we renew and reimagine the future of health care. Together, we will achieve our mission to enhance the health and well-being of the people and communities...
    Work at office
    Remote work
    Monday to Friday
    2 days per week
    3 days per week

    Independence Blue Cross

    Philadelphia, PA
    2 days ago
  • $110k - $130k

     ...The Investment Analyst supports the execution and processing of investment activity across the family office and nuclear decommissioning...  ...with both liquid and illiquid investment vehicles - public securities, private equity, private credit, hedge funds, and alternatives... 
    Work at office
    Immediate start
    Flexible hours

    Holtec International

    Camden, NJ
    16 hours ago
  • SEI is looking for a Business Analyst to join its Investment Manager Services Division in Oaks, Pennsylvania. This role involves serving as a liaison between different teams to assist with internal and external client solutions for alternative investment funds. Applicants... 

    SEI

    Oaks, PA
    2 days ago
  • $19.24 - $31.04 per hour

     ...Job Description Job Description The Bill Review Analyst is responsible for reviewing, auditing and data-entry of medical bills for...  ...Our ranges may be modified at any time. For leveled roles (I, II, III, Senior, Lead, etc.) new hires may be slotted into a different... 
    Hourly pay
    Minimum wage
    Full time
    Work at office
    Local area
    Flexible hours

    CorVel Healthcare Corporation

    Norristown, PA
    12 days ago
  •  ...The Security Analyst is responsible for the day-to-day execution of STARR's information security operations across a multi-concept restaurant...  ...post-Workday governance and the buildout of the Technology GRC pillar. Required Qualifications Two to four years of hands... 
    Full time

    STARR Restaurants

    Philadelphia, PA
    20 days ago
  •  ...Overview The Specialist, Information Assurance Compliance II (SIAC2) will support the Naval Surface Warfare Center Philadelphia...  ...operational sites may be required Clearance: Active Secret security clearance Job Responsibilities and/or Success Factors Risk... 
    Contract work
    For contractors

    Arlo Solutions

    Philadelphia, PA
    1 day ago
  • $90k - $100k

     ...Overview Information Assurance Compliance Specialist II Location: Philadelphia, PA Salary Range $90,000 to $100,000 per year...  ...system or site information and evaluate/document in eMASS the security posture of systems being assessed, authorized, and maintained... 
    Full time
    Flexible hours

    Na Oiwi Kane

    Philadelphia, PA
    1 day ago
  • $76.7k - $85.7k

     ...since 1962 and are nationally recognized as a member of Ward's Top 50 and rated A++ by A.M.Best. We are looking for a Reporting Analyst II to join our team, Nationwide! Summary Respond to regulatory and ad-hoc calls for statistics and support for statistics and support... 
    Work at office

    First Insurance Company Of Hawaii

    Bala Cynwyd, PA
    16 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Security Analyst II. Be the first to apply!