GRC, Vulnerability Management Analyst
Acrisure
About Acrisure A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more. In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible. Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's Vulnerability Management Program from a risk, compliance, and accountability perspective. This role serves as the bridge between Cybersecurity, IT Operations, Infrastructure, Cloud, Application Development, and business stakeholders to ensure vulnerabilities are appropriately evaluated, assigned, remediated, accepted, or escalated according to established policies and risk tolerance. This position does not perform engineering work and instead, the analyst is responsible for vulnerability governance, risk reporting, metrics, exception management, policy adherence, and executive-level visibility into the organization's vulnerability posture. Success in this role means establishing strong accountability across the organization for vulnerability remediation while providing clear visibility into cyber risk, remediation performance, and program effectiveness. The analyst enables informed risk decisions, supports regulatory compliance, and helps reduce organizational exposure by ensuring vulnerabilities are managed in accordance with enterprise risk expectations and security governance standards. Responsibilities: Essential Duties and Responsibilities - Vulnerability Governance Govern the enterprise Vulnerability Management Program to ensure alignment with cybersecurity policies, standards, and risk management requirements. Track vulnerabilities through their lifecycle from identification through remediation, mitigation, risk acceptance, or closure. Monitor vulnerability remediation performance against established service level objectives and risk-based remediation timelines. Facilitate regular vulnerability review meetings with infrastructure, cloud, endpoint, application, and business stakeholders. Coordinate remediation activities by validating ownership, accountability, and risk prioritization across responsible teams. Risk Management and Exception Governance Review, document, and manage vulnerability exception requests, risk acceptances, and compensating control assessments. Evaluate business and technical justifications for remediation extensions and risk acceptance decisions. Ensure vulnerability risks are assessed and managed in accordance with enterprise risk tolerance and governance standards. Escalate overdue vulnerabilities, repeat offenders, and unresolved risk issues to appropriate leadership and governance forums. Partner with Enterprise Risk Management and Compliance teams to maintain consistent risk management practices. Reporting, Metrics, and Compliance Oversight Develop and maintain vulnerability management dashboards, scorecards, and executive reporting. Track and report key performance indicators including remediation SLA compliance, vulnerability aging, exception volumes, and closure rates. Analyze vulnerability trends, recurring findings, and remediation performance across business units and technology domains. Support internal audits, external audits, regulatory examinations, and compliance assessments involving vulnerability management practices. Provide risk-based reporting and recommendations to cybersecurity leadership, governance committees, and executive stakeholders. Program Governance and Continuous Improvement Establish and maintain vulnerability management standards, procedures, workflows, and governance documentation. Drive continuous improvement initiatives that enhance program maturity, accountability, and operational effectiveness. Identify recurring control gaps and process deficiencies contributing to vulnerability exposure. Partner with Security Operations, Security Engineering, Infrastructure, Application Development, and Cloud teams to improve remediation processes. Support the development of governance policies, reporting frameworks, and vulnerability management program roadmaps. Minimum Qualifications Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field. 3+ years of experience in cybersecurity governance, risk management, compliance, audit, or vulnerability management. Knowledge of vulnerability management concepts, remediation workflows, vulnerability prioritization, and risk-based decision making. Understanding of cybersecurity frameworks and standards including NIST, CIS Controls, ISO 27001, and COBIT. Experience developing executive reporting, metrics, dashboards, and performance indicators. Strong analytical, communication, and stakeholder management skills. Ability to coordinate activities across technical and non-technical teams. Preferred Qualifications 5+ years of experience supporting enterprise cybersecurity governance or vulnerability management programs. Experience with GRC platforms such as Archer, ServiceNow, MetricStream, or similar solutions. Familiarity with vulnerability management platforms including Tenable, Qualys, Rapid7, Wiz, or Microsoft Defender Vulnerability Management. Experience supporting regulatory compliance programs including SOX, HIPAA, NYDFS, PCI-DSS, SOC 2, or ISO certifications. Relevant certifications such as: CRISC CISA CISM CGRC Security+ Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.Why Join Us:At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.Employee BenefitsWe also offer our employees a comprehensive suite of benefits and perks, including:Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.… and so much more!This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting View email address on click.appcast.io candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.Welcome, your new opportunity awaits you.SummaryLocation: 1170 Peachtree St Ste 1200 - ATLANTA, GA; GRAND RAPIDS, MIType: Full time
$160k - $195k
...Vulnerability Management Data AnalystPrinceton NJ or Berwyn PA or Clifton, NJ or Austin, TX or Atlanta, GA or Sacramento, CA or Boston, MA or... ...Yr plus Bonus plus BenefitRole:Recruit an experienced data analyst within its Global Cybersecurity Vulnerability Management team...SuggestedFull timeWork at office- OverviewJob PurposeThe Senior Engineer, Information Security, GRC is part of a team responsible for the global Information... ...operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within....Suggested
$84k - $89k
...Ryan Consulting Group, Inc. is seeking a Vulnerability Management Analyst to support the Cybersecurity Center’s mission of identifying, assessing, and mitigating cybersecurity risks across DoD systems, assets, and agency capabilities. This role is responsible for conducting...SuggestedContract workTemporary workFor contractorsLocal area- Ryan Consulting Group, Inc. is seeking a Vulnerability Management Analyst to support the Cybersecurity Center in identifying, assessing, and mitigating cybersecurity risks across DoD systems, assets, and agency capabilities. Responsibilities include conducting vulnerability...Suggested
$69k - $101k
.... Job Purpose and Impact ~ The Application Developer- SAP/GRC Security job maintains, integrates and implements software applications... .... Key Accountabilities SAP SECURITY CONFIGURATION MANAGEMENT: Sets up and maintains SAP security configurations (roles,...SuggestedWork experience placement- ...Join CirrusLabs as a Cybersecurity & GRC Analyst CirrusLabs is on a mission to become the world's most sought-after niche digital... ...you will support initiatives such as: Cyber & IT Risk Management Archer / GRC Platform Work Risk Data & Analytics Compliance...
$105.4k - $207.8k
Position Summary Cyber SAP Security and GRC Access & Process Control Senior Consultant / Senior Engineering Management SpecialistJoin Deloitte’s Enterprise Security team and help clients strengthen SAP security across enterprise transformation, cloud modernization...Local areaVisa sponsorship- Black Fox LLC is seeking a motivated Cybersecurity Analyst to support cybersecurity risk assessments for public sector and commercial clients... ...cybersecurity assessments, governance, risk, and compliance (GRC) initiatives, and cybersecurity documentation reviews. The...Remote jobPart timeFlexible hours
$50 - $55 per hour
Position: (GRC) Cybersecurity Analyst Client: Georgia Tech Research Institute (GTRI) Employment Type: W2 Only Location: Atlanta, GA (Hybrid) Ideal Candidate Profile Experience 5-7+ years in IT/Cybersecurity Technical background (Engineering > GRC preferred) Experience...Hourly pay$50 - $55 per hour
Georgia Tech Research Institute (GTRI) is seeking a (GRC) Cybersecurity Analyst for a W2 full-time role in Atlanta, GA. The position offers hybrid work and compensation of $50.00 - $55.00 per hour with strong emphasis on governance, risk and compliance in security operations...Hourly payFull time- Georgia Tech Research Institute (GTRI) in Atlanta, GA, seeks a seasoned GRC Cybersecurity Analyst to lead governance, risk, and compliance activities, protecting sensitive information. You will assess policies and procedures, drive risk assessments across units, and design...
$89.2k - $138.6k
...Job Description The Third-Party Lifecycle Management Program (TLMP) team is a second line of... ...lifecycle with Visa. What a Third-Party Analyst – North America (NA) does at Visa: This is... ...regulations is preferred. Working experience with GRC tools and system maintenance and...Full timeContract workWork experience placementWork at officeLocal area- ...Description: Position Summary Runs and analyzes automated vulnerability scans across servers, workstations, web applications, and... ...validates, filters, and prioritizes results into actionable, management-ready findings. Key Responsibilities • Configure and run...Remote work
- ...and ensure quality and on-time outcomes for clients. The role requires experience with SOC 2 and HITRUST engagements, familiarity with GRC platforms, and strong English communication for client interactions. You will contribute to delivering exceptional client experiences...
- ...security posture of a major enterprise. If you enjoy finding vulnerabilities before adversaries do, proposing better ways to test,... ...development, infrastructure teams, app teams, and various levels of management.Assist with standards, procedures, playbooks, and testing...Permanent employmentFull timePart timeH1bWork visaShift workDay shift
$95.86k - $208.27k
...then consider a career in Advisory.KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice.Responsibilities:Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile...H1bLocal area- Acrisure is seeking a Cybersecurity Vulnerability Governance Analyst in Atlanta to lead the Vulnerability Management Program with risk-based governance, reporting, and executive visibility. This role interfaces with Cybersecurity, IT Operations, Cloud, and business stakeholders...
- Xtreme Solutions Inc is seeking a vulnerability management professional to run automated scans across servers, workstations, web applications, and general devices, validate results, and prioritize findings for leadership. The role emphasizes coordinating scan timing with...Remote job
$23k
...each other’s successes. Here’s to crafting careers and creating new legacies. Crafted Highlights:In the role of Sr. Revenue Management Analyst working in Atlanta, GA, you will be part of the East Region Sales Team. This person will assess the impact and effectiveness...Temporary workWork experience placementLocal areaFlexible hours- ...accountability, and collaboration, we equip our teams to work at the highest levels possible.Job Summary:Acrisure is seeking an IT Asset Management Analyst to join the Global IT Asset Management team in Grand Rapids, MI. Operating within the governance framework established by the...Full timeImmediate startFlexible hours
- ...exceptional returns to our investors, we are seeking a talented and driven Analyst/Associate to join our dynamic and fast-growing team. Job Summary: LDG is seeking a dedicated and analytical Asset Management Analyst/Associate to join our Atlanta-based team. This role will...Full time
- ...redefining credit with security at the core. The Security Risk Management team designs automated controls and workflows to protect Affirm... ...Python, Cursor, Claude, and other agentic coding tools to scale GRC work. You’ll partner with Procurement, Legal, and Engineering...Remote work
- ...Asset Management AnalystThe Asset Management Analyst position is designed to execute enhanced asset management processes that pertain to our fleet management and revenue monitoring activities. Primarily, this individual will provide support for the asset team through...Full timeTemporary workLocal area
$104.5k - $213.8k
..., can improve efficiency, insights, and client outcomes. In management at Crowe, you play a pivotal role in leading teams, guiding project... ...across domains such as governance, risk, and compliance (GRC) and business resiliency. Serve as an extension of client...Local areaWorldwide- ...where your contributions are valued, your growth is supported, and your work makes a lasting impactJob Summary:The Senior Risk Management Analyst is responsible for collecting, analyzing, validating, and presenting the Company's exposure, claims, and insurance data to...Full time
- ...Order Management AnalystAtlanta, GA (Onsite) 6 Months +Required Skills:Purchase order validation, order entry, and booking support.Experience Level:Excellent written and verbal communication skills3-4 years' industry experience in order processing, distribution, or invoicing...Work at office
- Job PostingThis position is located in the Department of Health and Human Services, Administration for Children and Families, headquartered in Washington, District of Columbia.This announcement will close at 11:59 PM, on the day that 150 applications have been received...
- ...Sr Revenue Management Analyst Cheers to creating an incredible tomorrow! At Molson Coors, we tackle big challenges and defy the status quo. With a proud legacy of excellence, an incredible portfolio of beer, seltzers, spirits, and non-alcohol brands, and a bold vision...Work at officeLocal areaFlexible hours
- Penetration Tester (Remote from LATAM) 100% Remote from Latin America We're looking for an experienced Penetration Tester. If you're into offensive security, love breaking into systems (legally!), and have hands-on experience with tools like Burp Suite, Metasploit...Remote work
- ...Asset Management Associate Affordable Equity Partners in Atlanta is looking for an Asset Management Associate to join our growing team... ...days a week. Position Summary The Asset Management Analyst plays a critical role in safeguarding the financial health and...Work at officeWork from home2 days per week3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC, Vulnerability Management Analyst. Be the first to apply!
- grc analyst Atlanta, GA
- ethical hacker Atlanta, GA
- vulnerability analyst Atlanta, GA
- penetration tester Atlanta, GA
- servicenow business analyst Atlanta, GA
- business analyst internship Atlanta, GA
- business information analyst Atlanta, GA
- junior IT service management analyst Atlanta, GA
- erp business analyst Atlanta, GA
- oracle business analyst Atlanta, GA


