- Company Name
- The Intersect Group
- Job Title
- Senior GRC InfoSec Analyst
- Job Description
-
Job title: Senior GRC InfoSec Analyst
Role Summary: Lead the design, deployment, and governance of cybersecurity policies, standards, and controls across the organization to ensure compliance with regulatory frameworks and risk management objectives.
Expactations: Deliver comprehensive policy development and continuous improvement, maintain regulatory alignment, conduct risk assessments, support audits, and translate complex requirements into actionable guidance for cross‑functional teams.
Key Responsibilities:
- Develop, implement, and maintain enterprise cybersecurity and IT policies, standards, and guidelines.
- Keep policies current with laws, regulations, and industry standards (NIST, FFIEC, GLBA, NYDFS, SOX, PCI‑DSS).
- Conduct gap analyses, risk assessments, and control effectiveness reviews.
- Translate regulatory and technical concepts into clear, business‑friendly documentation.
- Lead and participate in internal and external audits, tracking findings to resolution.
- Manage policy governance lifecycle, including updates, approvals, and distribution.
- Monitor KPIs, generate dashboards, and recommend improvements based on audit/incident data.
- Collaborate with IT, legal, compliance, and business units to align security policies with objectives.
- Stay current on cybersecurity trends, threats, and best practices; advise on mitigation strategies.
Required Skills:
- Expertise in GRC tools (Archer, ServiceNow, OneTrust).
- Data analysis and reporting with Excel, Power BI, or equivalent.
- Strong knowledge of regulatory frameworks and cybersecurity standards.
- Ability to produce clear documentation and conduct stakeholder training.
- Project leadership and cross‑functional collaboration.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field.
- 6+ years in Cybersecurity GRC, policy development, risk management, or similar role.
- Certifications such as CISM and/or CISA highly desirable.
Preferred:
- Financial services or banking background.
- ServiceNow IRM experience.