$ cat jobs/security-grc-analyst-protective-aa6913d49337.json
Security GRC Analyst
The work we do has an impact on millions of lives, and you can be a part of it. We help protect our customers against life’s uncertainties. Regardless of where you work within the company, you’ll be helping provide protection and peace of mind when our customers need it most. The Security Risk Analyst supports the organization’s Information Security Risk Management program by executing many cyber risk functions such as regulatory compliance, 3rd Party, and security awareness activities under the direction of security leadership. This role focuses on ensuring adherence to regulatory requirements, industry standards, and internal policies through collaboration with compliance, legal, and technology teams. The analyst applies strong analytical skills, attention to detail, and effective communication to perform risk assessments, maintain security policies, and assist with compliance initiatives. They help track program performance, prepare reports for leadership, and contribute recommendations for improvement. Additionally, the analyst promotes a collaborative environment by sharing insights and supporting organizational security objectives. Key Responsibilities: Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, including documenting findings and driving mitigation strategies across systems, processes, and infrastructure. Demonstrated technical acumen in analyzing vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives. Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications to drive behavioral change and risk reduction. Deliver actionable reporting and insights, including assessment results, GRC metrics, dashboards, and executive-level presentations summarizing risk posture, control effectiveness, and program maturity. Perform end-to-end cyber third-party risk assessments, including vendor risk