Principal GRC Analyst

Business Wire Logo

Business Wire

💵 $175k-$182k
📍Remote - United States

Summary

Join Business Wire, a global leader in press release distribution, as a Principal Governance, Risk, and Compliance (GRC) Analyst. You will identify, assess, and mitigate cybersecurity risks, focusing on automation and optimization of controls. This role involves evaluating security control effectiveness, ensuring compliance, and streamlining risk management. The ideal candidate possesses deep cybersecurity risk management and regulatory compliance knowledge, along with experience in Integrated Risk Management and Third-Party Risk Management (TPRM) tools. You will partner with various teams to mitigate risks and automate controls. Generate reports and dashboards for senior leadership, and collaborate on policy documentation.

Requirements

  • Bachelor’s degree in Information Security, Information Technology, Information Systems Management, Computer Science, Engineering, or related field(s)
  • 8+ years of experience using risk management and GRC platforms to automate control testing, conduct risk assessments, and track compliance
  • A strong understanding of cybersecurity controls, risk mitigation strategies, and their application for data protection and privacy compliance
  • Ability to analyze complex cybersecurity risks, identify control weaknesses, and recommend actionable mitigation strategies
  • Must possess solid working knowledge of/experience in: Identity and access management and governance concepts and technologies, such as Microsoft Entra, Active Directory, PAM, etc
  • Vulnerability management platforms such as Rapid7
  • IT asset management, Configuration Management Databases (CMDB), and network asset discovery tools
  • Control frameworks and objectives (e.g., NIST CSF, NIST RMF, PCI-DSS, SOX, SOC 2, GDPR, CCPA, etc.)
  • Operating systems, databases, and middleware components
  • Conducting compliance and risk assessments
  • Management of IT and security projects
  • Office 365 tools (Word, Excel, SharePoint, OneDrive, Teams, and PowerPoint)
  • Self-motivated and results-oriented, including the ability to prioritize conflicting assignments
  • Exceptional organizational skills to balance work and lead projects
  • Strong verbal and written skills
  • Ability to collaborate and build consensus and strong relationships with various internal and external stakeholders (business, development, security, auditors, legal, etc.)
  • Ability to adapt and apply information to new scenarios and technologies

Responsibilities

  • Automate and manage cybersecurity controls across the organization, ensuring they are appropriately implemented and effectively mitigate risks
  • Evaluate, implement, and administer ITRM and TPRM tool(s)
  • Coordinate and participate in managing the risk register and risk mitigation efforts, including managing the risk exception process
  • Conduct internal cybersecurity and third-party risk assessments
  • Develop and maintain an inventory of cybersecurity controls mapped to industry standards (e.g., NIST, ISO 27001, CIS, SOC 2) and regulatory requirements (e.g., GDPR, CCPA, PCI-DSS, and SOX)
  • Develop assessment questionnaires and conduct compliance assessments to identify gaps in existing controls and recommend mitigation strategies, leveraging automation and assessment tools
  • Collaborate with key stakeholders (IT, InfoSec, Compliance, and Legal) to ensure that risks are understood, assessed, and appropriately addressed
  • Generate risk and control assessment reports and dashboards for senior leadership, identifying key risks, mitigation progress, and controls effectiveness metrics
  • Collaborate to document and maintain up-to-date policies and procedures related to cybersecurity risk management and control automation

Preferred Qualifications

Security and compliance certifications, such as CISSP, CISA, CISM, CGEIT, or CRISC, are preferred. Candidates with CISSP will be given preference

Benefits

  • Ability to work remotely
  • Excellent health benefits that begin on your first day of employment
  • $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
  • 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
  • PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs