Cybersecurity GRC Analyst

Western National Insurance

Edina (MN)

Hybrid

USD 66,300 - 114,290

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
401(k) plan with matching
HSA / FSA
Wellbeing program
Paid time off
Tuition reimbursement

Job summary

Western National Insurance is seeking a Cybersecurity GRC Analyst to strengthen our information security program by supporting regulatory compliance, managing third-party security risk, and advancing security maturity.

You will lead security awareness initiatives and deliver metrics for informed business decisions while collaborating across legal, vendor management, and IT teams.

Qualifications

  • Experience in governance, risk, and compliance or security awareness roles.
  • Solid understanding of NIST CSF, CIS Controls, COBIT, and related standards.
  • Experience supporting regulatory audits and evidence collection.
  • Experience conducting vendor security risk assessments and remediation.
  • Strong grasp of governance, risk, and compliance concepts.
  • Excellent written and verbal communication; proficient with MS Office.

Responsibilities

  • Supports regulatory compliance by maintaining audit-ready documentation and coordinating filings.
  • Partners with vendor management, legal, and stakeholders to embed security requirements in vendor lifecycle.
  • Performs security risk assessments of third-party vendors and tracks remediation.
  • Maintains vendor risk register and monitors progress toward risk mitigation.
  • Acts as primary point of contact for state regulators, auditors, and compliance inquiries.
  • Designs and executes security awareness training; develops phishing and security campaigns.
  • Develops reports and dashboards on compliance, awareness, incidents, and program performance.
  • Supports internal audits and maturity assessments with evidence collection.

Skills

GRC experience
Regulatory frameworks (NIST CSF, CIS)
Audits & evidence collection
Vendor security risk assessments
Governance concepts
Communication skills
MS Office proficiency
Analytical thinking

Education

Bachelor's degree in business, communications, or related field

Tools

Drata
Vanta
OneTrust
Archer

Job description

Western National Insurance Group is a private mutual insurance company with over 120 years of experience serving customers' property-and-casualty insurance needs in the Midwestern, Northwestern, and Southwestern United States.

Job Type: Full-time

Job Summary

Western National is seeking a Cybersecurity GRC Analyst to strengthen the organization’s information security program by supporting regulatory compliance, managing third‑party security risk, advancing security framework maturity, leading security awareness initiatives, and delivering meaningful security metrics that enable informed business decisions.

Responsibilities
  • Supports insurance-related regulatory compliance by maintaining audit‑ready documentation and coordinating timely and accurate regulatory filings across multiple states.
  • Partners with vendor management, legal, and business stakeholders to integrate security requirements throughout the vendor lifecycle.
  • Performs security risk assessments of third‑party vendors and service providers and tracks remediation activities.
  • Maintains the vendor risk register and monitors progress toward risk mitigation objectives.
  • Serves as the Information Security Team's primary point of contact for state insurance departments, auditors, and compliance‑related inquiries.
  • Designs, coordinates, and executes the organization's security awareness training program.
  • Develops targeted awareness campaigns focused on phishing, social engineering, and secure behaviors across the organization.
  • Creates and distributes security awareness communications, including newsletters, alerts, and announcements.
  • Tracks training participation, measures program effectiveness, and recommends continuous improvements.
  • Maps existing security controls to recognized frameworks, such as NIST Cybersecurity Framework (CSF), CIS Controls, and NYDFS requirements.
  • Conducts security framework gap assessments and develops recommendations to improve organizational maturity.
  • Supports evidence collection for internal audits, regulatory reviews, and annual maturity assessments.
  • Defines, tracks, and reports key risk indicators (KRIs) and key performance indicators (KPIs) for the information security program.
  • Develops dashboards and reports that provide leadership visibility into security compliance, awareness, incident response, and program performance.
  • Assists information security leadership with executive reporting and board presentation materials.
  • Exercises sound judgment when identifying compliance gaps, prioritizing work, and escalating security risks.
  • Recommends process improvements that strengthen governance, documentation, compliance activities, and security awareness efforts.
  • Consistently acts according to our customer experience standards.
  • Performs special projects and other duties as assigned.
Qualifications
  • Two-plus years of experience in governance, risk, and compliance (GRC); compliance; cybersecurity; or security awareness roles.
  • Strong understanding of security and regulatory frameworks, such as NIST CSF, CIS Controls, COBIT, and similar standards.
  • Experience supporting regulatory audits, evidence collection, or third‑party compliance assessments.
  • Experience conducting vendor security risk assessments and documenting remediation activities.
  • Strong understanding of governance, risk, and compliance concepts.
  • Excellent organizational, written, verbal, and interpersonal communication skills.
  • Proficient use of Microsoft Office applications, including Excel, PowerPoint, and Word.
  • Ability to analyze information, identify trends, and communicate recommendations effectively.
  • Bachelor's degree in communications, business, or a related field or equivalent relevant experience.
Preferred Qualifications
  • Experience using governance, risk, and compliance platforms, such as Drata, Vanta, OneTrust, or Archer.
  • Knowledge of state insurance regulations and compliance reporting requirements.
  • Experience developing or leading security awareness and phishing simulation programs.
  • Experience supporting vendor management or third‑party security review processes.
  • Experience developing executive dashboards and security performance reporting.
  • Professional certifications, such as CompTIA Security+, CISA, CRISC, or other governance, risk, and compliance-related credentials.
  • Experience within the insurance, financial services, or healthcare industry.
Compensation

The targeted hiring range for this role is $66,300 - $114,290 annually. Base pay may vary depending on the candidate’s knowledge, skills, credentials, and experience.

Benefits
  • Medical insurance plan options and other standard employee benefits, including dental insurance, vision benefits, life insurance, disability insurance, and more
  • Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA)
  • 401(k) Plan (participants are eligible for 100% matching on the first 6% of their contributions)
  • Wellbeing Program, including onsite fitness studio
  • Paid Time Off – including holiday, vacation, and volunteer
  • 100% company‑paid tuition reimbursement for approved job‑relevant coursework and access to The Institutes (Risk and insurance education)
  • Paid parental leave
  • Bonus opportunities
Additional Information

Western National believes in supporting balance between work and life by providing a flexible work environment, which includes a variety of hybrid and remote work arrangements designed to balance individual, job, department, and company needs.

Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

Western National provides employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Western National Mutual Insurance Co • Edina (MN)

Hybrid
USD 66,000 - 115,000
Medical insurance options
401(k) plan with matching contributions
100% company-paid tuition reimbursement
+2
Business Analyst Manager
Business Analyst Manager

Western National Insurance • Edina (MN)

On-site
USD 112,300 - 146,000
Medical and insurance benefits
401(k) plan with 100% matching
Paid Time Off
+2
Territory Sales Manager - Wisconsin
Territory Sales Manager - Wisconsin

Western National Insurance • Wisconsin

On-site
USD 88,400 - 130,400
Medical insurance plan options
HSA / FSA
401(k) with company match
+5
Remote Cyber GRC Analyst — Compliance & Awareness
Remote Cyber GRC Analyst — Compliance & Awareness

Western National Mutual Insurance Co • Edina (MN)

Hybrid
USD 66,000 - 115,000
Medical insurance options
401(k) plan with matching contributions
100% company-paid tuition reimbursement
+2
Manager, Premium Audit
Manager, Premium Audit

Western National Group & Umialik Insurance • Edina (MN)

Hybrid
USD 104,000 - 143,000
Bonus opportunities
401(k) Plan
Tuition reimbursement
+1
Business Analyst III
Business Analyst III

DoorDash • Honolulu (HI)

On-site
USD 100,000 - 123,000
Bonus opportunities
Health insurance
Senior Casualty Claims Representative
Senior Casualty Claims Representative

Western National Mutual Insurance Co • Edina (MN)

Hybrid
USD 66,000 - 92,000
Health Savings Accounts (HSA)
401(k) Plan with matching
Wellbeing Program
+4
Commercial Lines Support Specialist I
Commercial Lines Support Specialist I

Western National Insurance Group • Seattle (WA), Northern (KY)

Hybrid
USD 29,000 - 39,000
Bonus opportunities
Underwriting Data Support Specialist
Underwriting Data Support Specialist

Western National Mutual Insurance Co • Edina (MN)

Hybrid
USD 38,000 - 45,000
Medical insurance options
401(k) Plan with matching contributions
Paid Time Off
+2
Senior Commercial Lines Underwriter
Senior Commercial Lines Underwriter

Western National Mutual Insurance Co • Seattle (WA)

Hybrid
USD 91,000 - 115,000
Medical insurance options
401(k) Plan with matching contributions
Company-paid tuition reimbursement