Enable job alerts via email!

Governance and Compliance Analyst

Elsevier

Atlanta (GA)

On-site

USD 80,000 - 100,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a GRC Analyst to enhance their cybersecurity governance program. In this pivotal role, you will lead the design and implementation of a comprehensive governance framework, ensuring compliance with critical cybersecurity standards. Collaborating with cross-functional teams, you will drive security initiatives, manage compliance frameworks, and serve as a trusted advisor to stakeholders. This is an exciting opportunity to make a significant impact in a dynamic environment where your expertise will shape the future of cybersecurity governance.

Qualifications

  • Experience in designing and implementing cybersecurity governance frameworks.
  • Strong background in compliance with laws and regulations.

Responsibilities

  • Design and maintain a cybersecurity governance framework aligned with best practices.
  • Monitor compliance and prepare for audits and assessments.

Skills

Cybersecurity Governance
Risk Management
Compliance Standards
Problem-Solving
Communication Skills

Tools

ISO 27001
NIST
COBIT
FedRamp
HIPAA
PCI

Job description

Are you looking to utilize your compliance and governance expertise as a critical member of our GRC team?

About the role: We are seeking an experienced Governance, Risk, and Compliance (GRC) Analyst to lead the development and implementation of our cybersecurity governance program and maintain compliance with our information security standards and frameworks. The successful candidate will have a deep understanding of cybersecurity frameworks, risk management, and compliance standards, and will work collaboratively with cross-functional teams to ensure alignment with business objectives and regulatory requirements.

About the team: This diverse team is ensuring that the GRC policy landscape is being adhered to and ensuring that all necessary protections are in place.

Key Responsibilities:

  1. Designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry’s best practices (e.g., ISO 27001, NIST, COBIT).
  2. Creating, reviewing, and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  3. Monitoring compliance with internal policies and external regulations and prepare for audits and assessments.
  4. Establishing enterprise level security governance structure, charters, participants and roles, and perform periodic role reviews to ensure appropriate accountability is maintained.
  5. Working closely with IT, legal, and business units to ensure cybersecurity governance initiatives are integrated into overall business processes.
  6. Driving security-related certification efforts such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.
  7. Generating regular reporting including KPIs, metrics and SLAs reporting, executive reporting, and other ad hoc reporting as required by management.
  8. Responsible for resolution of cybersecurity GRC issues.
  9. Serving as a trusted advisor to the business and technology stakeholders across the enterprise to partner on security issues and stay aligned on common goals.

Requirements:

  1. Experience designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry best practices (e.g., ISO 27001, NIST, COBIT).
  2. Experience creating, reviewing and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  3. Experience implementing cybersecurity and compliance related frameworks such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.
  4. Experience managing an enterprise cybersecurity GRC program. Experience in defining cybersecurity controls, particularly related to regulatory, legislative, and industry specific compliance requirements.
  5. Ability to develop and implement security programs.
  6. Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating the resources necessary to effectively troubleshoot/diagnose complex project issues.
  7. Advanced communication (verbal and written) and customer service skills. Strong interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Governance and Compliance Analyst

RELX

Atlanta

On-site

USD 70.000 - 110.000

4 days ago
Be an early applicant

Governance and Compliance Analyst

Elsevier

Atlanta

On-site

USD 70.000 - 110.000

12 days ago

Governance and Compliance Analyst

RELX

Atlanta

On-site

USD 70.000 - 110.000

30+ days ago

Director, Compliance - Governance

Equifax, Inc.

Alpharetta

Hybrid

USD 90.000 - 120.000

Today
Be an early applicant

Registered Investment Advisor Compliance Manager

Alera Group

Springfield

Remote

USD 90.000 - 120.000

Yesterday
Be an early applicant

Compliance Analyst -Medicare Part B- REMOTE

Lensa

Nashville

Remote

USD 59.000 - 94.000

Today
Be an early applicant

Senior Compliance Analyst, Duals (D-SNP) Products

Centene Corporation

Missouri

Remote

USD 68.000 - 124.000

10 days ago

Sr. Business Governance & Compliance Analyst

PeopleReady

Tacoma

Remote

USD 73.000 - 89.000

20 days ago

Vendor Compliance and Governance Analyst

Alliant Insurance Services

Remote

USD 60.000 - 100.000

5 days ago
Be an early applicant