GRC Analyst: Shape Policy, Risk & Compliance

Ice Miller LLP

Philadelphia (Philadelphia County)

On-site

USD 75,000 - 100,000

Full time

40 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Vision and Dental Insurance
401k (employer match)
Life insurance

Job summary

Ice Miller LLP is seeking a GRC Analyst to leverage knowledge of security policies, standards, controls, and industry best practices. This role consults with teams and informs on risk to systems and data, ensuring GRC functions are integrated into firm programs and that risk mitigation is effective.

Minimum requirements include familiarity with HIPAA, PCI DSS, ISO2700x, and NIST frameworks, plus strong written and verbal communication.

Qualifications

  • Understanding of security regulations (HIPAA, PCI, ISO27001).
  • Familiarity with common security frameworks (NIST CSF, NIST SP 800-53, HITRUST).
  • Experience documenting risk and compliance activities.
  • Ability to communicate complex security topics to varied audiences.
  • Proficiency in incident response playbooks and tabletop exercises.

Responsibilities

  • Governance: develop and manage security policies, standards, procedures aligned to NIST and CIS.
  • Assess platforms against security standards and coordinate remediation with security staff.
  • Interface with security personnel to align expectations and actions.
  • Collaborate with IT to identify and remediate cybersecurity risks promptly.
  • Develop information security awareness and training related to governance changes.
  • Evaluate policy exceptions and manage identity governance activities.
  • Handle audit findings, regulatory input, and compliance requirements.
  • Oversee data transfers and ethical walls as needed.
  • Risk: measure and monitor cybersecurity risk; manage risk exception queues.
  • Perform risk assessments and support business impact analyses.
  • Develop cyber resilience plans including incident response and disaster recovery.
  • Participate in Third Party Risk Management activities.
  • Compliance: monitor regulations and changes impacting information security policies.
  • Support internal and external audits and security questionnaires.
  • Advise management on regulatory impacts and key risks.

Skills

GRC knowledge
NIST CSF
Risk assessment
Policy development
Incident response

Tools

NIST 800-53
CIS controls

Job description

Ice Miller LLP is seeking a GRC Analyst to leverage knowledge of security policies, standards, controls, and industry best practices. This role consults with teams and informs on risk to systems and data, ensuring GRC functions are integrated into firm programs and that risk mitigation is effective.

Minimum requirements include familiarity with HIPAA, PCI DSS, ISO2700x, and NIST frameworks, plus strong written and verbal communication.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst — Risk, Compliance & Security Governance
GRC Analyst — Risk, Compliance & Security Governance

Ice Miller LLP • Baltimore (MD)

On-site
USD 75,000 - 100,000
Health insurance
Paid time off
401k with employer match
+1
GRC Analyst — Shape Enterprise AI Security & Compliance
GRC Analyst — Shape Enterprise AI Security & Compliance

Fireworks AI • San Mateo (CA)

On-site
USD 120,000 - 160,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Governance Risk and Compliance Analyst
Governance Risk and Compliance Analyst

Ice Miller LLP • Philadelphia

On-site
USD 75,000 - 100,000
Health insurance
Vision and Dental Insurance
401k (employer match)
+1
Security GRC Analyst: Mitigate Risk & Elevate Compliance
Security GRC Analyst: Mitigate Risk & Elevate Compliance

Socket.dev • United States

Remote
USD 90,000 - 120,000
Health insurance
401(k) with company match
Paid time off
GRC Cybersecurity Analyst — Policy, Risk & Compliance
GRC Cybersecurity Analyst — Policy, Risk & Compliance

Central Business Solutions, Inc • Atlanta (GA)

On-site
USD 95,000 - 110,000
Governance Risk and Compliance Analyst
Governance Risk and Compliance Analyst

Ice Miller LLP • Baltimore (MD)

On-site
USD 75,000 - 100,000
Health insurance
Paid time off
401k with employer match
+1
GRC & Risk Analyst – SOC 2, ISO 27001, PCI
GRC & Risk Analyst – SOC 2, ISO 27001, PCI

CloudData • United States

On-site
USD 80,000 - 100,000
GRC Analyst: Shape Security Governance & Risk
GRC Analyst: Shape Security Governance & Risk

NorthMark Strategies • Dallas (TX)

On-site
USD 110,000 - 140,000
Lunch stipend
Medical benefits
Paid time off
Healthcare GRC Analyst: Risk, Compliance & Vendor Oversight
Healthcare GRC Analyst: Risk, Compliance & Vendor Oversight

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000