GRC Cybersecurity Analyst III

ICCU

Meridian, Chubbuck (ID, ID)

On-site

USD 105,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ICCU is seeking a senior GRC Cybersecurity Analyst III to lead enterprise governance, risk, and compliance initiatives within IT. You will oversee risk assessments, regulatory compliance, IT audits, and policy development, while mentoring junior staff and coordinating with executives and external stakeholders.

The role requires 9+ years in information security, 6+ years in senior IT security, and 3+ years in GRC projects, with familiarity of NIST CSF, PCI‑DSS, and CIS Controls.

Qualifications

  • 9+ years in information security roles.
  • 6+ years in senior IT security roles (security, infra, dev, cloud).
  • 3+ years in senior GRC projects or teams.
  • Experience with regulatory compliance and certification programs.

Responsibilities

  • Lead enterprisewide cyber and information security risk assessments and audits.
  • Help set strategy to strengthen defenses and close control gaps.
  • Manage third‑party cyber risk assessments, vendor reviews, and remediation tracking.
  • Oversee compliance frameworks: NIST CSF, FFIEC, PCI‑DSS, CIS Controls, FedLine, SWIFT.
  • Develop and maintain IT policies, standards, and procedures for regulations.
  • Coordinate IT audits with internal teams and external auditors/regulators.
  • Build IT GRC dashboards, risk registers, and executive reports.
  • Draft statements of work for new IT GRC initiatives.
  • Lead tabletop exercises and incident response planning with stakeholders.
  • Mentor junior GRC analysts and collaborate with IT, Compliance, Risk.
  • Align GRC efforts with IT, compliance, and risk teams.
  • Interact with auditors, regulators, and certification bodies as needed.
  • Monitor compliance gaps and mitigation plans; report audit readiness.
  • Stay current on regulatory developments affecting cybersecurity programs.

Skills

GRC leadership
Cybersecurity
Risk assessments
Stakeholder management

Education

Bachelor's degree in Info Assurance
Master's degree preferred
DoD 8570 certs (CISSP/CISM/CISA)

Tools

SIEM tools
Vulnerability scanners
GRC systems
Dashboards

Job description

The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a subject matter expert, mentor to junior staff, and liaison to executive leadership and external stakeholders while advancing ICCU’s mission of Helping Members Achieve Financial Success.

Duties & Responsibilities
  • Lead and execute enterprisewide cyber and information security risk assessments and audits.
  • A primary contributor to setting strategy and direction in strengthening and reinforcing ICCUs technology defenses and identifying and remedying weaknesses and control gaps within the ICCU environment.
  • Manage third‑party cyber risk assessments, vendor reviews, and remediation tracking.
  • Oversee compliance frameworks including NIST CSF, FFIEC, PCI‑DSS, CIS Controls, FedLine, and SWIFT.
  • Develop and maintain IT policies, standards, and procedures aligned with regulatory mandates.
  • Act as lead liaison and coordinator of internal and external IT audits.
  • Build and maintain IT GRC dashboards, risk registers, and executive reports.
  • Scope and draft statements of work and proposals for new IT GRC initiatives.
  • Lead tabletop exercises, Pen Test reviews, and incident response planning in partnership with stakeholders.
  • Provide mentorship and guidance to junior GRC Cybersecurity analysts.
  • Collaborate with IT, Compliance, and Risk teams to align GRC efforts.
  • Serve as a primary IT point of contact for auditors, regulators, and certification bodies.
  • Monitor and report on compliance gaps, risk mitigation plans, and audit readiness.
  • Stay current on regulatory developments, compliance frameworks, and emerging governance risks impacting cybersecurity programs.
  • Support strategic planning and budgeting for GRC tools and capabilities.
  • Other duties as assigned.
Qualifications
Education & Certifications
  • A bachelor’s degree in Information Assurance, Cyber Security, Computer Science, Computer Information Technology, or similar field of study, or equivalent work experience is required.
  • A master’s degree or equivalent certificate in information assurance or computer related fields such as Computer Science, Computer Security or Software Development is strongly preferred. A masters degree may substitute for 1 year of required experience.
  • One Level I certification, One Level II, and One Level III certification from the DoD 8140 (8570) Cyber Workforce Qualification Matrix pertaining to GRC (eg, SSCP, CISSP, CISM, CISA, CRISC, GSEC, CGRC, CCSP, CSSLP, GSE, or equivalent).
Experience
  • 9+ years of work experience in roles with significant Information Security duties.
  • 6+ years of work experience in senior level IT technical roles in Security, Infrastructure, Application Development, Operations, Cloud Management, Ecommerce, or similar areas.
  • 3+ years of experience in senior roles with cyber / infosec GRC projects or teams.
  • Proven experience with regulatory compliance and certification programs.
  • Experience in regulated industries such as financial services or healthcare.
  • Familiarity with enterprise risk management (ERM) frameworks.
Tools & Technologies
  • Security Information and Event Management (SIEM) tools for log aggregation, monitoring, and analysis.
  • Vulnerability Scanning Platforms for identifying, reporting, and tracking security weaknesses.
  • Enterprise GRC systems(or equivalent) for assessment distribution and tracking.
  • Internal dashboards (for metrics, assessments, audit readiness, and executive reporting).
  • Familiarity with project management tools.
  • Microsoft Office Suite (Excel, Word).
  • Understanding of cloud technologies and SaaS platforms.
  • Strong leadership, communication, and stakeholder management skills.
  • Ability to manage complex projects and cross‑functional teams.
  • Strategic thinking with strong attention to detail.
  • Ability to simplify complexity and drive results.
  • High sense of urgency and initiative.
  • Ability to work independently and collaboratively.
Physical & Operational Requirements

This role is primarily office‑based and requires extended periods of sitting, computer use, and interaction with standard office equipment. Occasional lifting of up to 15 pounds may be required. The employee must have sufficient vision to read documents and screens, and hearing ability to communicate effectively in person and via telephone. Flexibility may be required during organizational changes or high‑priority audit cycles.

The above statements reflect the general details considered necessary to describe the essential functions of the job and should not be construed as a detailed description of all the work requirements that may be inherent of the job.

Must be eligible for membership at ICCU to obtain employment.

ICCU is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, age, disability, protected veteran status or other characteristics protected by law.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Cybersecurity Strategist
Senior GRC Cybersecurity Strategist

ICCU • Meridian (ID), Chubbuck (ID)

On-site
USD 105,000 - 150,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
Information Security Analyst II (GRC)
Information Security Analyst II (GRC)

Meritrust Credit Union • Wichita (KS), Broomfield (CO)

On-site
USD 78,000 - 98,000
Comprehensive medical insurance plan
Dental and vision insurance
Generous paid‑time‑off
+8
SVP & Director of IT Governance - Cyber Security
SVP & Director of IT Governance - Cyber Security

Socket.dev • Uniontown (OH)

On-site
USD 120,000 - 180,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark Bank • Ridgeland (MS)

Hybrid
USD 60,000 - 80,000
IT GRC Analyst II
IT GRC Analyst II

State Employees' Credit Union • Raleigh (NC)

On-site
USD 90,000 - 120,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark • Ridgeland (MS)

Hybrid
USD 65,000 - 85,000
IT GRC Analyst II
IT GRC Analyst II

SECU • North Carolina

On-site
USD 80,000 - 110,000
(GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK
(GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK

Central Business Solutions, Inc • Atlanta (GA)

On-site
USD 95,000 - 110,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 130,000 - 170,000