GRC Security Analyst II

Aqua America, Inc.

Bryn Mawr (PA)

On-site

USD 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equal Opportunity Employer
Accommodation for individuals with disabilities

Job summary

Aqua America, Inc. is hiring a GRC Security Analyst II responsible for managing risk assessments, developing security awareness programs, and ensuring compliance with security standards. The role requires a bachelor's degree in Information Technology or a related field, along with 3-5 years of experience in Governance & Risk. Candidates must also obtain a relevant certification within their first year of employment.

The successful candidate will collaborate with IT and business teams to enhance security practices and must demonstrate strong communication and analytical skills. This position offers exposure to various security tools including Qualys and RSA Archer.

Qualifications

  • Bachelor's degree in relevant field required.
  • 3-5 years of Governance & Risk experience necessary.
  • One certification (CISSP, GIAC, CRISC, etc.) is required within 12 months.

Responsibilities

  • Manage risk assessments and remediation processes.
  • Develop and implement security awareness training.
  • Lead vendor and 3rd party risk assessments.
  • Monitor compliance with security standards.
  • Act as liaison to audit teams.

Skills

Governance & Risk
Vulnerability Management
Security Awareness
Risk Analysis
Communication Skills
Analytical Skills

Education

Bachelors in Information Technology, Cyber Security or related field

Tools

Qualys
RSA Archer

Job description

Essential Utilities, Inc.

Job Title: GRC Security Analyst II (Governance & Risk)

Responsibilities
  • Manage execution of both enterprise-wide and focused risk, threat, and vulnerability assessments, including but not limited to Security Awareness, Vulnerability, Configuration, and Third-Party Assessments.
  • Analyze and prioritize risk, vulnerability, and compliance findings to define remediation priorities considering all available data sources; partnering with technology and business stakeholders to socialize and implement remediation plans.
  • Define and manage qualitative and quantitative metrics and reporting to measure the success of vulnerability, third party, security awareness, security awareness, configuration, and asset management remediations.
  • Ability to lead ongoing vulnerability management processes, including working with IT and business stakeholders to prepare vulnerability remediation plans, track progress, and reduce overall vulnerability exposures.
  • Participate in development, implementation and operation of control/compliance frameworks and security best practices based on ISO 27001/27002, NIST (800‑30, Cyber Security Framework/CSF), COBIT, Critical Security Controls, CIS Configuration Benchmarks.
  • Monitor compliance with security configuration standards for servers, endpoints, software, and networking platforms based on CIS Benchmarks.
  • Work closely with IT, development, and operations teams to ensure the integration of security practices into the software development lifecycle (SDLC) and IT operations.
  • Lead or assist with vendor and 3rd party risk assessments.
  • Create/maintain documentation of security solutions, services, configurations, and processes.
  • Work closely with engineers focused on intrusion detection, incident response and security operations to manage risk related to existing and emerging threats.
  • Collaborate with other security engineers to analyze, process, integrate, communicate, and respond to threat intelligence.
  • Ability to participate in or lead development, improvements and updates to continually improve security controls, policies, guidelines, processes and procedures.
  • Develop and deliver security awareness training programs for employees to enhance their understanding of security best practice to ensure that security and risk management continue to be integrated into the corporate culture.
  • Lead development and operation of the security awareness program to ensure that security and risk management continue to be integrated into the corporate culture.
  • Implement and maintain controls for compliance and privacy.
  • Act as liaison to internal and external audit teams as needed.
  • Provide escalation support for the Information Technology Help Desk as required.
  • Ability to work off hours maintenance windows and participate in rotating on call shift periodically.
  • Ability to work alone or function effectively as part of a team.
  • All other duties as assigned by management.
Qualifications
  • Bachelors in Information Technology, Computer Science, Cyber Security, Security and Risk Analysis, Information Assurance.
  • 3‑5 years of previous Governance & Risk experience.
  • Candidates must have a minimum of one of the following certifications or will be required to obtain within the first 12 months: CISSP, GIAC (GSEC, GSNA), CRISC, CISA, CISM, CCSP, SSCP, CAP, CSSLP, CSX Practitioner.
  • Experience working with assessment tools such as Qualys Policy Compliance and CIS‑CAT.
  • Experience developing and using Qualys, or other vulnerability management, platforms with experience in multiple modules and/or areas: Vulnerability Management, Policy Compliance, Continuous Monitoring, Policy Compliance, Web Application Scanning and Asset Management.
  • Experience leading security awareness program development including: Leading regular phishing assessment campaigns.
  • Creating innovative security awareness campaigns using solution provider and custom‑developed tools/trainings designed to be flexible and adaptable across a diverse employee population (executives, engineering, marketing and communications, finance, customer service, etc.).
  • Participate in aligning the security awareness program with the enterprise’s greatest risks and measure the impact in risk reduction from security awareness efforts.
  • GRC platform experience, with RSA Archer knowledge a strong positive.
  • Strong written and verbal communication skills are required as this position will be responsible for working directly with technical teams and business stakeholders.
  • Demonstrates strong organizational skills and the ability to multi‑task, prioritize workload and delegate responsibilities.
  • Strong analytical skills for assessing and prioritizing security risks.
  • Ability to promote a security‑conscious culture within the organization.
  • Ability to adapt to evolving threats, technologies, and organizational needs.
  • Ability to understand and integrate security into project and application lifecycles for enterprise IT systems.
  • Minimum of 3 to 5 years experience in Information Technology focusing on information security auditing, risk analysis, and vulnerability management.
  • General knowledge of the following technologies from a security perspective: Active Directory, database platforms, web server platforms, Middleware, PKI, cloud computing, Office 365 and Azure.
  • Experience using statistical, quantitative, and qualitative analysis techniques.
  • Proactive approach to staying informed on the latest security threats, vulnerabilities, and industry best practices.

Essential Utilities, Inc., is an Equal Opportunity/Affirmative Action employer. Equal employment opportunity is provided to all employees and applicants for employment without regard to the following legally protected characteristics: race, color, religion, sex, national origin, age, pregnancy (including childbirth and related medical conditions, including medical conditions related to lactation), physical or mental disability, covered‑veteran status, genetic information (including testing and characteristics), sexual orientation, gender identity or expression or any other characteristic protected by applicable local, state or federal law. Essential Utilities is committed to providing reasonable accommodation to individuals with disabilities. If you have a condition that may prevent you from applying for a job online or need to request an accommodation during the interview process, please call (1-877-271-9012).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Security Analyst II
GRC Security Analyst II

Aqua America, Inc. • Pennsylvania

On-site
USD 80,000 - 100,000
Competitive benefits package
Career growth opportunities
Commitment to sustainable growth
Sr. Cybersecurity GRC Analyst (Remote)
Sr. Cybersecurity GRC Analyst (Remote)

TPx • United States

On-site
USD 105,000 - 145,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Security GRC Analyst
Security GRC Analyst

Socket.dev • United States

Remote
USD 90,000 - 120,000
Health insurance
401(k) with company match
Paid time off
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 130,000 - 170,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Security Analyst I – Identity & Access Management (IAM) & Compliance
Security Analyst I – Identity & Access Management (IAM) & Compliance

aquaamerica • Bryn Mawr (PA)

On-site
USD 55,000 - 75,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Cybersecurity Senior GRC Analyst
Cybersecurity Senior GRC Analyst

UGI Utilities, Inc. • Pennsylvania

On-site
USD 85,000 - 110,000
Competitive compensation plan
Comprehensive benefits
Upward mobility opportunities
+1