Lead GRC Analyst

Msig USA

Northern (KY)

Hybrid

USD 120,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

MSIG USA is seeking a Lead Governance, Risk & Compliance (GRC) Analyst to mature security governance, risk management, and compliance activities. You will work hands-on, mentor others, and engage with senior leadership on risk and compliance posture.

The role emphasizes regulatory alignment, audit support, and policy governance, with opportunities to grow into leadership. This hybrid role requires 5–8+ years in GRC or IT security in a regulated industry.

Qualifications

  • 5–8+ years of experience in GRC, IT risk management, IT audit, or information security.
  • Hands-on experience with regulatory compliance, audits, or risk assessments.
  • Working knowledge of NYDFS Cybersecurity Regulation (23 NYCRR 500) and at least one major framework (NIST CSF, ISO 27001).
  • Experience maintaining risk registers, audit evidence, or compliance documentation.
  • Strong written communication skills to document risks, controls, and findings clearly.

Responsibilities

  • Governance & Compliance Execution: Maintain and operate MSIG’s security governance and compliance program; track obligations and deadlines; monitor regulatory changes.
  • IT Risk Management: Conduct risk assessments across infrastructure, applications, and cloud; maintain risk register and remediation status.
  • Audit & Regulatory Support: Coordinate internal/external audit activities, assist with remediation planning and follow-up.
  • Policy & Standards Management: Support policy development, review cycles, and awareness across the organization.
  • Third-Party Risk Management: Perform vendor security risk assessments; support due diligence with Procurement and Legal.
  • Reporting & Program Support: Prepare GRC metrics and dashboards; support leadership reporting and continuous improvement.

Skills

GRC
IT risk management
IT audits
Regulatory compliance
Documentation
NIST CSF
ISO 27001
Risk registers

Tools

ServiceNow GRC
Archer
OneTrust

Job description

## Lead GRC AnalystApply: Hybrid: NJ-Warren: Full time: Posted Yesterday: JR-001021MSIG USA continues to grow!**Company Overview:**MSIG USA is the US-based subsidiary of MS&AD Insurance Group Holdings, Inc., one of the world’s top P&C carriers and a global Class 15 insurer, with A+ ratings and a reach that spans 40+ countries and regions. Leveraging our 350-year heritage, MSIG USA brings the financial strength, expertise, and global footprint to offer commercial insurance solutions that address your business’s unique risks.**Role Overview**MSIG is seeking a Lead**, Governance, Risk & Compliance (GRC)** to help run and mature core security governance, risk management, and compliance activities. This role is ideal for an experienced **GRC analyst, IT risk professional, or IT auditor** who is ready to take on broader ownership, mentor others, and grow into a people or program leadership position.The Manager will be **hands-on and execution-focused**, supporting regulatory compliance, audits, IT risk management, and policy governance. While the role will contribute to leadership reporting, **primary Board and executive-facing responsibilities are limited** and supported by senior security leadership.**Key Responsibilities****1. Governance & Compliance Execution*** Maintain and operate MSIG’s security governance and compliance program* Support compliance with key regulations and frameworks (e.g., NYDFS 23 NYCRR 500, HIPAA, GDPR, NIST CSF, ISO 27001)* Track compliance obligations, evidence, and deadlines using defined processes and tools* Assist with monitoring regulatory changes and assessing their operational impact**2. IT Risk Management*** Conduct and support IT and security risk assessments across infrastructure, applications, and cloud environments* Maintain the IT risk register, including risk documentation, remediation tracking, and status updates* Partner with technical teams to document controls and support risk remediation efforts**3. Audit & Regulatory Support*** Coordinate internal and external audit activities, including evidence collection and response tracking* Support interactions with auditors and regulators, with senior leadership leading formal communications* Track audit findings and assist with remediation planning and follow-up**4. Policy & Standards Management*** Support the development, review, and maintenance of security and IT policies and standards* Manage policy review cycles and ensure documentation remains current and accessible* Help promote awareness and adoption of security policies across the organization**5. Third-Party Risk Management (TPRM)*** Perform vendor and third-party security risk assessments* Maintain vendor risk documentation, findings, and remediation tracking* Partner with Procurement and Legal to support security due diligence activities**6. Reporting & Program Support*** Prepare GRC metrics, dashboards, and summary reports for security leadership* Contribute to leadership and management-level reporting on risk and compliance posture* Support continuous improvement initiatives across the GRC program**Qualifications****Required*** 5–8+ years of experience in GRC, IT risk management, IT audit, or information security* Hands-on experience with regulatory compliance, audits, or risk assessments* Working knowledge of NYDFS Cybersecurity Regulation (23 NYCRR 500) and at least one major framework (NIST CSF, ISO 27001, etc.)* Experience maintaining risk registers, audit evidence, or compliance documentation* Strong written communication skills with the ability to document risks, controls, and findings clearly**Preferred*** Experience in insurance or financial services* Familiarity with GRC tools (e.g., ServiceNow GRC, Archer, OneTrust, or similar)* Exposure to cloud environments (Azure and/or AWS)* Relevant certifications such as CISA, CRISC, CISM, or CISSP (or actively pursuing)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead GRC Analyst
Lead GRC Analyst

MSIG USA • Warren Township (IA)

On-site
USD 120,000 - 180,000
Lead GRC Analyst — Hybrid IT Risk & Compliance Leader
Lead GRC Analyst — Hybrid IT Risk & Compliance Leader

Msig USA • Northern (KY)

Hybrid
USD 120,000 - 160,000
GRC Lead: Security Risk & Compliance
GRC Lead: Security Risk & Compliance

MSIG USA • Warren Township (IA)

On-site
USD 120,000 - 180,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
GRC Analyst/Specialist
GRC Analyst/Specialist

SK Select Staffing, Inc. • New York (NY)

Hybrid
USD 90,000 - 120,000
Delivery / Program Lead
Delivery / Program Lead

Msig USA • New Jersey

Hybrid
USD 120,000 - 160,000
Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000