Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL

Oxford (MS)

On-site

USD 110,000 - 150,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

mTrade is seeking a Senior Cybersecurity Risk & Governance Analyst to strengthen our information security GRC program. You will assess cyber risks across the organization, coordinate third-party risk, and support customer due diligence, audits, and governance initiatives.

You will report to the CISO and collaborate with Technology, Compliance, Legal, and Internal Audit teams. The role emphasizes regulatory alignment, cloud security, and executive risk reporting in a fast-paced environment.

Qualifications

  • Bachelor's degree in Cybersecurity or related field; 5+ years in cybersecurity risk management, governance, or audit.
  • Experience with regulated industries (financial services, fintech, banking).
  • Ability to conduct risk assessments and manage risk registers.
  • Experience responding to customer security questionnaires & audit inquiries.
  • Experience reviewing SOC 1/2 reports & vendor due diligence materials.
  • Familiarity with frameworks (NIST CSF, ISO 27001, SOC 2, PCI DSS).
  • Proficient with cloud security concepts and Microsoft Azure.

Responsibilities

  • Maintain and enhance the organization's cybersecurity GRC program.
  • Conduct risk assessments for systems, processes, and cloud services.
  • Track KRIs and remediation activities; support policy development.
  • Coordinate third-party risk management and vendor due diligence.
  • Prepare executive risk summaries and governance reports.
  • Support customer security questionnaires and audits.

Skills

Cybersecurity risk management
Regulatory compliance
Communication skills
Analytical thinking
Cloud governance

Education

Bachelor's degree in Cybersecurity, Information Systems, Information Security, Risk Management, Business, Finance, Accounting, or related field

Tools

Azure
ServiceNow GRC
Archer
LogicGate
AuditBoard

Job description

Senior Cybersecurity Risk & Governance Analyst

Job Category: Analytics

Requisition Number: SENIO001101

  • Posted : August 13, 2026
  • Full-Time
Locations

Showing 1 location

Oxford, MS 38655, USA

Description

mTrade is seeking a highly motivated Senior Cybersecurity Risk & Governance Analyst to support and enhance our Information Security Governance, Risk, and Compliance (GRC) program. This role is responsible for helping identify, assess, monitor, and communicate cyber and technology risks across the organization while supporting third-party risk management, customer due diligence activities, audit coordination, and security governance initiatives.

This position reports into the Information Security organization and works closely with the Chief Information Security Officer (CISO), Technology, Compliance, Legal, Internal Audit, and business stakeholders. The successful candidate will contribute to strengthening the organization's cybersecurity posture, operational resilience, regulatory compliance, and customer trust programs.

This role offers significant exposure to cybersecurity governance, risk management, cloud security, third-party risk, customer assurance activities, executive reporting, and industry-standard security frameworks. It provides a growth path into senior cybersecurity governance, risk, compliance, and security leadership roles.

Key Responsibilities

Cybersecurity Governance & Risk Management:

  • Maintain and enhance the organization's cybersecurity governance, risk, and compliance program.
  • Conduct cyber and technology risk assessments for systems, business processes, cloud services, and strategic initiatives.
  • Maintain the enterprise risk register, ensuring risks, owners, mitigation plans, and status updates remain current.
  • Track key risk indicators (KRIs), emerging cyber threats, and remediation activities.
  • Assist technology and business teams with risk identification, treatment planning, and control implementation.
  • Support development and maintenance of information security policies, standards, procedures, and governance documentation.
  • Assist with cybersecurity risk reporting for executive leadership and governance committees.

Third-Party Risk Management:

  • Conduct vendor cybersecurity assessments and due diligence reviews for new and existing third-party relationships.
  • Evaluate vendor security documentation, including SOC reports, penetration test summaries, security assessments, audit reports, and compliance certifications.
  • Assess risks associated with cloud-hosted services, SaaS platforms, and strategic technology providers.
  • Track remediation activities resulting from third-party assessments and risk reviews.
  • Partner with Procurement, Legal, Compliance, Technology, and business stakeholders throughout the vendor lifecycle.
  • Maintain accurate third-party risk records and reporting within the organization's GRC platform.

Customer Security Assurance & Due Diligence:

  • Coordinate responses to customer security questionnaires, risk assessments, and due diligence requests.
  • Support customer audits and security review meetings.
  • Collaborate with Information Security, Technology, Privacy, Legal, Compliance, and business teams to gather accurate responses.
  • Maintain a centralized repository of approved security, compliance, risk, and privacy responses.
  • Support development and maintenance of customer assurance materials, including SOC reports, policy summaries, security overviews, and compliance documentation.
  • Identify opportunities to improve response quality, consistency, and efficiency through automation and AI-enabled tools.

Audit, Compliance & Control Assurance:

  • Support internal and external audits, including SOC examinations and customer audits.
  • Coordinate evidence collection, documentation, and stakeholder responses.
  • Assist with remediation tracking and validation of audit findings.
  • Monitor compliance with internal policies, regulatory requirements, and security frameworks.
  • Support control testing, assessment activities, and continuous improvement initiatives.

Metrics, Reporting & Governance:

  • Develop cybersecurity metrics, dashboards, and executive reporting materials.
  • Prepare risk summaries and presentations for management and governance committees.
  • Analyze risk trends and provide actionable recommendations to leadership.
  • Identify opportunities to enhance governance processes through data analytics, workflow automation, and AI-enabled technologies.
  • Support ongoing maturation of the cybersecurity program.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Information Security, Risk Management, Business, Finance, Accounting, or a related field.
  • 5+ years of experience in cybersecurity risk management, IT risk, governance, compliance, internal audit, third-party risk management, operational risk, or related disciplines.
  • Experience working within financial services, fintech, banking, regulated technology, healthcare, insurance, or another regulated industry.
  • Experience conducting risk assessments and maintaining risk registers.
  • Experience responding to customer security questionnaires, due diligence requests, and audit inquiries.
  • Experience reviewing SOC 1 and SOC 2 reports, security assessments, and vendor due diligence materials.
  • Experience supporting SOC examinations, regulatory assessments, customer audits, or customer security reviews.
  • Demonstrated experience applying at least one recognized cybersecurity, risk, or control framework, such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, FFIEC, or PCI DSS.
  • Working familiarity with Microsoft Azure, Microsoft 365, cloud governance, and cloud security concepts.
  • Strong understanding of cybersecurity risk management concepts, governance practices, and internal controls.
  • Excellent written and verbal communication skills, including the ability to communicate effectively with senior leadership, auditors, regulators, customers, and technical teams.
  • Strong analytical, organizational, and problem-solving skills.
  • Ability to manage multiple priorities and work independently in a fast-paced environment.

Preferred Qualifications

  • Experience with GRC platforms such as ServiceNow GRC, Archer, LogicGate, AuditBoard, ProcessUnity, or similar solutions.
  • Experience leveraging AI-enabled technologies, workflow automation, Microsoft Copilot, Microsoft Power Platform, Microsoft Purview, or analytics platforms to improve security and risk processes.
  • One or more relevant professional certifications, such as CRISC, CISA, CISM, CISSP, CIA, or CRCM.
  • Experience supporting process improvement, risk reporting automation, or executive-level cybersecurity metrics and dashboards.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cyber Compliance Analyst III
Cyber Compliance Analyst III

Hard Rock Hotel & Casino Ottawa • United States

On-site
USD 120,000 - 150,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
GRC Cybersecurity Specialist
GRC Cybersecurity Specialist

We Place People Executive Search Firm • Austin (TX)

On-site
USD 110,000 - 140,000
Junior Cybersecurity GRC Analyst
Junior Cybersecurity GRC Analyst

Talanto • Northern (KY)

Hybrid
USD 5,500 - 12,000
Medical: Health plan options with HSA
Dental: PPO coverage
Vision: Annual exam allowance
+5
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000