Senior IT Governance, Risk, and Compliance (GRC) Analyst

Kennesaw State University

Kennesaw (GA)

On-site

USD 90,000 - 130,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Kennesaw State University is seeking a Senior IT Governance, Risk, and Compliance (GRC) Analyst to lead enterprise cybersecurity governance, risk management, compliance, and third-party risk activities. The role provides strategic guidance, conducts complex assessments, and promotes risk-informed decision-making across the university.

The ideal candidate has 5+ years of GRC-related experience, relevant certifications, and strong abilities to communicate with technical and non-technical

Qualifications

  • Bachelor's degree or equivalent in IT, cybersecurity, or related field.
  • Five (5) years of governance, risk, compliance, audit, or cybersecurity experience.
  • Relevant certifications such as CISSP, CISA, CRISC, CISM, Security+ or ITIL.
  • Experience with GRC platforms and regulatory requirements (GLBA, HIPAA, FERPA, PCI-DSS, NIST).

Responsibilities

  • Lead IT and cybersecurity risk assessments using NIST, CIS, and institutional frameworks.
  • Maintain enterprise IT risk register with ownership, remediation tracking.
  • Lead third-party vendor risk assessments and review SOC reports and questionnaires.
  • Coordinate audit readiness activities and evidence collection.
  • Assess controls against GLBA, HIPAA, FERPA, PCI-DSS, NIST and related standards.
  • Develop metrics and executive dashboards communicating risk and compliance status.

Skills

Regulatory compliance
GRC frameworks
Risk assessment
Vendor risk management
Audit support
Executive reporting
Communication skills

Education

Bachelor's degree in IT/Cybersecurity

Tools

ServiceNow GRC
RSA Archer
OneTrust
Apptega

Job description

Senior IT Governance, Risk, and Compliance (GRC) Analyst

Job ID: 303701

Location: Kennesaw, Georgia

Full/Part Time: Full Time

Regular/Temporary: Regular

About Us

Are you ready to transform lives throughacademic excellence, innovative research, strong communitypartnerships and economic opportunity? Kennesaw State University isone of the 50 largest public institutions in the country. Withgrowing enrollment and global reach, we continue to expand ourinstitutional influence and prominence beyond the state of Georgia.We offer more than 190 undergraduate, graduate, and doctoraldegrees to empower over 50,000 students to become thought leaders,lifelong learners, and informed global citizens. Ourentrepreneurial spirit, high-impact research, and Division Iathletics draw students from throughout the region and from morethan 100 countries across the globe. Our university's vibrantculture, career opportunities,rich benefits, and valuesof respect, integrity, collaboration, inclusivity, andaccountability make us an employer of choice. We are part oftheUniversity System ofGeorgia.We are searching for talented people to joinKennesaw State University in our vision.Come TakeFlight at KSU!

Location

(Primary Location for JobResponsibilities) Our Kennesaw campus is located at 1000Chastain Road NW, Kennesaw, GA 30144.

Our Marietta campus is located at 1100 SouthMarietta Parkway, Marietta, GA 30060.

Job Summary

The position leads enterprise cybersecurity governance, riskmanagement, compliance, and third-party risk activities whilesupporting alignment with institutional, state, and federalrequirements. This position serves as a senior subject matterexpert, providing strategic guidance, leading complex assessments,and promoting risk-informed decision-making across theuniversity.

Responsibilities
  • Leads enterprise IT and cybersecurity risk assessments usingNIST, CIS, and institutional frameworks, evaluating compensatingcontrols and contextual risk to support informeddecision-making.
  • Maintains and enhances the enterprise IT risk register, ensuringaccurate risk documentation, ownership assignment, remediationtracking, and risk acceptance processes.
  • Leads third-party vendor risk assessments, analyzing SOCreports, HECVATs, security questionnaires, and supportingdocumentation to evaluate organizational risk.
  • Coordinates audit readiness activities, evidence collection,stakeholder engagement, response tracking, and remediation effortsrelated to cybersecurity and regulatory audits.
  • Assesses and validates technical, administrative, andoperational controls against GLBA, HIPAA, FERPA, PCI-DSS, NIST, andrelated compliance requirements.
  • Supports the University's data privacy program, includingRecords of Processing Activities (RoPA), data privacy consultationsand assessments, data privacy requests, privacy risk identificationand mitigation, and the development and implementation of dataprivacy awareness and training initiatives.
  • Develops, reviews, and maintains cybersecurity policies,standards, procedures, and governance documentation to supportcompliance and operational maturity.
  • Collaborates with internal stakeholders to evaluate, validate,and reassess IT controls, identify control gaps and risks, andsupport the development and implementation of appropriateremediation strategies.
  • Collaborates with the Office of Research, faculty, and other keystakeholders to support the governance, compliance, riskmanagement, and security and privacy requirements associated withsponsored research, controlled information, and regulated researchenvironments.
  • Partners with business, academic, and technology stakeholdersto identify risks, recommend mitigation strategies, and supportimplementation of corrective actions.
  • Develops metrics, dashboards, and executive reports thatcommunicate cybersecurity risk, compliance status, trends, andprogram effectiveness to leadership.
Required Qualifications

Educational Requirements

  • Bachelor's degree from an accredited institution of higher education or an equivalent combination of relevant education and/orexperience.

Required Experience

  • Five (5) years of professional experience supporting governance,risk, compliance, audit, legal, cybersecurity, or related functions and disciplines.
Preferred Qualifications

Additional Preferred Qualifications

  • Relevant certifications such as CISSP, CISA, CRISC, CGRC, CISM, Security+, or ITIL Foundation

Preferred Educational Qualifications

  • An advanced degree from an accredited institution of higher education in a related field such as Information Technology,Cybersecurity, Information Systems, Business Administration, orRisk Management

Preferred Experience

  • Experience in higher education or regulated environments (FERPA,GLBA, HIPAA, PCI-DSS, NIST 800-171, CMMC)
  • Experience with GRC platforms such as ServiceNow GRC, RSA Archer,OneTrust, Apptega, or similar systems
Knowledge, Skills, & Abilities

ABILITIES

  • Ability to interpret regulatory, contractual, and institutionalcompliance requirements
  • Ability to develop governance documentation, policies, standards,and procedures
  • Ability to communicate technical and risk-related concepts totechnical and non-technical audiences
  • Ability to prepare executive-level reports, metrics, and recommendations
  • Strong analytical and problem-solving skills with the ability toevaluate complex risk scenarios
  • Able to handle multiple tasks or projects at one time, meetingassigned deadlines

KNOWLEDGE

  • Advanced knowledge of cybersecurity governance, risk management,compliance, and privacy principles and frameworks
  • Knowledge of cybersecurity frameworks including NIST, RMF, CIS, ISO27001, and related standards
  • Knowledge of research security principles and applicablerequirements governing federally sponsored research, controlledinformation, and regulated research environments.
  • Experience leading IT risk assessments and evaluating compensatingcontrols and contextual risk
  • Experience with GRC tools, dashboards, and compliance trackingsystems
  • Strong understanding of vendor risk management and third-partysecurity assessment practices

SKILLS

  • Excellent interpersonal, initiative, teamwork, problem-solving, independent judgment, organization, communication (verbal andwritten), time management, project management, and presentationskills
  • Proficient with computer applications and programs associated withthe position (i.e., Microsoft Office suite)
  • Strong attention to detail and follow-up skills
  • Strong customer service skills and phone and e-mail etiquette
USG Core Values

The University System of Georgia is comprised of our 25institutions of higher education and learning as well as the SystemOffice. Our USG Statement of Core Values are Integrity, Excellence,Accountability, and Respect. These values serve as thefoundation for all that we do as an organization, and each USGcommunity member is responsible for demonstrating and upholdingthese standards.More details on the USG Statement of CoreValues and Code of Conduct are available in USG Board Policy8.2.18.1.2 and can be found on-line at https://www.usg.edu/policymanual/section8/C224/#p8.2.18_personnel_conduct. Additionally, USG supports Freedom of Expression as stated inBoard Policy 6.5 Freedom of Expression and Academic Freedom foundon-line at https://www.usg.edu/policymanual/section6/C2653.

Equal Employment Opportunity

Kennesaw State University is an EqualEmployment Opportunity Employer. The University is committed tomaintaining a fair and respectful environment for living, work andstudy. To that end, and in accordance with federal and state law,Board of Regents policy, and University policy, the Universityprohibits harassment of or discrimination against any personbecause of race, color, sex (including sexual harassment,pregnancy, and medical conditions related to pregnancy), sexualorientation, gender identity, gender expression, ethnicity ornational origin, religion, age, genetic information, disability, orveteran or military status by any member of the KSU Community oncampus, in connection with a University program or activity, or ina manner that creates a hostile environment for members of the KSUcommunity. For additional information on this policy, or to file a complaintunder the provisions of this policy, students, employees,applicants for employment or admission or other third partiesshould contact the Office of Institutional Equity at EnglishBuilding, Suite 225, eeo@kennesaw.edu.

Other Information

This is not a supervisory position. This position does not have any financial responsibilities. This position will not be required to drive. This role is considered a position of trust. This position does not require a purchasing card (P-Card). This position may travel 1% - 24% of the time. This position does not require security clearance.

Background Check
  • Standard Enhanced
  • Education

Per the University System of Georgia background check policy,all final candidates will be required to consent to a criminalbackground investigation. Final candidates may be asked to disclosecriminal record history during the initial screening process andprior to a conditional offer of employment. Applicants forpositions of trust with screening results which confirm adisqualifying criminal history will be immediately disqualifiedfrom employment eligibility

All applicants are required to include professional referencesas part of their application process. Some positions may requireadditional job-based screenings such as motor vehicle report,credit check, pre-employment drug screening and/or verification ofacademic credentials.

https://www.usg.edu/hr/assets/hr/hrap_manual/HRAP_Background_Investigation_Employment.pdf

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Kennesaw State University • Kennesaw (GA)

On-site
USD 100,000 - 150,000
Associate Vice President, Research Computing and Emerging Technologies
Associate Vice President, Research Computing and Emerging Technologies

Kennesaw State University • Kennesaw (GA)

On-site
USD 150,000 - 190,000
Senior Internal Auditor
Senior Internal Auditor

Kennesaw State University • Kennesaw (GA)

On-site
USD 86,400 - 96,000
Comprehensive benefits
Tuition waiver
Wellness options
IT Project Delivery Director
IT Project Delivery Director

Kennesaw State University • Kennesaw (GA)

On-site
USD 120,000 - 160,000
Senior Learning Technology Systems Administrator
Senior Learning Technology Systems Administrator

Kennesaw State University • Kennesaw (GA)

On-site
USD 70,000 - 95,000
Senior Application Manager
Senior Application Manager

Kennesaw State University • Kennesaw (GA)

On-site
USD 110,000 - 140,000
Career Consultant
Career Consultant

Kennesaw State University • Kennesaw (GA)

On-site
USD 52,000 - 70,000
Senior Business Operations Manager - Strategic Communications and Marketing
Senior Business Operations Manager - Strategic Communications and Marketing

Kennesaw State University • Kennesaw (GA)

On-site
USD 85,000 - 96,000
13 paid holidays
Vacation time
Tuition waiver
+1
Director, IT Applications
Director, IT Applications

Kennesaw State University • Kennesaw (GA)

On-site
USD 120,000 - 160,000
Office Manager, Mechanical Engineering
Office Manager, Mechanical Engineering

Kennesaw State University • Marietta (GA)

On-site
USD 28,000 - 32,000