Senior Security Analyst, GRC

GreatAmerica Financial Services

Cedar Rapids (IA)

Hybrid

USD 110,000 - 150,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work arrangements
Monthly Bonuses for Eligible Employees
401(k) and Company Match
Annual Profit Sharing
Paid Time Off
Health Insurance
Dental Insurance
Vision Insurance
Short-Term and Long Term Disability
Company Paid Life Insurance
Flexible Spending Accounts (FSA)
Health Savings Accounts (HSA)
Employee Assistance Program
Parental Leave
Tuition Assistance
Leadership Development Opportunities
Networking Opportunities
Paid Parking

Job summary

GreatAmerica Financial Services is seeking a Senior Security Analyst, GRC to support enterprise security governance and risk management across the organization. You will partner with technology, risk, compliance, and audit teams to strengthen the governance framework and ensure effective operation of the three lines of defense.

Responsibilities include policy development, risk assessment coordination, regulatory liaison, and reporting for executives.

Qualifications

  • Strong knowledge of information security governance, risk management, and regulatory compliance.
  • Experience supporting regulatory exams, audits, and remediation tracking.
  • Ability to develop dashboards and communicate risk posture to senior leadership.
  • Experience in banking or regulated financial services is preferred.

Responsibilities

  • Support development and maintenance of the information security governance framework.
  • Coordinate information security risk assessments and manage the risk register.
  • Act as liaison for regulators and auditors and support regulatory responses.
  • Develop and maintain governance reporting for executive leadership and risk committees.
  • Align governance with frameworks like NIST CSF, NIST RMF, CIS, and ITGC; suggest improvements.

Skills

Security governance
Regulatory compliance
Risk management
Control assessment
Policy development

Education

Bachelor's degree or equivalent preferred

Tools

Optro/Auditboard

Job description

GreatAmerica Financial Services is a highly successful entrepreneurial company providing equipment financing to businesses across the United States. Our exemplary customer service, our principle-centered business philosophy and our team-based operating approach are key to our success and growth.

We are looking to add a Key Member to our Enterprise Security Team!

The Senior Security Analyst, GRC supports the bank’s enterprise security governance program, ensuring alignment with regulatory expectations, enterprise risk management, and industry frameworks. This role oversees security policies, standards, risk governance, partners with third-party security oversight, and provides support for regulatory engagement. The Senior Analyst partners with technology, risk, compliance, and audit teams to strengthen the bank’s Enterprise Security Governance framework and ensures effective operation of the three lines of defense by independently reviewing control effectiveness designed by first-line security engineering and IT operations.

As a Senior Security Analyst, GRC, you will:

Security Governance & Policy
  • Support the development and maintenance of the bank’s information security governance framework.
  • Track the lifecycle of security policies and standards, reporting non-compliance to the policy owners.
  • Ensure alignment with regulatory guidance from the Federal Financial Institutions Examination Council and banking regulators.
  • Maintain governance artifacts including policy exception processes and control documentation.
  • Independently review first-line procedures for alignment with approved policies and standards.
Risk & Compliance Oversight (Second Line)
  • Support enterprise risk management by coordinating information security risk assessments.
  • Track and manage the security risk register.
  • Monitor and independently validate remediation of identified risks and control gaps.
  • Independently assess controls built and operated by first-line security engineering and IT operations teams and formally challenge control design, ownership, and evidence sufficiency through the second-line issue and escalation process.
Regulatory & Audit Management
  • Act as the primary security governance liaison for regulators and auditors.
  • Support exams and reviews conducted by applicable agencies.
  • Coordinate and support responses to regulatory findings, internal audit issues, and external requests from customers.
Security Metrics & Reporting
  • Develop and maintain security governance reporting for executive leadership.
  • Produce dashboards for:
  • Support the presentation of quarterly updates to risk committees and senior management.
Framework Alignment & Continuous Improvement
  • Maintain governance alignment with industry frameworks – NIST CSF, NIST RMF, CIS, ITGC
  • Recommend and support improvements to governance processes and tooling (Optro/Auditboard)
  • Collaborate across legal, compliance, risk, and technology functions

To be successful in the role, you will need:

  • Bachelor’s degree or equivalent preferred.
  • Minimum of 5 years of work experience in information security, risk, security governance or audit
  • Strong knowledge of information security governance, risk management, regulatory compliance, and control frameworks, preferably within banking or regulated financial services.
  • Working knowledge of banking regulatory expectations, FFIEC guidance, and recognized security frameworks such as NIST CSF, NIST RMF, CIS, and ITGC.
  • Experience supporting regulatory exams, audit reviews, external customer requests, findings, issue management, and remediation tracking
Skills and Abilities
  • Ability to maintain security policies, standards, governance artifacts, risk registers, control documentation, and policy exception processes.
  • Ability to independently assess control design, ownership, evidence sufficiency, remediation status, and operating effectiveness within a second-line risk oversight model.
  • Strong analytical and reporting skills, including the ability to develop dashboards and communicate risk posture, policy compliance, control effectiveness, and incident trends.
  • Ability to partner effectively across security, technology, risk, compliance, audit, legal, and business teams while maintaining appropriate independence and challenge.
  • Strong written and verbal communication skills, including the ability to document complex topics clearly and support updates to senior leaders, risk committees, auditors, and regulators.
  • Strong organizational, project coordination, follow-through, and judgment skills, with the ability to manage competing priorities and respond effectively to time-sensitive work.
Preferred Certifications
  • ISACA CISA
  • ISACA CRISC
  • ISC2 CGRC
  • ISC2 CISSPISACA CISM
Other Requirements
  • Exceptional organizational, analytical, and follow-through skills.
  • Excellent verbal and written communication skills.
  • Role will likely include periodic large project-oriented demands with tight deadlines requiring more than standard work hours and the need to respond quickly.
  • Must demonstrate sound business judgment.

Sharing rewards is an integral part of our culture. We believe in the value of hard work and reward our employees beyond the paycheck. Our total rewards package is based on eligibility and includes:

Financial Benefits
  • Competitive Compensation
  • Monthly Bonuses for Eligible Employees
  • 401(k) and Company Match
  • Annual Profit Sharing
  • Paid Time Off
Health, Wellbeing, and Family Planning Benefits
  • Paid Vacation - starting at 80 hours annually for employees in their first year of service.
  • Paid Sick Days - Ten (10) per year with a conversion option for unused time.
  • Ten (10) Paid Holidays per year
  • Gym Reimbursement
  • Health Insurance
  • Dental Insurance
  • Vision Insurance
  • Short-Term and Long Term Disability
  • Company Paid Life Insurance
  • Flexible Spending Accounts (FSA)
  • Health Savings Accounts (HSA)
  • Employee Assistance Program
  • Parental Leave
Education and Career Planning Benefits
  • Tuition Assistance
  • Networking Opportunities
  • Leadership Development Opportunities
Perks
  • Paid Parking
  • Service Awards
  • Hybrid work arrangements
  • Business casual environment
  • A strong organizational culture focused on our greatest asset: you!

We value diverse backgrounds and adding new perspectives.

Please note, applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst, GRC
Senior Security Analyst, GRC

GreatAmerica Bank National Association • Cedar Rapids (IA)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangements
Health Insurance
401(k) and Company Match
+1
Security Operations Analyst
Security Operations Analyst

GreatAmerica Financial Services • Cedar Rapids (IA)

On-site
USD 55,000 - 70,000
Hybrid work arrangements
Health Insurance
401(k) and Company Match
+1
Senior Security Analyst, GRC
Senior Security Analyst, GRC

GreatAmerica Financial Services Corporation • Northern (KY)

Hybrid
USD 120,000 - 150,000
Hybrid work arrangements
Paid time off
Health insurance
+1
Security Operations Analyst
Security Operations Analyst

GreatAmerica • Cedar Rapids (IA)

Hybrid
USD 55,000 - 75,000
Paid Parking
Service Awards
Hybrid work arrangements
+2
Security Operations Analyst
Security Operations Analyst

GreatAmerica Financial Services Corporation • Cedar Rapids (IA)

Hybrid
USD 60,000 - 75,000
Health Insurance
401(k) Match
Bonuses
+7
Senior Security Governance and Risk Analyst
Senior Security Governance and Risk Analyst

GreatAmerica Bank National Association • Cedar Rapids (IA)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangements
Health Insurance
401(k) and Company Match
+1
Senior Security & GRC Analyst — Remote
Senior Security & GRC Analyst — Remote

GreatAmerica Financial Services Corporation • Northern (KY)

Hybrid
USD 120,000 - 150,000
Hybrid work arrangements
Paid time off
Health insurance
+1
Director, Data Analytics & Insights
Director, Data Analytics & Insights

GreatAmerica Financial Services Corporation • Cedar Rapids (IA)

Hybrid
USD 140,000 - 200,000
401(k) with company match
Profit sharing
Paid time off
+11
Senior Security Analyst, GRC - Hybrid Impactful Governance
Senior Security Analyst, GRC - Hybrid Impactful Governance

GreatAmerica Financial Services • Cedar Rapids (IA)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangements
Monthly Bonuses for Eligible Employees
401(k) and Company Match
+15
Senior Governance, Risk, & Compliance Analyst
Senior Governance, Risk, & Compliance Analyst

Jobgether • United States

On-site
USD 58,000 - 222,000
Medical, dental, vision insurance
Flexible work environment
Paid time off
+1