Vulnerability Management & GRC Analyst

Selective Insurance

Short Hills (NJ)

On-site

USD 116,000 - 157,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

comprehensive health care plans
retirement savings plan with company  
Employee Stock Purchase Program
tuition assistance and reimbursement
20 days of paid time off

Job summary

Selective Insurance is seeking a GRC/Third-Party Risk and Vulnerability Management Analyst in New Jersey. You will perform governance, risk, and compliance activities, coordinate vendor due diligence, and support audit requirements.

The role emphasizes evidence validation, remediation tracking, and clear reporting to stakeholders. Ideal candidates will have 3–5 years of GRC or related experience, familiarity with NIST and SOX controls, and strong communication skills.

Qualifications

  • Working knowledge of cybersecurity, risk management, compliance, vulnerability management, audit, or third-party risk concepts.
  • Ability to evaluate security evidence and identify incomplete information to flag risk.
  • Strong attention to detail and ability to manage multiple assessments concurrently.
  • Clear written and verbal communication for business stakeholders.
  • Proficiency with Microsoft Office; experience with GRC, vendor risk, vulnerability management, ticketing, or reporting tools is preferred.

Responsibilities

  • Execute GRC activities including risk documentation, control mapping, and evidence tracking.
  • Coordinate policy and procedure lifecycle updates and validation of evidence.
  • Prepare materials for governance forums, risk reviews, audits, and compliance reporting.
  • Coordinate vendor assessments, due diligence, and stakeholder communications through closure.
  • Review vendor questionnaires, SOC/ISO reports, penetration test summaries, and other artifacts for risk relevance.
  • Document assessment conclusions, remediation items, and residual risk in line with TPRM procedures.
  • Track remediation status, exceptions, and aging issues; validate ownership and progress with stakeholders.
  • Contribute to metrics on risk, vendor status, vulnerability remediation, and documentation completeness.
  • Assist with audit findings remediation, control gaps, risk acceptances, and compliance actions.

Skills

Cybersecurity
Risk management
Compliance
Vulnerability management
Audit
Third-party risk
Documentation
Communication
GRC tools
Reporting tools

Education

Bachelor's degree in a related field

Tools

GRC software
Ticketing tools
Reporting tools

Job description

Selective Insurance is seeking a GRC/Third-Party Risk and Vulnerability Management Analyst in New Jersey. You will perform governance, risk, and compliance activities, coordinate vendor due diligence, and support audit requirements.

The role emphasizes evidence validation, remediation tracking, and clear reporting to stakeholders. Ideal candidates will have 3–5 years of GRC or related experience, familiarity with NIST and SOX controls, and strong communication skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management & GRC Analyst
Vulnerability Management & GRC Analyst

Selective Insurance • Hartford (CT)

On-site
USD 116,000 - 157,000
Comprehensive health care plans
Retirement plan with company match
Tuition assistance
+1
Senior GRC Analyst: Risk & Compliance
Senior GRC Analyst: Risk & Compliance

Selective Insurance • Charlotte (NC)

On-site
USD 116,000 - 157,000
Health insurance
401(k) with company match
Tuition assistance
+1
Senior GRC & Risk Compliance Analyst
Senior GRC & Risk Compliance Analyst

Selective Insurance • Hartford (CT)

On-site
USD 116,000 - 157,000
Health care plans
Retirement plan with company match
Employee Stock Purchase Program
+2
Manager, Cybersecurity Risk and Compliance
Manager, Cybersecurity Risk and Compliance

The Judge Group • Trenton (NJ)

Hybrid
USD 140,000 - 170,000
Health benefits and insurance
PTO
401k
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Sr. GRC Analyst (Hybrid)
Sr. GRC Analyst (Hybrid)

Selective Insurance • Hartford (CT)

On-site
USD 116,000 - 157,000
Comprehensive health care plans
Retirement plan with company match
Tuition assistance
+1
Vendor Risk & GRC Analyst (Third-Party Security)
Vendor Risk & GRC Analyst (Third-Party Security)

Anthropic • San Francisco (CA)

On-site
USD 255,000 - 270,000
Competitive compensation
Equity options
Flexible hours
+1
Senior GRC Manager - Cyber Risk & Compliance (Hybrid NJ)
Senior GRC Manager - Cyber Risk & Compliance (Hybrid NJ)

The Judge Group • Trenton (NJ)

Hybrid
USD 140,000 - 170,000
Health benefits and insurance
PTO
401k
GRC Analyst: Third-Party Risk & Vendor Oversight
GRC Analyst: Third-Party Risk & Vendor Oversight

United States Digital Space LLC • Boston (MA)

On-site
USD 70,000 - 110,000