远程工作雷达

安全GRC分析师

Security GRC Analyst

开发工程未标注地域
公司protective
薪资未公开
工作地点Work From Home
地域资格未标注地域
时区要求无特别要求
用工类型Full Time
发布时间未知
数据来源Lever
前往企业招聘页投递 →

我们的工作影响数百万人的生活,你可以成为其中一员。
我们帮助客户抵御生活中的不确定性。无论你在公司哪个部门工作,你都将帮助客户在最需要的时候获得保障和安心。

安全风险分析师在安全领导的指导下,通过执行多种网络风险职能(如监管合规、第三方和安全意识活动),支持组织的信息安全风险管理计划。该职位专注于通过与合规、法律和技术团队合作,确保遵守监管要求、行业标准和内部政策。

分析师运用强大的分析技能、细致的关注和有效的沟通能力,进行风险评估、维护安全政策并协助合规计划。他们跟踪项目表现,为管理层准备报告,并提出改进建议。此外,分析师通过分享见解和支持组织的安全目标,促进协作环境。

员工福利:
我们通过广泛的福利计划来保护员工及其家庭的福祉。除了提供全面的健康、牙科和视力保险外,我们还通过心理健康福利和员工援助计划支持员工的情绪健康。工作与生活的平衡很重要,Protective 提供多种带薪休假福利(例如带薪假期、带薪育儿假、短期残疾和文化纪念日)。员工的财务健康与身体和情绪健康同样重要。一些财务福利包括医疗账户的贡献、养老金计划和有公司匹配的 401(k) 计划。所有员工都被鼓励通过参与 ProHealth Rewards(Protective 的平台)来改善整体健康状况,同时赚取现金奖励。

某些福利的资格可能因职位不同而有所差异,具体以公司福利计划条款为准。

残疾人申请者的工作安排:
如果您因残疾需要在申请和招聘过程中获得工作安排,请发送邮件至 eric.hess@protective.com。此信息将被保密,并仅用于确定适当的安排。

查看英文原文

The work we do has an impact on millions of lives, and you can be a part of it.
We help protect our customers against life’s uncertainties. Regardless of where you work within the company, you’ll be helping provide protection and peace of mind when our customers need it most.

The Security Risk Analyst supports the organization’s Information Security Risk Management program by executing many cyber risk functions such as regulatory compliance, 3rd Party, and security awareness activities under the direction of security leadership. This role focuses on ensuring adherence to regulatory requirements, industry standards, and internal policies through collaboration with compliance, legal, and technology teams.

The analyst applies strong analytical skills, attention to detail, and effective communication to perform risk assessments, maintain security policies, and assist with compliance initiatives. They help track program performance, prepare reports for leadership, and contribute recommendations for improvement. Additionally, the analyst promotes a collaborative environment by sharing insights and supporting organizational security objectives.

Employee Benefits:  
We aim to protect the wellbeing of our employees and their families with a broad benefits offering. In addition to offering comprehensive health, dental and vision insurance, we support emotional wellbeing through mental health benefits and an employee assistance program. Work/life balance is important and Protective offers a variety of paid time away benefits (e.g., paid time off, paid parental leave, short-term disability, and a cultural observance day). The financial health of our employees is just as important as physical and emotional health.  Some of the financial wellbeing benefits include contributions to healthcare accounts, a pension plan, and a 401(k) plan with Company matching. All employees are encouraged to protect their overall wellbeing by engaging in ProHealth Rewards, Protective’s platform to improve wellbeing while earning cash rewards.

Eligibility for certain benefits may vary by position in accordance with the terms of the Company’s benefit plans.

Accommodations for Applicants with a Disability:
If you require an accommodation to complete the application and recruitment process due to a disability, please email eric.hess@protective.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application and recruitment process.

Please note that the above email is solely for individuals with disabilities requesting an accommodation.  General employment questions should not be sent through this process.

We are proud to be an equal opportunity employer committed to being inclusive and attracting, retaining, and growing an inclusive workforce.

Key Responsibilities:

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, including documenting findings and driving mitigation strategies across systems, processes, and infrastructure.
  • Demonstrated technical acumen in analyzing vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives.
  • Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications to drive behavioral change and risk reduction.
  • Deliver actionable reporting and insights, including assessment results, GRC metrics, dashboards, and executive-level presentations summarizing risk posture, control effectiveness, and program maturity.
  • Perform end-to-end cyber third-party risk assessments, including vendor risk assessments, onboarding/offboarding processes, and embedding a shift-left security approach across the vendor lifecycle—particularly for high-risk and complex engagements.
  • Drive process and tooling optimization, contributing to GRC platform design, standardizing workflows, and improving operational consistency and scalability.
  • Support governance and control management, including developing and maintaining policies, standards, and control libraries aligned to regulatory requirements and industry best practices.
  • Enable audit readiness and due diligence, managing evidence collection, standardizing responses, and maintaining repositories for external audits and third-party inquiries.
  • Stay current on evolving regulations, frameworks, and industry trends, incorporating updates into practices and controls.
  • Manage priorities and execution using Agile methodologies, including tracking tasks, resolving issues, escalating risks, and providing timely status updates.

Required Skills & Expertise:

  • Bachelor’s degree in Cybersecurity, Information Systems, or related field. 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.
  • Working knowledge of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk management terminology.
  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation activities.
  • General knowledge of security tools and controls across domains such as network security, endpoint protection, email security, vulnerability management, access controls, and log management; foundational understanding of cloud service models (IaaS, SaaS, PaaS).
  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI; able to translate metrics into actionable insights for leadership.
  • Experience contributing to continuous improvement of GRC programs, including identifying enhancements and presenting recommendations to leadership.
  • Experience developing and delivering training materials, with strong written and verbal communication skills to effectively engage technical and business stakeholders.
  • Strong organizational, analytical, and multitasking abilities, with a demonstrated ability to manage competing priorities and collaborate effectively across teams.

Preferred Qualifications:

  • Strong consideration for experience with cloud security compliance (Azure/AWS).
  • Experience with Microsoft Office Suite; familiarity with tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer.
  • Achieved certifications such as: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, Security+
本页面信息整理自 Lever,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位