Protective Life logo
Protective Life
Posted 73 days agoVerified live 1d ago

Security GRC Analyst

Brief overview

Remote
UndergradOr in progress
$70k–$77k/yrStated range
1+ yrsMinimum
NIST CSFNIST 800-53SOC 2CISVulnerability assessment analysisSecurity awareness program developmentPhishing simulationsGRC metrics reportingThird-party risk managementVendor risk assessmentsGRC platform designSecurity policy developmentAudit readinessAgile methodologiesServiceNowArcherSharePoint

Job description

Summary

Protective Life is dedicated to providing protection and peace of mind to its customers. The Security GRC Analyst supports the organization's Information Security Risk Management program by executing various cyber risk functions and ensuring adherence to regulatory requirements and industry standards.

Responsibilities

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, including documenting findings and driving mitigation strategies across systems, processes, and infrastructure
  • Demonstrated technical acumen in analyzing vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives
  • Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications to drive behavioral change and risk reduction
  • Deliver actionable reporting and insights, including assessment results, GRC metrics, dashboards, and executive-level presentations summarizing risk posture, control effectiveness, and program maturity
  • Perform end-to-end cyber third-party risk assessments, including vendor risk assessments, onboarding/offboarding processes, and embedding a shift-left security approach across the vendor lifecycle—particularly for high-risk and complex engagements
  • Drive process and tooling optimization, contributing to GRC platform design, standardizing workflows, and improving operational consistency and scalability
  • Support governance and control management, including developing and maintaining policies, standards, and control libraries aligned to regulatory requirements and industry best practices
  • Enable audit readiness and due diligence, managing evidence collection, standardizing responses, and maintaining repositories for external audits and third-party inquiries
  • Stay current on evolving regulations, frameworks, and industry trends, incorporating updates into practices and controls
  • Manage priorities and execution using Agile methodologies, including tracking tasks, resolving issues, escalating risks, and providing timely status updates

Skills

  • Bachelor's degree in Cybersecurity, Information Systems, or related field
  • 1-3 years of experience in GRC, risk management, or compliance within cybersecurity
  • Working knowledge of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk management terminology
  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation activities
  • General knowledge of security tools and controls across domains such as network security, endpoint protection, email security, vulnerability management, access controls, and log management; foundational understanding of cloud service models (IaaS, SaaS, PaaS)
  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI; able to translate metrics into actionable insights for leadership
  • Experience contributing to continuous improvement of GRC programs, including identifying enhancements and presenting recommendations to leadership
  • Experience developing and delivering training materials, with strong written and verbal communication skills to effectively engage technical and business stakeholders
  • Strong organizational, analytical, and multitasking abilities, with a demonstrated ability to manage competing priorities and collaborate effectively across teams
  • Strong consideration for experience with cloud security compliance (Azure/AWS)
  • Experience with Microsoft Office Suite; familiarity with tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer
  • Achieved certifications such as: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, Security+

Qualifications

Must Haves

  • Bachelor's degree in Cybersecurity, Information Systems, or related field
  • 1-3 years of experience in GRC, risk management, or compliance within cybersecurity
  • Working knowledge of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk management terminology
  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation activities
  • General knowledge of security tools and controls across domains such as network security, endpoint protection, email security, vulnerability management, access controls, and log management; foundational understanding of cloud service models (IaaS, SaaS, PaaS)
  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI; able to translate metrics into actionable insights for leadership
  • Experience contributing to continuous improvement of GRC programs, including identifying enhancements and presenting recommendations to leadership
  • Experience developing and delivering training materials, with strong written and verbal communication skills to effectively engage technical and business stakeholders
  • Strong organizational, analytical, and multitasking abilities, with a demonstrated ability to manage competing priorities and collaborate effectively across teams

Nice to Haves

  • Strong consideration for experience with cloud security compliance (Azure/AWS)
  • Experience with Microsoft Office Suite; familiarity with tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer
  • Achieved certifications such as: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, Security+

Benefits

  • Comprehensive health, dental and vision insurance
  • Mental health benefits
  • An employee assistance program
  • Variety of paid time away benefits (•e.g.•, paid time off, paid parental leave, short-term disability, and a cultural observance day)
  • Contributions to healthcare accounts
  • A pension plan
  • A 401(k) plan with Company matching
  • Engaging in ProHealth Rewards, Protective’s platform to improve wellbeing while earning cash rewards
  • Eligibility for certain benefits may vary by position in accordance with the terms of the Company’s benefit plans

More jobs like this