{"schemaVersion":"jobsearcher.job.v1","id":"2cec87dbdf294afa8b7b841d","url":"https://jobsearcher.com/jobs/2cec87dbdf294afa8b7b841d","canonicalUrl":"https://jobsearcher.com/jobs/2cec87dbdf294afa8b7b841d","title":"Security GRC Analyst","description":"The work we do has an impact on millions of lives, and you can be a part of it.\nWe help protect our customers against life’s uncertainties. Regardless of where you work within the company, you’ll be helping provide protection and peace of mind when our customers need it most.\n\nThe Security Risk Analyst supports the organization’s Information Security Risk Management program by executing many cyber risk functions such as regulatory compliance, 3rd Party, and security awareness activities under the direction of security leadership. This role focuses on ensuring adherence to regulatory requirements, industry standards, and internal policies through collaboration with compliance, legal, and technology teams.\nThe analyst applies strong analytical skills, attention to detail, and effective communication to perform risk assessments, maintain security policies, and assist with compliance initiatives. They help track program performance, prepare reports for leadership, and contribute recommendations for improvement. Additionally, the analyst promotes a collaborative environment by sharing insights and supporting organizational security objectives.\nKey Responsibilities:\nPerform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, including documenting findings and driving mitigation strategies across systems, processes, and infrastructure.\nDemonstrated technical acumen in analyzing vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives.\nDevelop and execute security awareness programs, including training, phishing simulations, newsletters, and communications to drive behavioral change and risk reduction.\nDeliver actionable reporting and insights, including assessment results, GRC metrics, dashboards, and executive-level presentations summarizing risk posture, control effectiveness, and program maturity.\nPerform end-to-end cyber third-party risk assessments, including vendor risk assessments, onboarding/offboarding processes, and embedding a shift-left security approach across the vendor lifecycle—particularly for high-risk and complex engagements.\nDrive process and tooling optimization, contributing to GRC platform design, standardizing workflows, and improving operational consistency and scalability.\nSupport governance and control management, including developing and maintaining policies, standards, and control libraries aligned to regulatory requirements and industry best practices.\nEnable audit readiness and due diligence, managing evidence collection, standardizing responses, and maintaining repositories for external audits and third-party inquiries.\nStay current on evolving regulations, frameworks, and industry trends, incorporating updates into practices and controls.\nManage priorities and execution using Agile methodologies, including tracking tasks, resolving issues, escalating risks, and providing timely status updates.\nRequired Skills & Expertise:\nBachelor’s degree in Cybersecurity, Information Systems, or related field. 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.\nWorking knowledge of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk management terminology.\nUnderstanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation activities.\nGeneral knowledge of security tools and controls across domains such as network security, endpoint protection, email security, vulnerability management, access controls, and log management; foundational understanding of cloud service models (IaaS, SaaS, PaaS).\nProven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI; able to translate metrics into actionable insights for leadership.\nExperience contributing to continuous improvement of GRC programs, including identifying enhancements and presenting recommendations to leadership.\nExperience developing and delivering training materials, with strong written and verbal communication skills to effectively engage technical and business stakeholders.\nStrong organizational, analytical, and multitasking abilities, with a demonstrated ability to manage competing priorities and collaborate effectively across teams.\nPreferred Qualifications:\n\nStrong consideration for experience with cloud security compliance (Azure/AWS).\nExperience with Microsoft Office Suite; familiarity with tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer.\nAchieved certifications such as: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, Security+\nProtective’s targeted salary range for this position is $70,000 to $77,000. Actual salaries may vary depending on factors, including but not limited to, job location, skills, and experience. The range listed is just one component of Protective’s total compensation package for employees.\nEmployee Benefits:\nWe aim to protect the wellbeing of our employees and their families with a broad benefits offering. In addition to offering comprehensive health, dental and vision insurance, we support emotional wellbeing through mental health benefits and an employee assistance program. Work/life balance is important and Protective offers a variety of paid time away benefits (e.g., paid time off, paid parental leave, short-term disability, and a cultural observance day). The financial health of our employees is just as important as physical and emotional health. Some of the financial wellbeing benefits include contributions to healthcare accounts, a pension plan, and a 401(k) plan with Company matching. All employees are encouraged to protect their overall wellbeing by engaging in ProHealth Rewards, Protective’s platform to improve wellbeing while earning cash rewards.\n\nEligibility for certain benefits may vary by position in accordance with the terms of the Company’s benefit plans.\n\nAccommodations for Applicants with a Disability:\nIf you require an accommodation to complete the application and recruitment process due to a disability, please email eric.hess@protective.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application and recruitment process.\n\nPlease note that the above email is solely for individuals with disabilities requesting an accommodation. General employment questions should not be sent through this process.\n\nWe are proud to be an equal opportunity employer committed to being inclusive and attracting, retaining, and growing an inclusive workforce.\nWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.","company":"Protective","rawCompany":"protective","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-05T00:13:59.498Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security GRC Analyst","description":"The work we do has an impact on millions of lives, and you can be a part of it.\nWe help protect our customers against life’s uncertainties. Regardless of where you work within the company, you’ll be helping provide protection and peace of mind when our customers need it most.\n\nThe Security Risk Analyst supports the organization’s Information Security Risk Management program by executing many cyber risk functions such as regulatory compliance, 3rd Party, and security awareness activities under the direction of security leadership. This role focuses on ensuring adherence to regulatory requirements, industry standards, and internal policies through collaboration with compliance, legal, and technology teams.\nThe analyst applies strong analytical skills, attention to detail, and effective communication to perform risk assessments, maintain security policies, and assist with compliance initiatives. They help track program performance, prepare reports for leadership, and contribute recommendations for improvement. Additionally, the analyst promotes a collaborative environment by sharing insights and supporting organizational security objectives.\nKey Responsibilities:\nPerform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, including documenting findings and driving mitigation strategies across systems, processes, and infrastructure.\nDemonstrated technical acumen in analyzing vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives.\nDevelop and execute security awareness programs, including training, phishing simulations, newsletters, and communications to drive behavioral change and risk reduction.\nDeliver actionable reporting and insights, including assessment results, GRC metrics, dashboards, and executive-level presentations summarizing risk posture, control effectiveness, and program maturity.\nPerform end-to-end cyber third-party risk assessments, including vendor risk assessments, onboarding/offboarding processes, and embedding a shift-left security approach across the vendor lifecycle—particularly for high-risk and complex engagements.\nDrive process and tooling optimization, contributing to GRC platform design, standardizing workflows, and improving operational consistency and scalability.\nSupport governance and control management, including developing and maintaining policies, standards, and control libraries aligned to regulatory requirements and industry best practices.\nEnable audit readiness and due diligence, managing evidence collection, standardizing responses, and maintaining repositories for external audits and third-party inquiries.\nStay current on evolving regulations, frameworks, and industry trends, incorporating updates into practices and controls.\nManage priorities and execution using Agile methodologies, including tracking tasks, resolving issues, escalating risks, and providing timely status updates.\nRequired Skills & Expertise:\nBachelor’s degree in Cybersecurity, Information Systems, or related field. 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.\nWorking knowledge of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk management terminology.\nUnderstanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation activities.\nGeneral knowledge of security tools and controls across domains such as network security, endpoint protection, email security, vulnerability management, access controls, and log management; foundational understanding of cloud service models (IaaS, SaaS, PaaS).\nProven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI; able to translate metrics into actionable insights for leadership.\nExperience contributing to continuous improvement of GRC programs, including identifying enhancements and presenting recommendations to leadership.\nExperience developing and delivering training materials, with strong written and verbal communication skills to effectively engage technical and business stakeholders.\nStrong organizational, analytical, and multitasking abilities, with a demonstrated ability to manage competing priorities and collaborate effectively across teams.\nPreferred Qualifications:\n\nStrong consideration for experience with cloud security compliance (Azure/AWS).\nExperience with Microsoft Office Suite; familiarity with tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer.\nAchieved certifications such as: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, Security+\nProtective’s targeted salary range for this position is $70,000 to $77,000. Actual salaries may vary depending on factors, including but not limited to, job location, skills, and experience. The range listed is just one component of Protective’s total compensation package for employees.\nEmployee Benefits:\nWe aim to protect the wellbeing of our employees and their families with a broad benefits offering. In addition to offering comprehensive health, dental and vision insurance, we support emotional wellbeing through mental health benefits and an employee assistance program. Work/life balance is important and Protective offers a variety of paid time away benefits (e.g., paid time off, paid parental leave, short-term disability, and a cultural observance day). The financial health of our employees is just as important as physical and emotional health. Some of the financial wellbeing benefits include contributions to healthcare accounts, a pension plan, and a 401(k) plan with Company matching. All employees are encouraged to protect their overall wellbeing by engaging in ProHealth Rewards, Protective’s platform to improve wellbeing while earning cash rewards.\n\nEligibility for certain benefits may vary by position in accordance with the terms of the Company’s benefit plans.\n\nAccommodations for Applicants with a Disability:\nIf you require an accommodation to complete the application and recruitment process due to a disability, please email eric.hess@protective.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application and recruitment process.\n\nPlease note that the above email is solely for individuals with disabilities requesting an accommodation. General employment questions should not be sent through this process.\n\nWe are proud to be an equal opportunity employer committed to being inclusive and attracting, retaining, and growing an inclusive workforce.\nWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.","datePosted":"2026-08-05T00:13:59.498Z","dateModified":"2026-08-05T00:13:59.498Z","hiringOrganization":{"@type":"Organization","name":"Protective","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2cec87dbdf294afa8b7b841d"},"url":"https://jobsearcher.com/jobs/2cec87dbdf294afa8b7b841d"}}