Governance, Risk and Compliance (GRC) Analyst
Summary
Support NIS2 and other cybersecurity framework compliance (ISO 27001, TISAX) at Emerson through gap assessments, remediation tracking, audit coordination, and stakeholder communication in an information security governance role.
If you are a Governance, Risk and Compliance (GRC) Analyst professional looking for an opportunity to grow your career, this is an exciting opportunity to help strengthen Emerson’s cybersecurity and compliance programs. In this role, you will support and maintain compliance with the European Union Network and Information Security Directive (NIS2) while partnering with stakeholders across the organization to assess, implement, coordinate, and monitor information security activities. You will play a key role in identifying compliance gaps, supporting remediation efforts, enhancing cybersecurity governance, and contributing to broader security initiatives, including ISO 27001, TISAX, and other information security frameworks.
- Support NIS2 assessments across the organization by evaluating information security controls, processes, and practices.
- Document security controls, coordinate evidence collection, and help maintain ongoing compliance with NIS2 requirements.
- Identify compliance gaps and collaborate with stakeholders to develop and track remediation plans that mitigate risk.
- Partner with teams across Emerson to implement and sustain security measures aligned with regulatory and business requirements.
- Monitor progress toward compliance objectives and help ensure remediation activities are completed effectively and on schedule.
- Prepare and present compliance status updates, risks, and program initiatives to leadership and key stakeholders.
- Support internal and external audits related to NIS2 and other cybersecurity frameworks.
- Deliver training sessions, awareness activities, and guidance on NIS2 requirements and information security best practices.
- Stay informed on regulatory changes and emerging requirements to help maintain ongoing compliance.
- Coordinate audit preparation activities, including scheduling, stakeholder engagement, evidence collection, and participant readiness.
- Review audit findings, track corrective actions, and report on remediation progress.
- Contribute to control assurance and compliance initiatives that enhance the organization’s overall cybersecurity posture.
- Support information security framework assessments, management system implementations, gap remediation efforts, and continuous improvement initiatives across multiple cybersecurity standards and frameworks.
- Experience in information security, governance, compliance, risk management, or a related field.
- Knowledge of cybersecurity principles, controls, standards, and regulatory requirements.
- Experience supporting or participating in assessments, audits, or compliance initiatives involving frameworks such as NIS2, ISO 27001, TISAX, or similar standards.
- Ability to identify control gaps, evaluate risks, and support the development of practical remediation plans.
- Strong communication and collaboration skills with the ability to work effectively across diverse teams and stakeholder groups.
- Ability to organize, coordinate, and manage multiple priorities while maintaining attention to detail.
- Experience coordinating evidence collection, compliance documentation, or audit activities.
- Demonstrated ability to interpret requirements and translate them into actionable business and security practices.
- Fluency in English.
- Ability to travel up to 20% as business needs require.
- A degree in Information Technology, Information Systems, Computer Science, Cybersecurity, or a related field, or equivalent combination of education, training, and relevant experience.
- Experience supporting internal or external audit programs.
- Familiarity with cybersecurity governance, risk management, and compliance programs in multinational organizations.
- Experience working with multiple information security frameworks and regulatory requirements.
- Knowledge of control assurance methodologies and continuous improvement practices.
- Proficiency in one or more additional European languages.
- Relevant industry certifications related to cybersecurity, information security, auditing, governance, risk management, or compliance.