freehire launches on Product Hunt on 26 August.

Follow →

Security GRC Analyst

Open 17d
The work we do has an impact on millions of lives, and you can be a part of it.
We help protect our customers against life’s uncertainties. Regardless of where you work within the company, you’ll be helping provide protection and peace of mind when our customers need it most.

The Security Risk Analyst supports the organization’s Information Security Risk Management program by executing many cyber risk functions such as regulatory compliance, 3rd Party, and security awareness activities under the direction of security leadership. This role focuses on ensuring adherence to regulatory requirements, industry standards, and internal policies through collaboration with compliance, legal, and technology teams.

The analyst applies strong analytical skills, attention to detail, and effective communication to perform risk assessments, maintain security policies, and assist with compliance initiatives. They help track program performance, prepare reports for leadership, and contribute recommendations for improvement. Additionally, the analyst promotes a collaborative environment by sharing insights and supporting organizational security objectives.

Key Responsibilities:

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS, including documenting findings and driving mitigation strategies across systems, processes, and infrastructure.

  • Demonstrated technical acumen in analyzing vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives.

  • Develop and execute security awareness programs, including training, phishing simulations, newsletters, and communications to drive behavioral change and risk reduction.

  • Deliver actionable reporting and insights, including assessment results, GRC metrics, dashboards, and executive-level presentations summarizing risk posture, control effectiveness, and program maturity.

  • Perform end-to-end cyber third-party risk assessments, including vendor risk assessments, onboarding/offboarding processes, and embedding a shift-left security approach across the vendor lifecycle—particularly for high-risk and complex engagements.

  • Drive process and tooling optimization, contributing to GRC platform design, standardizing workflows, and improving operational consistency and scalability.

  • Support governance and control management, including developing and maintaining policies, standards, and control libraries aligned to regulatory requirements and industry best practices.

  • Enable audit readiness and due diligence, managing evidence collection, standardizing responses, and maintaining repositories for external audits and third-party inquiries.

  • Stay current on evolving regulations, frameworks, and industry trends, incorporating updates into practices and controls.

  • Manage priorities and execution using Agile methodologies, including tracking tasks, resolving issues, escalating risks, and providing timely status updates.

Required Skills & Expertise:

  • Bachelor’s degree in Cybersecurity, Information Systems, or related field. 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.

  • Working knowledge of regulatory frameworks, audit processes, and control environments, including familiarity with industry standards and risk management terminology.

  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts, with the ability to support risk identification, assessment, and mitigation activities.

  • General knowledge of security tools and controls across domains such as network security, endpoint protection, email security, vulnerability management, access controls, and log management; foundational understanding of cloud service models (IaaS, SaaS, PaaS).

  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI; able to translate metrics into actionable insights for leadership.

  • Experience contributing to continuous improvement of GRC programs, including identifying enhancements and presenting recommendations to leadership.

  • Experience developing and delivering training materials, with strong written and verbal communication skills to effectively engage technical and business stakeholders.

  • Strong organizational, analytical, and multitasking abilities, with a demonstrated ability to manage competing priorities and collaborate effectively across teams.

Preferred Qualifications:

  • Strong consideration for experience with cloud security compliance (Azure/AWS).

  • Experience with Microsoft Office Suite; familiarity with tools such as SharePoint, Power BI, ServiceNow, UpGuard, or Archer.

  • Achieved certifications such as: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, CIDSP, Security+

Employee Benefits:
We aim to protect the wellbeing of our employees and their families with a broad benefits offering. In addition to offering comprehensive health, dental and vision insurance, we support emotional wellbeing through mental health benefits and an employee assistance program. Work/life balance is important and Protective offers a variety of paid time away benefits (e.g., paid time off, paid parental leave, short-term disability, and a cultural observance day). The financial health of our employees is just as important as physical and emotional health. Some of the financial wellbeing benefits include contributions to healthcare accounts, a pension plan, and a 401(k) plan with Company matching. All employees are encouraged to protect their overall wellbeing by engaging in ProHealth Rewards, Protective’s platform to improve wellbeing while earning cash rewards.

Eligibility for certain benefits may vary by position in accordance with the terms of the Company’s benefit plans.

Accommodations for Applicants with a Disability:
If you require an accommodation to complete the application and recruitment process due to a disability, please email eric.hess@protective.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application and recruitment process.

Please note that the above email is solely for individuals with disabilities requesting an accommodation. General employment questions should not be sent through this process.

We are proud to be an equal opportunity employer committed to being inclusive and attracting, retaining, and growing an inclusive workforce.

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, GitHub URL, Portfolio/video resume URL, Other website

  • As part of any recruiting and hiring process, Protective collects and processes personal information relating to job applicants. The Company is committed to being transparent about how it collects and uses that information and to meeting its information protection obligations. In the recruitment and hiring process the “personal information” we collect includes: General Identifying and Contact Information (e.g., name, mailing address, phone number, email address), Employment History Information, Education History Information. Please be aware that the personal information you provide during the application process may be shared internally with employees of Protective as well as our designated third-party vendors for the purposes of the recruitment and hiring process, including contacting you regarding your application and assessing your qualifications for job openings with Protective. California applicants should review the state-specific notice provided in accordance with the California Privacy Rights Act. By clicking “Consent” below you understand and freely give your consent to Protective and our designated third-party vendors collecting and processing your personal information relating to your potential employment with Protective. Applicant Notice - California: As part of Protective’s commitment to transparency related to personal information, and in order to comply with the California Privacy Rights Act (“CPRA”), we are providing you with this disclosure regarding the categories of personal information we may collect from you and the purposes for which that information may be used. Information We Collect: In the recruitment and hiring process the categories of “personal information” we collect include: General Identifying and Contact Information (e.g., name, mailing address, phone number, email address), Employment History Information, Education History Information. Use of Personal Information: The personal information we collect during the application process is used to assess your qualifications for the purposes of the recruitment and hiring process, including contacting your regarding your application and assessing your qualifications for job openings with Protective. The personal information you provide will not be “sold to” or “shared with” a third-party as those terms are defined by the CPRA. The Company will not collect additional categories of personal information or use the personal information we collect for materially different, unrelated, or incompatible purposes without providing you notice. Retention of Information: Each of the categories of information you provide are subject to our internal policies on retaining employee and applicant information. These policies are based on applicable legal retention requirements for retaining personal information of applicants and/or employees. As part of our internal policies, we have a process in place to determine when this information is no longer needed and can be disposed of in a secure manner. Additional Information: For more information on your rights under the CPRA, please see the Company’s California Privacy Rights Act Policy. yes / no · optional
  • Are you legally authorized to work in the United States? choose one
  • Do you now, or will you in the future, require immigration sponsorship for work authorization (e.g., H-1B)? choose one
  • Have you ever been employed with Protective or one of its affiliates? choose one
  • What is your target compensation (salary and bonus)?
  • Do you have any family members who are employed with Protective? written answer
  • How did you hear about this opportunity? choose one · optional
  • Please describe a cybersecurity risk assessment that you personally conducted (or would conduct) for a business application, vendor, or technology service. In your response, explain: 1. How you identified and evaluated the risks 2. What framework(s) or control standards you used (e.g., NIST CSF, NIST 800-53, CIS Controls, SOC 2) 3. How you determined the risk rating or severity 4. What remediation recommendations you made 5. How you communicated findings to technical and business stakeholders 6. The outcome or risk reduction achieved (if applicable) written answer

See also