Back to List

This role requires candidates who are currently authorized to work in the U.S. without sponsorship, and C2C arrangements are not accepted. This role is on-site.

 

Job Summary
The Senior Security & Governance Analyst role is responsible for leading the development, implementation, communication, and maintenance of enterprise technology policies, standards, and procedures that align with industry frameworks and regulatory requirements. This role ensures technology processes comply with applicable regulations, effectively manage risk, and maintain strong governance practices. Responsibilities include developing controls, monitoring compliance, and supporting broader risk management initiatives.

Responsibilities

  • Lead the creation, enhancement, and implementation of cybersecurity and IT policies, standards, and guidelines.

  • Continuously review and update policies to ensure they remain current, effective, and aligned with emerging threats and regulatory changes.

  • Ensure compliance with relevant laws, regulations, and industry frameworks (e.g., NIST, FFIEC, GLBA, NYDFS, SOX, PCI-DSS).

  • Partner with IT, Legal, Compliance, and business stakeholders to ensure cybersecurity policies support organizational objectives.

  • Translate complex technical and regulatory information into clear, easy-to-understand language for end users.

  • Provide expertise to support framework-based risk assessments, identify control gaps, develop reports, and recommend prioritized remediation actions.

  • Stay informed on evolving cybersecurity threats, industry trends, and best practices.

  • Maintain accurate documentation of policy reviews, assessments, training activities, and incident response actions.

  • Benchmark internal policies against industry standards to identify improvement opportunities.

  • Develop and maintain governance frameworks to support cybersecurity and IT policy management.

  • Monitor key performance indicators, conduct gap analyses, perform risk assessments, and evaluate control effectiveness.

  • Establish feedback loops and analyze metrics, audit findings, and incident patterns to strengthen policies and procedures.

  • Lead and support internal and external audits related to cybersecurity governance; ensure findings and remediation efforts are tracked to closure.

  • Maintain comprehensive records of all cybersecurity policies, procedures, and governance activities; communicate updates across the organization.

  • Identify opportunities for improving cybersecurity governance and risk practices and validate the effectiveness of remediation plans.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field (preferred).

  • 6+ years of experience in Cybersecurity GRC, policy development, risk management, or similar domains.

  • Experience using GRC platforms (e.g., Archer, ServiceNow, OneTrust).

  • Proficiency with data and reporting tools (e.g., Excel, Power BI).

  • Relevant certifications such as CISM, CISA, or comparable credentials are highly desirable.

Apply to this Job
First Name *
Last Name *
Email

Phone

Yes
No