
Cybersecurity GRC Analyst
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in United States.
• Oversee and enhance the institutional cybersecurity risk program.
• Keep the risk register updated and document identified risks.
• Create and monitor Plans of Action and Milestones (POA&Ms).
• Collaborate with system and data owners to coordinate corrective actions.
• Conduct cybersecurity risk evaluations for new solutions, services, and technology acquisitions.
• Process and prioritize risk review requests.
• Execute or facilitate security risk assessments, including evaluations of third-party vendors.
• Utilize HECVAT, SOC 2 reports, and similar assurance documents during vendor assessments.
• Record findings and provide recommendations.
• Forward risk acceptance and approval decisions to the appropriate authority.
• Map and uphold cybersecurity controls in compliance with NIST SP 800-171, CIS Controls, FERPA, HIPAA, CJIS, PCI, GLBA Safeguards Rule, and additional standards.
• Formulate, review, and sustain cybersecurity policies, standards, procedures, and guidelines.
• Supervise compliance and facilitate audit readiness, including evidence collection and documentation.
• Act as a liaison with internal and external auditors as well as regulatory bodies.
• Oversee cybersecurity exception and risk acceptance processes.
• Lead periodic risk reviews and address overdue items.
• Coordinate the remediation of audit, risk assessment, and compliance findings.
• Develop metrics, dashboards, and reports for cybersecurity.
• Spearhead initiatives for cybersecurity awareness and training, which includes phishing simulations, campaigns, onboarding, annual education, and role-specific training.
• Support cybersecurity engagement and outreach efforts, including a network of cybersecurity champions.
• Generate reports, briefings, and presentations for executive leadership and governance committees.
• Utilize artificial intelligence and automation to refine analysis, reporting, workflows, and the overall operations of the cybersecurity program.
• Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or a comparable combination of education and experience.
• A minimum of five years of professional experience in cybersecurity, IT risk management, compliance, or support for information security programs.
• Familiarity with audit preparation and evidence documentation practices.
• Understanding of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and relevant regulatory requirements.
• Proficiency in cybersecurity risk assessment methodologies and security control frameworks.
• Experience in maintaining risk registers, POA&Ms, or tracking corrective actions, as well as supporting risk acceptance or exception processes.
• Capability to analyze cybersecurity risks and propose practical mitigation strategies.
• Proficiency in developing policies, procedures, and governance documentation.
• Skill in creating reports, dashboards, and metrics for leadership and governance audiences.
• Excellent written communication abilities, particularly in policy documentation and executive-level reporting.
• Ability to effectively collaborate with both technical and non-technical stakeholders.
• Proven experience using AI-assisted tools or automation to enhance security workflows, processes, or reporting.
• Familiarity with the responsible implementation of artificial intelligence and automation in professional settings, including essential data protection considerations.
• U.S. work authorization that does not necessitate employer sponsorship now or in the future.
• Must not need visa sponsorship or OPT extensions at any stage.
• The selected candidate will be subject to appropriate background screenings.
• A cover letter and resume or curriculum vitae are required.
• Three professional references may be requested from finalists.
• Comprehensive health benefits, encompassing medical, dental, vision, flexible spending accounts (FSA), and Health Savings Account (HSA) options.
• Employer-funded basic life insurance and long-term disability coverage, with additional voluntary coverage options available.
• Retirement plan through TIAA featuring a 10% employer contribution and opportunities for further tax-deferred retirement savings.
• Generous paid time off, including vacation and sick leave.
• 13 paid holidays annually.
• Tuition waiver program for employees, covering graduate courses and Maine Law.
• Significant tuition discounts for eligible spouses and dependent children.
• Employee Assistance Program (EAP) available.
• Wellness programs offered.
• Opportunities for professional development and career advancement within Maine's public university system.
• Pet insurance available.
• Discounts on home and auto insurance.
• Options for supplemental disability and life insurance.
CNA Insurance
SysMap Solutions
Get handpicked remote jobs straight to your inbox weekly.