
Principal Security Analyst – Governance, Risk, and Compliance
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Lead the security risk quantification program and process to facilitate informed decision-making throughout the organization.
• Convey security risks by developing Key Risk Indicators (KRIs) and reporting to various stakeholder groups, including the Executive Leadership Team (ELT) and the Board of Directors.
• Create, evaluate, and implement cybersecurity controls and procedures necessary to safeguard the confidentiality, integrity, and availability of Blackbaud data.
• Oversee and coordinate both internal and external security, compliance, and regulatory assessments, which include customer audits, independent attestations, certification audits, and third-party reviews. Act as the primary liaison with assessors and stakeholders to ensure the successful execution of assessment activities and remediation efforts.
• Serve as a key participant in corporate governance forums and committees, actively advocating for cybersecurity practices, risk management, and adherence to policies.
• Collaborate with control owners to consistently monitor control implementations, evaluate their effectiveness, and manage noncompliance issues until resolved.
• Improve change management processes to promote, communicate, and educate stakeholders regarding updates to policies, standards, and procedures.
• Identify opportunities to enhance and mature the organization's governance, risk, and compliance programs through ongoing improvement initiatives and adherence to industry best practices.
• Over 8 years of experience in Information Technology and/or Security.
• More than 3 years of experience in leading audit/assessment projects.
• At least 3 years of experience with risk management frameworks (e.g., NIST CSF).
• Over 2 years of experience in quantitative risk management frameworks (FAIR, OCTAVE, etc.).
• Familiarity with corporate GRC solutions (Archer, ServiceNow, etc.).
• Experience in financial services or other highly regulated sectors (e.g., SOX, SOC, PCI DSS).
• Experience working within an agile team environment.
• Proven understanding of cyber risks and the development of mitigation plans.
• Strong communication and presentation skills.
• Capability to manage multiple priorities and high-pressure situations.
• Possession of industry certifications such as CISSP, CRISC, CISM/CISA, AWS certification(s), or Azure certification(s).
• Medical, dental, and vision insurance.
• Flexible remote work options.
• Wellness programs.
• 401(k) program with employer matching.
• Flexible paid time off.
• Generous parental leave policy.
• Donations for doers program.
• Pet insurance and legal/identity protection services.
• Tuition reimbursement program.
The Home Depot
Lennar
Golden 1 Credit Union
NuHarbor Security
Get handpicked remote jobs straight to your inbox weekly.