Cybersecurity GRC Analyst

University of Maine SystemUnited States,
$65,000 - $75,000Remote

About The Position

The University of Maine System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join their Information Security team. This role is crucial for protecting the information, systems, and data supporting Maine's public universities. The GRC Analyst will advance the University of Maine System's cybersecurity governance framework, risk management processes, regulatory compliance efforts, and security awareness program. This position involves coordinating cybersecurity risk and compliance activities across various departments and with external partners, supporting audit readiness, developing and maintaining policies and controls, and fostering a culture of shared cybersecurity responsibility. It is an ideal opportunity for a cybersecurity professional who enjoys bridging technical security requirements with policy, risk management, compliance, communication, and organizational strategy.

Requirements

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or an equivalent combination of education and experience.
  • Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support.
  • Experience with audit preparation and evidence documentation practices.
  • Knowledge of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and applicable regulatory requirements.
  • Knowledge of cybersecurity risk assessment methodologies and security control frameworks.
  • Experience maintaining risk registers, POA&Ms, or corrective action tracking, and supporting risk acceptance or exception processes.
  • Ability to analyze cybersecurity risks and develop practical mitigation recommendations.
  • Ability to develop policies, procedures, and governance documentation.
  • Ability to develop reports, dashboards, and metrics for leadership and governance audiences.
  • Strong written communication skills, including policy documentation and executive-level reporting.
  • Ability to collaborate effectively with both technical and nontechnical stakeholders.
  • Demonstrated use of AI-assisted tools or automation to improve security workflows, processes, or reporting.
  • Familiarity with the responsible use of artificial intelligence and automation in professional environments, including appropriate data protection considerations.

Nice To Haves

  • Relevant governance, risk, compliance, audit, or privacy certifications, such as: CISA - Certified Information Systems Auditor, CRISC - Certified Risk and Information Systems Control, CGRC - Certified in Governance, Risk, and Compliance, CISM - Certified Information Security Manager, CIPP - Certified Information Privacy Professional, CIPM - Certified Information Privacy Manager
  • Certification or professional development related to artificial intelligence, automation, or emerging technologies.
  • Experience working in higher education, the public sector, a multi-campus organization, or another complex enterprise IT environment.
  • Experience supporting cybersecurity governance, risk management, and compliance programs.
  • Experience with GRC platforms such as ServiceNow GRC, Isora GRC, OneTrust, or Archer, and familiarity with HECVAT for vendor security reviews.
  • Experience coordinating internal and external cybersecurity awareness and training programs.
  • Experience designing or implementing automation solutions that improve workflows, reporting, or operational efficiency.

Responsibilities

  • Manage and support the institutional cybersecurity risk program, including maintaining the risk register, documenting risks, developing and tracking Plans of Action and Milestones (POA&Ms), and coordinating corrective actions with systems and data owners.
  • Manage the cybersecurity risk review process for new solutions, services, and technology acquisitions, including intake and triage of risk review requests, conducting or coordinating security risk assessments (including third-party and vendor reviews using the Higher Education Community Vendor Assessment Toolkit (HECVAT), Standard and Organization Controls (SOC) 2 reports, and similar assurance documentation), documenting findings and recommendations, and routing risk acceptance and approval decisions to the appropriate authority.
  • Map and maintain cybersecurity controls against applicable frameworks and regulatory requirements, including National Institute of Standards and Technology Special Publication (NIST SP 800-171), Center for Internet Security (CIS) Controls, Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS), Payment Card Industry (PCI), the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, and other relevant standards.
  • Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines.
  • Monitor compliance with cybersecurity policies and regulatory obligations and coordinate audit readiness activities, including evidence collection and documentation.
  • Serve as a liaison with internal and external auditors and regulatory entities.
  • Manage cybersecurity exception and risk acceptance processes, including documentation, approvals, and periodic reviews.
  • Facilitate periodic risk reviews with risk and system owners, including re-review of accepted risks and expiring exceptions, and escalate overdue items for decision.
  • Coordinate remediation of findings identified through audits, risk assessments, and compliance reviews.
  • Develop cybersecurity metrics, dashboards, and reports that support operational monitoring, executive decision-making, and governance.
  • Lead the development and administration of cybersecurity awareness and training initiatives, including phishing simulations, enterprise-wide campaigns, onboarding and annual education, and role-based training.
  • Support cybersecurity engagement and outreach efforts, including a cybersecurity champions network and other initiatives that promote shared responsibility for security.
  • Prepare reports, briefings, and presentations for executive leadership and governance bodies regarding cybersecurity risks, compliance posture, and program effectiveness.
  • Leverage artificial intelligence and automation to improve analysis, reporting, workflows, and cybersecurity program operations.

Benefits

  • Competitive salary: $65,000–$75,000 commensurate with education and experience.
  • Comprehensive health benefits, including medical, dental, vision, flexible spending accounts (FSA), and Health Savings Account (HSA) options
  • Employer-paid benefits, including basic life insurance and long-term disability coverage, with additional voluntary coverage options available
  • Retirement plan through TIAA with 10% employer contribution and opportunities for additional tax-deferred retirement savings
  • Generous paid time off, including vacation and sick leave, plus 13 paid holidays each year
  • Tuition waiver program for employees, including graduate courses and Maine Law, plus substantial tuition discounts for eligible spouses and dependent children
  • Employee Assistance Program (EAP) and wellness programs supporting your health and well-being
  • Professional development and opportunities to grow your career within Maine's public university system
  • Additional voluntary benefits, including pet insurance, home and auto insurance discounts, and supplemental disability and life insurance options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service