As the Senior Cybersecurity Analyst, GRC, you will be an integral member of the Governance, Risk and Compliance team within the Cybersecurity Department. Essential Functions: Develop and maintain core Governance, risk and compliance artifacts, including GRC program charter, cybersecurity service catalog and related documentation Establish and mature a cybersecurity metrics and reporting program, including cybersecurity metrics program charter, process, governance, and structure for metrics and data collection, developing reports and dashboards, and partner with control owners to analyze and report metrics Provide subject matter expertise on common control frameworks and lead efforts to create, improve, and monitor cybersecurity controls. Develop and maintain standards and SOPs (standard operating procedures) for third party risk management, solution risk assessments, exception management, and other GRC processes Conduct detailed security risk assessments (vendor and solution), and mature security risk assessment process including questionnaire development, workflow optimization in ServiceNow, risk analysis, and issue identification Produce high quality risk assessment reports and deliver readouts to business unit leaders, translating technical risks to clear business impacts and recommendations Review and analyze vendor cybersecurity documentation, including SIG questionnaires, SOC2 Type II, and other assurance artifacts Lead the end‑to‑end cybersecurity exception management process, including intake, validation, risk analysis, documentation, and routing for approval. Lead the design, development, and implementation of a consistent cyber risk treatment and monitoring process, including defining workflows, documenting standard and SOP, treatment plan requirements, and governance routines. Lead the risk treatment and monitoring activities, including maintaining the cyber risk register, validating risk scoring, tracking remediation progress, and ensuring risks are updated, reviewed, and closed in alignment with governance requirements. Work with control owners, system owners, SMEs, other internal and external resources to gather data, develop and oversee risk treatment options and action plans, to help drive and achieve results for technology related assessment findings and exception requests. Lead cybersecurity projects and initiatives, including project planning, stakeholder engagement, and progress reporting to leadership. Leverage and expand ServiceNow GRC capabilities to automate workflows, improve data quality, and enhance reporting
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
1,001-5,000 employees