Grc Analyst- Corp. IT Security - Firstbank Pr

FirstBank Puerto RicoSan Juan, PR

About The Position

Responsible for assessing, prioritizing, reporting, and driving the remediation of cybersecurity, technology, and compliance risks across the Corporation. Support the design, implementation, and continuous improvement of governance, risk, and compliance programs aligned with regulatory requirements, industry standards, and business objectives. Partner with cross-functional stakeholders, including Finance, Legal, Audit, Human Resources, and Technology teams, to implement security and compliance initiatives, strengthen risk management practices, and ensure the protection of the Corporation’s assets and technology environment. Apply recognized frameworks and standards such as ISO 27001, NIST, GLBA, and SOX to enhance the organization’s overall security and compliance posture.

Requirements

  • A Bachelor’s degree in Information Systems or Computer Science related field.
  • At least three (3) to five (5) years of experience in a similar job.
  • Bilingual Communication Excellence: Communicates complex risk and security concepts clearly in both English and Spanish to diverse stakeholders.
  • Advanced Technical Proficiency: Effectively analyzes and validates technical controls using strong knowledge of systems and security tools.
  • Information Security Framework Expertise: Applies leading frameworks (COBIT, ISO 27001, NIST) to design, assess, and improve security and compliance programs.
  • Collaboration and Leadership Skills: Drives cross-functional collaboration and influences stakeholders to strengthen risk and compliance outcomes.
  • Adaptability in High-Performance Environments: Performs effectively under pressure while managing multiple priorities in fast-paced environments.
  • Analytical & Problem-Solving Skills: Identifies risks and control gaps using strong analytical thinking and delivers practical, risk-based solutions.
  • Advanced Microsoft Office Skills: Produces data-driven insights and professional reports using advanced Microsoft Office tools.
  • Organizational & Prioritization Skills: Manages tasks efficiently through strong organization, attention to detail, and prioritization.
  • Risk & Compliance Mindset: Integrates governance, risk, and compliance principles into business decisions and operational processes.

Nice To Haves

  • CISA certification is preferred but not required.

Responsibilities

  • Assist the GRC Manager in maintaining the GRC Program from end-to-end.
  • Support the Governance, Risk, and Compliance (GRC) program by maintaining and enhancing information security policies, procedures, standards, and governance practices in alignment with regulatory requirements, internal policies, and industry best practices.
  • Assist in the development, monitoring, and reporting of the Information Security Program, including security metrics, KRIs, dashboards, scorecards, self-assessments, and reporting to management, committees, and the Board of Directors.
  • Conduct risk assessments, identify information security and technology-related risks, recommend mitigation strategies, and track remediation efforts to ensure timely and effective risk resolution.
  • Coordinate and support internal audits, external audits, and regulatory examinations by providing documentation, evidence, subject matter expertise, and follow-up on findings, observations, and corrective action plans.
  • Monitor the remediation of technology, cybersecurity, and business audit findings, ensuring accountability, management commitment, and successful closure of identified deficiencies.
  • Review and monitor IT security controls, access management processes, and governance activities to support ongoing compliance, quality assurance, and operational effectiveness.
  • Maintain vendor governance documentation and support third-party risk management activities in accordance with Vendor Management and Information Security requirements.
  • Assist with security awareness initiatives, special projects, vendor evaluations, and continuous improvement efforts that strengthen the organization's cybersecurity and compliance posture.
  • Participates in special projects and research as it relates to Corporate Security, including assessing current relationships, the need for request for proposals (RFPs), and coordinating upgrades to current, or transition to new vendors.
  • Performs special tasks in order to assist internal, external auditors and regulators in their procedures.
  • Performs other tasks as requested by the GRC Manager.
  • Performs/Supports highly technical tasks such as: Systems and procedures review and implementation, Policies Awareness training, Special Investigations (Forensic), Root Cause Analysis Process.
  • Perform other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service