GRC Cybersecurity Analyst III

ICCUChubbuck, ID
Onsite

About The Position

The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a subject matter expert, mentor to junior staff, and liaison to executive leadership and external stakeholders while advancing ICCU’s mission of Helping Members Achieve Financial Success.

Requirements

  • A bachelor’s degree in Information Assurance, Cyber Security, Computer Science, Computer Information Technology, or similar field of study, or equivalent work experience is required.
  • One Level I certification, One Level II, and One Level III certification from the DoD 8140 (8570) Cyber Workforce Qualification Matrix pertaining to GRC (eg, SSCP, CISSP, CISM, CISA, CRISC, GSEC, CGRC, CCSP, CSSLP, GSE, or equivalent).
  • 9+ years of work experience in roles with significant Information Security duties.
  • 6+ years of work experience in senior level IT technical roles in Security, Infrastructure, Application Development, Operations, Cloud Management, Ecommerce, or similar areas.
  • 3+ years of experience in senior roles with cyber / infosec GRC projects or teams.
  • Proven experience with regulatory compliance and certification programs.
  • Experience in regulated industries such as financial services or healthcare.
  • Familiarity with enterprise risk management (ERM) frameworks.
  • Security Information and Event Management (SIEM) tools for log aggregation, monitoring, and analysis.
  • Vulnerability Scanning Platforms for identifying, reporting, and tracking security weaknesses.
  • Enterprise GRC systems (or equivalent) for assessment distribution and tracking.
  • Internal dashboards (for metrics, assessments, audit readiness, and executive reporting).
  • Familiarity with project management tools.
  • Microsoft Office Suite (Excel, Word).
  • Understanding of cloud technologies and SaaS platforms.
  • Strong leadership, communication, and stakeholder management skills.
  • Ability to manage complex projects and cross‑functional teams.
  • Strategic thinking with strong attention to detail.
  • Ability to simplify complexity and drive results.
  • High sense of urgency and initiative.
  • Ability to work independently and collaboratively.
  • Must be eligible for membership at ICCU to obtain employment.

Nice To Haves

  • A master’s degree or equivalent certificate in information assurance or computer related fields such as Computer Science, Computer Security or Software Development is strongly preferred.
  • A masters degree may substitute for 1 year of required experience.

Responsibilities

  • Lead and execute enterprisewide cyber and information security risk assessments and audits.
  • A primary contributor to setting strategy and direction in strengthening and reinforcing ICCUs technology defenses and identifying and remedying weaknesses and control gaps within the ICCU environment.
  • Manage third‑party cyber risk assessments, vendor reviews, and remediation tracking.
  • Oversee compliance frameworks including NIST CSF, FFIEC, PCI‑DSS, CIS Controls, FedLine, and SWIFT.
  • Develop and maintain IT policies, standards, and procedures aligned with regulatory mandates.
  • Act as lead liaison and coordinator of internal and external IT audits.
  • Build and maintain IT GRC dashboards, risk registers, and executive reports.
  • Scope and draft statements of work and proposals for new IT GRC initiatives.
  • Lead tabletop exercises, Pen Test reviews, and incident response planning in partnership with stakeholders.
  • Provide mentorship and guidance to junior GRC Cybersecurity analysts.
  • Collaborate with IT, Compliance, and Risk teams to align GRC efforts.
  • Serve as a primary IT point of contact for auditors, regulators, and certification bodies.
  • Monitor and report on compliance gaps, risk mitigation plans, and audit readiness.
  • Stay current on regulatory developments, compliance frameworks, and emerging governance risks impacting cybersecurity programs.
  • Support strategic planning and budgeting for GRC tools and capabilities.
  • Other duties as assigned.

Benefits

  • ICCU is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, age, disability, protected veteran status or other characteristics protected by law.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service