The GRC and Privacy Analyst plays a critical role in managing risks related to information technology, information security, privacy, regulatory compliance, and governance. This role ensures that the organization's operations and procedures meet government and industry compliance standards. The analyst will work closely with IT and business units to identify and mitigate security risks, maintain regulatory compliance, and protect digital assets. Conduct gap analysis and implement frameworks and standards such as CRI, PCI-DSS, GLBA, NIST, and SOX. Develop and revise policies, standards, processes, and guidelines for the organization. Conduct vendor risk assessments and ensure compliance with organizational security requirements. Oversee data privacy practices and ensure alignment with regulatory requirements. Support organizational compliance initiatives and the development of governance frameworks. Monitor regulatory changes and promote ethical behavior across the organization. Conduct regular security assessments and penetration testing. Assist in the development and maintenance of identity and access management procedures. Participate in incident response and business continuity planning. Collaborate with cross-functional teams to integrate security controls into business processes. Participate in employee education and awareness programs related to security and privacy. Stay updated on emerging threats, vulnerabilities, and industry best practices. Monitor network traffic and security logs to detect and analyze potential security threats, anomalies, and breaches. Utilize centralized XDR system to identify and respond to unauthorized activities. Collaborate with IT teams to prioritize and remediate vulnerabilities in a timely manner. Participate in technical and non-technical projects requiring security oversight to ensure policies, procedures and standards are met. Assist with investigation and response to security incidents. Coordinate with internal teams to mitigate the impact of security incidents and prevent future occurrences. Participate in employee education events for employees to raise awareness of security threats and security best practice. Participate in periodic IT/IS audits, exams and assessments, as Perform other security-related duties as assigned.