The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation, maintenance, and responsibilities for multiple information security disciplines such as security policy, awareness and education, risk management, and regulatory compliance. This role coordinates enterprise-wide risk assessment, risk remediation, continuous monitoring, and IT compliance documentation and reporting efforts. The analyst also coordinates the development and implementation of enterprise-wide information security policies, standards, and guidance in alignment with relevant compliance regimes, institutional strategies, and industry best practices. They manage the creation and dissemination of regular enterprise-wide information security awareness and training efforts through multiple communication channels, and determine and document information security requirements and controls necessary for the protection of information resources. The role implements and administers plans, processes, and procedures necessary to ensure compliance with regulatory frameworks, and provides guidance and assistance regarding information security matters such as the interpretation of information security policies and requirements or their applicability to particular situations. The Senior IT GRC Analyst manages detailed network, operating system, database, and application compliance assessments and security configuration audits, and manages and participates in information security projects and initiatives. They support, maintain, monitor, troubleshoot, and enhance security infrastructure tools, methodologies, software, and hardware. Additionally, they analyze data from Information Security functions and provide reports and recommended response actions to Information Security management. The role represents Information Security to other organizations on information security related matters, as assigned, and publishes regular status reports for management. This is an experienced cybersecurity professional role, typically obtained through advanced education and work experience, working independently with minimal supervision. The analyst leads other team members through specific tasks and provides guidance, and stands in for department leadership when they are unavailable. Responsibilities typically include establishing operational plans for the job area and developing and implementing new products, processes, standards, or operational plans that will have an impact on the achievement of functional results. Problems faced are difficult to complex, requiring communication with cybersecurity and IT leadership and occasional communication with senior leadership across the enterprise. This role specifically supports compliance monitoring of secure research environments and projects involving Controlled Unclassified Information (CUI), participates in research cybersecurity and export control reviews to assess compliance with approved safeguards and data protection requirements, and provides guidance and training on secure data handling practices, access controls, and research cybersecurity expectations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior