> Markdown version of [/jobs/ext/1183113-cybersecurity-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1183113-cybersecurity-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Analyst - **Company:** Western National Group - **Location:** Edina, MN, United States (Remote available) - **Experience:** Experienced - **Salary:** $66,300.0 - $114,290.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Control Objectives for Information and Related Technology (COBIT), CompTIA Security+, Cyber Security, Executive Information Systems, Microsoft Office, Microsoft PowerPoint, Phishing, Performance Monitor, CIS Benchmarks - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f45d1fcab0d8e4fb ## About the Role What are the must-have qualifications for a candidate? * Two-plus years of experience in governance, risk, and compliance (GRC); compliance; cybersecurity; or security awareness roles. * Strong understanding of security and regulatory frameworks, such as NIST CSF, CIS Controls, COBIT, and similar standards. * Experience supporting regulatory audits, evidence collection, or third-party compliance assessments. * Experience conducting vendor security risk assessments and documenting remediation activities. * Strong understanding of governance, risk, and compliance concepts. * Excellent organizational, written, verbal, and interpersonal communication skills. * Proficient use of Microsoft Office applications, including Excel, PowerPoint, and Word. * Ability to analyze information, identify trends, and communicate recommendations effectively. * Bachelor's degree in communications, business, or a related field or equivalent relevant experience. What will our ideal candidate have? * Experience using governance, risk, and compliance platforms, such as Drata, Vanta, OneTrust, or Archer. * Knowledge of state insurance regulations and compliance reporting requirements. * Experience developing or leading security awareness and phishing simulation programs. * Experience supporting vendor management or third-party security review processes. * Experience developing executive dashboards and security performance reporting. * Professional certifications, such as CompTIA Security+, CISA, CRISC, or other governance, risk, and compliance-related credentials. * Experience within the insurance, financial services, or healthcare industry. ## Description * Supports insurance-related regulatory compliance by maintaining audit-ready documentation and coordinating timely and accurate regulatory filings across multiple states. * Partners with vendor management, legal, and business stakeholders to integrate security requirements throughout the vendor lifecycle. * Performs security risk assessments of third-party vendors and service providers and tracks remediation activities. * Maintains the vendor risk register and monitors progress toward risk mitigation objectives. * Serves as the Information Security Team's primary point of contact for state insurance departments, auditors, and compliance-related inquiries. * Designs, coordinates, and executes the organization's security awareness training program. * Develops targeted awareness campaigns focused on phishing, social engineering, and secure behaviors across the organization. * Creates and distributes security awareness communications, including newsletters, alerts, and announcements. * Tracks training participation, measures program effectiveness, and recommends continuous improvements. * Maps existing security controls to recognized frameworks, such as NIST Cybersecurity Framework (CSF), CIS Controls, and NYDFS requirements. * Conducts security framework gap assessments and develops recommendations to improve organizational maturity. * Supports evidence collection for internal audits, regulatory reviews, and annual maturity assessments. * Defines, tracks, and reports key risk indicators (KRIs) and key performance indicators (KPIs) for the information security program. * Develops dashboards and reports that provide leadership visibility into security compliance, awareness, incident response, and program performance. * Assists information security leadership with executive reporting and board presentation materials. * Exercises sound judgment when identifying compliance gaps, prioritizing work, and escalating security risks. * Recommends process improvements that strengthen governance, documentation, compliance activities, and security awareness efforts. * Consistently acts according to our customer experience standards, including responding quickly, maintaining a positive attitude, building rapport, demonstrating empathy, managing the customer's expectations, using the proper communication channel for the situation, and taking ownership to ensure the customer's issue is resolved. * Performs special projects and other duties as assigned. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)