> Markdown version of [/jobs/ext/1863373-cybersecurity-senior-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1863373-cybersecurity-senior-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Senior GRC Analyst - **Company:** UGI Corporation - **Location:** Denver, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems Security Architecture Professional, Smartsuite, RSA (Cryptosystem), Information Technology, Servicenow - **Published:** July 1, 2026 - **Apply:** https://www.juju.com/job/00000000gcgkem ## About the Role + Bachelor's degree in Information Security, Risk Management, Computer Science, or related field, required. + 4+ years of experience in GRC, risk management, or compliance roles. Skills and Competencies: + Strong understanding of GRC tools and platforms (e.g., RSA Archer, ServiceNow GRC, Fusion). + Familiarity with risk management frameworks (e.g., NIST 800, COBIT, FAIR) and compliance standards. + Exceptional analytical, problem-solving, and organizational skills. + Strong written and verbal communication skills, with the ability to interact effectively with stakeholders at all levels. + Certifications such as CISA, CRISC, CISSP, CMMC, or PCI preferred. Key Attributes: + Attention to detail and ability to manage multiple priorities. + Proactive mindset with a focus on continuous improvement. + Collaborative team player who can influence without authority. ## Description The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance obligations while managing risk effectively. The GRC Cybersecurity Senior Analyst will report directly to the Global Cybersecurity Risk Manager. This role involves collaborating with cross-functional teams to design, implement, and maintain governance, risk, and compliance processes for UGI Utilities Inc. cybersecurity regulatory requirements. The ideal candidate is detail-oriented, analytical, and experienced in compliance, risk management frameworks, and governance best practices., Governance: + Track UGI Utilities, Inc. compliance to the cybersecurity regulatory requirements (i.e., TSA, PUC, etc.) + Through collaboration assist with tracking the maintenance of processes and procedure documentation that supports the compliance to regulatory requirements. + Assist with the review of policies and standards through collaborating with stakeholders. + Collaborate with stakeholders to establish and track metrics for UGI Utilities, Inc. cybersecurity regulatory governance programs. + Collaborate with stakeholders who monitor regulatory requirements and monitor industry developments to ensure compliance with changes. Risk Management: + Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc.) to measure regulatory compliance for required internal and external assessments related to UGI Utilities, Inc. + Track all gaps from internal and external assessments to completion. Compliance: + Create awareness of compliance to company policies and standards and regulatory requirements through monitoring and reporting. + Collaborate with IT stakeholders to monitor UGI Utilities, Inc. cybersecurity exceptions and other IT operational activities that may have gaps. Collaboration and Reporting: + Partner with IT, Legal, HR, Enterprise Risk Management and other departments to ensure alignment on risk and compliance efforts. + Collaborate with stakeholders to ensure they have operational metrics to monitor their compliance. + Collaborate with the Cybersecurity GRC team to deliver regular risk and compliance metrics for the IT senior leadership. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)