Senior Cybersecurity GRC Analyst

Eliassen Group
King of Prussia, PA, United States
14 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$80,000.0 - $105,000.0
Working hours
Regular working hours

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Supervisory Control and Data Acquisition (SCADA) Smartsuite RSA (Cryptosystem) Information Technology Process Control Systems Operational Systems Servicenow

Job description

Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within a critical infrastructure environment. This role is responsible for helping ensure compliance with cybersecurity regulatory requirements, monitoring risk remediation activities, supporting governance programs, and collaborating across business and technology teams to strengthen cybersecurity maturity. The ideal candidate will have a background in GRC, cybersecurity compliance, and risk management, with hands-on experience supporting Operational Technology (OT), SCADA, Industrial Control Systems (ICS), and critical infrastructure environments. This individual will partner with Information Technology, Legal, Enterprise Risk Management, Human Resources, and business stakeholders to drive compliance, governance, and cybersecurity risk reduction initiatives. Candidates must be able to work on-site four days, * Track compliance to cybersecurity regulatory requirements such as TSA and PUC.

  • Assist with maintaining processes and procedure documentation that supports regulatory compliance.
  • Support the review of policies and standards in collaboration with stakeholders.
  • Collaborate to establish and track metrics for cybersecurity regulatory governance programs.
  • Support development and maintenance of cybersecurity governance frameworks for OT and SCADA, aligning with standards including NERC CIP, IEC 62443, and NIST SP 800-82.
  • Collaborate with stakeholders to monitor regulatory changes and industry developments.
  • Track activities including tabletop exercises, architecture design reviews, TSA Cybersecurity Action Plan, and biennial cybersecurity audits.
  • Track gaps from internal and external assessments to completion.
  • Assist with tracking risk assessments and remediation for OT/SCADA systems, including ICS, PLCs, and remote monitoring infrastructure.
  • Create awareness of compliance to company policies, standards, and regulatory requirements through monitoring and reporting.
  • Collaborate with IT stakeholders to monitor cybersecurity exceptions and other IT operational activities that present gaps.
  • Partner with IT, Legal, HR, and Enterprise Risk Management to align risk and compliance efforts.
  • Ensure stakeholders have operational metrics to monitor their compliance.
  • Deliver regular risk and compliance metrics for IT senior leadership in partnership with the Cybersecurity GRC team.

Requirements

a week in the Denver/Lancaster, PA area and must demonstrate real-world experience supporting, assessing, governing, or auditing OT/SCADA/ICS environments., * 4+ years of experience in GRC, risk management, or compliance roles.

  • Strong understanding of GRC tools and platforms such as RSA Archer, ServiceNow GRC, or Fusion.
  • Familiarity with frameworks and standards including NIST 800 series, COBIT, and FAIR.
  • Proven experience supporting, assessing, governing, or auditing OT/SCADA/ICS environments.
  • Analytical, problem-solving, and organizational skills.
  • Written and verbal communication skills with stakeholder engagement capability.
  • Certifications such as CISA, CRISC, CISSP, CMMC, or PCI preferred.

Education Requirements:

  • Bachelor’s degree in Information Security, Risk Management, Computer Science, or related field.

Benefits & conditions

This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.

Salary: $80,000 - $105,000/ yr. w2, Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.

W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.

If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.

About the company

Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all