> Markdown version of [/jobs/ext/3224561-cybersecurity-grc-analyst](https://www.wearedevelopers.com/jobs/ext/3224561-cybersecurity-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Analyst - **Company:** University of Maine - **Location:** Orono, United States (Remote available) - **Experience:** Starter - **Salary:** $65,000.0 - $75,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Artificial Intelligence, Applications Architecture, Bioinformatics, Delphi (Programming Language), Cyber Security, Information Systems, Internet Security, Machine Learning, OpenShift, Systems Development Life Cycle, Release Management, Anti-Phishing, Software Systems, SQL Databases, Software Vulnerability Management, Information Technology, RSA Archer Platform, CIS Benchmarks, Servicenow, Microservices - **Published:** September 2, 2026 - **Apply:** https://fa-ewca-saasfaprod1.fa.ocs.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/jobs/preview/3058 ## About the Role * Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or an equivalent combination of education and experience. * Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support. * Experience with audit preparation and evidence documentation practices. * Knowledge of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and applicable regulatory requirements. * Knowledge of cybersecurity risk assessment methodologies and security control frameworks. * Experience maintaining risk registers, POA&Ms, or corrective action tracking, and supporting risk acceptance or exception processes. * Ability to analyze cybersecurity risks and develop practical mitigation recommendations. * Ability to develop policies, procedures, and governance documentation. * Ability to develop reports, dashboards, and metrics for leadership and governance audiences. * Strong written communication skills, including policy documentation and executive-level reporting. * Ability to collaborate effectively with both technical and nontechnical stakeholders. * Demonstrated use of AI-assisted tools or automation to improve security workflows, processes, or reporting. * Familiarity with the responsible use of artificial intelligence and automation in professional environments, including appropriate data protection considerations. Preferred Qualifications * Relevant governance, risk, compliance, audit, or privacy certifications, such as: + CISA - Certified Information Systems Auditor + CRISC - Certified Risk and Information Systems Control + CGRC - Certified in Governance, Risk, and Compliance + CISM - Certified Information Security Manager + CIPP - Certified Information Privacy Professional + CIPM - Certified Information Privacy Manager * Certification or professional development related to artificial intelligence, automation, or emerging technologies. * Experience working in higher education, the public sector, a multi-campus organization, or another complex enterprise IT environment. * Experience supporting cybersecurity governance, risk management, and compliance programs. * Experience with GRC platforms such as ServiceNow GRC, Isora GRC, OneTrust, or Archer, and familiarity with HECVAT for vendor security reviews. * Experience coordinating internal and external cybersecurity awareness and training programs. * Experience designing or implementing automation solutions that improve workflows, reporting, or operational efficiency. ## Description Manage cybersecurity governance, risk, and compliance activities across a university system. Maintain risk registers, POA&Ms, controls, policies, exceptions, and audit evidence; conduct vendor and solution risk reviews; coordinate remediation; develop metrics and executive reports; and lead security awareness, phishing simulation, training, and outreach programs. Apply cybersecurity frameworks and regulatory requirements while using AI and automation to improve workflows and reporting. The summary above was generated by AI The University of Maine System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join our Information Security team. This position plays an important role in protecting the information, systems, and data that support Maine's public universities. The GRC Analyst will help advance the University of Maine System's cybersecurity governance framework, risk management processes, regulatory compliance efforts, and security awareness program. Working across Information Technology, academic departments, administrative units, and with external partners, the Cybersecurity GRC Analyst will coordinate cybersecurity risk and compliance activities, support audit readiness, develop and maintain policies and controls, and help strengthen a culture of shared responsibility for cybersecurity throughout the University of Maine System. This is an excellent opportunity for a cybersecurity professional who enjoys connecting technical security requirements with policy, risk management, compliance, communication, and organizational strategy. This is a fully remote position, open to candidates who live and are authorized to work in the United States. Standard hours are Monday through Friday, 8:00 AM to 4:30 PM ET, with occasional evening or weekend work as needs arise. What You'll Do: * Manage and support the institutional cybersecurity risk program, including maintaining the risk register, documenting risks, developing and tracking Plans of Action and Milestones (POA&Ms), and coordinating corrective actions with systems and data owners. * Manage the cybersecurity risk review process for new solutions, services, and technology acquisitions, including intake and triage of risk review requests, conducting or coordinating security risk assessments (including third-party and vendor reviews using the Higher Education Community Vendor Assessment Toolkit (HECVAT), Standard and Organization Controls (SOC) 2 reports, and similar assurance documentation), documenting findings and recommendations, and routing risk acceptance and approval decisions to the appropriate authority. * Map and maintain cybersecurity controls against applicable frameworks and regulatory requirements, including National Institute of Standards and Technology Special Publication (NIST SP 800-171), Center for Internet Security (CIS) Controls, Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS), Payment Card Industry (PCI), the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, and other relevant standards. * Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines. * Monitor compliance with cybersecurity policies and regulatory obligations and coordinate audit readiness activities, including evidence collection and documentation. * Serve as a liaison with internal and external auditors and regulatory entities. * Manage cybersecurity exception and risk acceptance processes, including documentation, approvals, and periodic reviews. * Facilitate periodic risk reviews with risk and system owners, including re-review of accepted risks and expiring exceptions, and escalate overdue items for decision. * Coordinate remediation of findings identified through audits, risk assessments, and compliance reviews. * Develop cybersecurity metrics, dashboards, and reports that support operational monitoring, executive decision-making, and governance. * Lead the development and administration of cybersecurity awareness and training initiatives, including phishing simulations, enterprise-wide campaigns, onboarding and annual education, and role-based training. * Support cybersecurity engagement and outreach efforts, including a cybersecurity champions network and other initiatives that promote shared responsibility for security. * Prepare reports, briefings, and presentations for executive leadership and governance bodies regarding cybersecurity risks, compliance posture, and program effectiveness. * Leverage artificial intelligence and automation to improve analysis, reporting, workflows, and cybersecurity program operations. What We Are Looking For: The successful candidate will bring knowledge of cybersecurity governance, risk management, and compliance principles along with the ability to translate complex security requirements into practical policies, processes, recommendations, and communications., Materials must be submitted via "Apply Now" below. You will need to complete an application and upload the following: * A cover letter that describes your experience, interests, and suitability for the position. * A resume or curriculum vitae. Important items to know about the recruitment process: Review of applications will begin immediately. The position will remain open until filled. For full consideration, applications must be submitted by September 13, 2026. * Incomplete application materials cannot be considered. * Candidates selected to proceed to the final stages of the search process will be requested to provide three (3) names and contact information for references. * The successful applicant is subject to appropriate background screenings., Lead customer implementations of SOPHiA GENETICS genomic analysis solutions, from planning and sample selection through configuration, training, adoption, and issue resolution. Manage MaxCare Program schedules, timelines, sampling strategies, Statements of Work, technical setup, and cross-functional delivery. Translate laboratory, bioinformatics, data, and clinical regulatory requirements into practical solutions while building trusted customer relationships. The field-based US role includes approximately 30% travel. Top Skills: BioinformaticsCustom ReportingFederated Sso AuthenticationLibrary PreparationNext-Generation SequencingSophia Ddm Platform PNC Bank Software Engineer 2 Hours Ago Remote or Hybrid USA 75K-150K Annually Junior 75K-150K Annually Junior Machine Learning * Payments * Security * Software * Financial Services Develops, tests, deploys, maintains, and debugs software across the full project lifecycle. Translates business requirements into technical designs, supports production systems, documents solutions, estimates development tasks, collaborates with teammates, and mentors newer developers. The role requires application architecture, SDLC, testing, troubleshooting, and maintenance experience using Java, .NET, and/or Delphi, with Delphi preferred. Top Skills: .NetDelphiJava PNC Bank Senior Software Engineer 2 Hours Ago Remote or Hybrid USA Senior level Senior level Machine Learning * Payments * Security * Software * Financial Services Designs, develops, tests, deploys, maintains, and debugs software solutions. Leads complex technical initiatives, Java microservices and API integration, OpenShift deployments, server and database administration, release management, production support, vulnerability remediation, incident resolution, and vendor coordination. Supports remote deposit platforms while managing application resiliency, security compliance, documentation, and stakeholder communication. Top Skills: AgileAPIsCandescent Remote Deposit/CaptureCloud-Native ArchitecturesConnect:DirectContainerizationDevOpsJavaLinuxMicroservicesMicrosoft Sql ServerOpenshift Container PlatformPowershellPythonSdlcShell ScriptingWindows Server What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute ## Related Videos - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [From Zero to Hero: Launch & Manage Your Cloud Apps with Free OpenShift & Red Hat Developer Hub](https://www.wearedevelopers.com/videos/1023-from-zero-to-hero-launch-manage-your-cloud-apps-with-free-openshift-red-hat-developer-hub) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)