> Markdown version of [/jobs/ext/3309836-lead-cybersecurity-grc-db-bc-analyst](https://www.wearedevelopers.com/jobs/ext/3309836-lead-cybersecurity-grc-db-bc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cybersecurity GRC, DB/BC Analyst - **Company:** University System of New Hampshire - **Location:** Durham, NH, United States - **Experience:** Expert - **Salary:** $69,560.0 - $124,580.0 - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Cyber Security, Disaster Recovery, Issue Tracking Systems, IT Management, PCI Data Security Standards, Anti-Phishing, Data Processing, Information Technology - **Published:** September 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ee04466b69757ac3 ## About the Role * Bachelor's degree and four years of experience in information technology/cybersecurity field or equivalent combination of education and experience. * Experienced in or knowledgeable about a broad range of cybersecurity subject areas * Specific knowledge about IT contingency planning (disaster recovery/business continuity, and incident response) * Demonstrated experience working in managed project teams * Strong organizational skills and attention to detail * Effective oral and written communication skills with demonstrated ability to compose and present material to communicate difficult concepts * Able to develop and present information, ideas and instructions with minimal oversight * Able to exercise sound judgment within generally defined practices and processes with guidance in selecting methods, techniques, and evaluation criteria for obtaining results. * Demonstrated ability to effectively coordinate multiple priorities in a dynamic environment * Effective time management skills demonstrated by successful and timely completion of daily operational tasks * Ability to work both independently and in a team-oriented, collaborative environment, * Experience in higher education. * Certifications related to cybersecurity such as GSEC, SSCP, or Security+ * Experience creating policies or standards within an enterprise IT organization ## Description Cybersecurity Policies & Standards 30% Assist with the development and publication of cybersecurity policies and standards aligned with the NIST Cybersecurity Framework and leveraging the NIST 800-53 and 800-171 control sets. Coordination of ongoing review sessions with key stakeholders and overall program monitoring to ensure all Policies & Standards are maintained appropriately. Draft new and updated policies and standards to maintain currency and applicability to evolving threats, compliance requirements, and business needs. Maintain and oversee an annual cycle and schedule for review of all existing policy and standards. Coordinate cybersecurity policy & standard exception process. Communicate with stakeholders during the process of exception request and review as well as expiration and/or renewal. Maintain all records of exceptions, their associated risks, risk mitigations, and approved durations. Compliance & Risk Management 30% Oversee third-party vendor security assessment & review (SAR) programs and processes. Assist in design, development, and updates of SAR processes. Maintain all records of vendor security reviews and communicate to stakeholders on required updates and renewals. Coordinate contracted risk assessments from outside contractors including scheduling, communication, and recordkeeping involving administrative, academic, and business units and related IT departments and teams. Participate in performing internal risk assessments and risk analysis of USNH systems and services. Assist in management of the risk register including providing periodic reporting of metrics on the scope and potential impact of risks to the organization. Assist with the development of information handling standards and procedures for all regulated information in use across USNH. Build relationships with regulated data subject matter experts at each institution. Assist with other tasks related to safeguarding regulated data across USNH as needed. Assist with development and implementation of disaster recovery and business continuity plans. Assist with setup, coordination, and execution of periodic tests of the plans and processes. Awareness & Training 15% Work with other IT teams as well as administrative, academic, and other business units to develop and deliver cybersecurity training programs, both generic and role-specific, computer-based and in-person. Administer phishing awareness and similar activities including designing and proposing phishing simulations, deploying, and measuring simulated phishing attacks, and tracking and reporting on program metrics. Incident Response 15% Oversee the processes used for record keeping roles during cybersecurity incident response. Contributed to the overall incident response plan, especially related to incident tracking, reporting, and after-action reviews. Assist in the development of incident response training and periodic incident response drills and testing activities Perform incident recording activities during cybersecurity incidents and maintain records needed for compliance, audit, and after-action review. Other duties. 10% Support other information security and information technology projects and initiatives as assigned. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [Decode Your People: Using PCM to Build High-Performance Teams](https://www.wearedevelopers.com/videos/100194-decode-your-people-using-pcm-to-build-high-performance-teams) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)