Sr Security (GRC) Analyst

Georgia-Pacific
Atlanta, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Atlanta, United States of America

Tech stack

Data analysis
Computer Security
Information Systems Security Architecture Professional
Information Technology Security Auditing
Information Technology
Multiplatform

Job description

The Senior Cyber Security GRC Analyst helps operationalize and mature a comprehensive enterprise Governance, Risk & Compliance capability. This role coordinates security activities with GP operating units and third-party infrastructure providers in a complex, multi-business, multi-platform IT environment. You will be a working team member focused on security frameworks; the cyber security program, policies, and standards; defining and refining security metrics and dashboards; managing the cyber security risk register and risk profile; audit and assurance activities; security awareness; and vendor risk assessment processes.

This role can be based in either our Wichita, KS HQ or GP HQ in Atlanta, GA. This is a hybrid role which requires more time in the office than out which typically translates to minimum 3x in office per week.

Our Team

The GP GRC team is a small but dynamic group dedicated to managing the security and compliance of our organization. Our key objectives include performing and tracking risk analysis, operationalizing cyber security standards, and operating a cyber awareness capability. We work collaboratively, continuously improving our processes and procedures, and you will help shape the future of our company's security posture.

What You Will Do

  • Align the GP cyber security program to standard industry security frameworks, regulations, and best practices
  • Collaborate to develop cyber dashboards and meaningful security metrics to monitor cyber posture and communicate risks to senior leadership
  • Maintain, operationalize, and mature security policies, standards, and procedures
  • Develop and mature the ongoing security audit program to monitor and verify the effectiveness of security; analyze data, develop trend analysis, and ensure compliance with existing standards, policies, and procedures
  • Conduct risk assessments for third-party and internally developed products, keeping assessments moving to timely, well-documented closure and providing accurate status to stakeholders throughout
  • Monitor regulatory compliance as required (CFATS, MTSA, GDPR, PCI)
  • Work with GP cyber customers to identify business needs and tailor risk assessments to business risk profiles
  • Help mature GP cyber awareness, tabletop simulation, and security review capabilities

Requirements

  • Experience in cybersecurity, information technology, or a closely related technical field, with a working understanding of core cybersecurity concepts and how they affect business operations
  • Experience translating technical information into clear updates, documentation, or presentations for both technical and non-technical audiences
  • Experience building working relationships and partnering across teams to gather information, align stakeholders, and move work forward without direct authority
  • Experience independently managing multiple concurrent assignments to completion within committed timelines - including tracking your own progress, proactively surfacing at-risk deadlines, and following through without being prompted
  • Experience quickly learning unfamiliar technology, processes, or subject area and becoming effective in it
  • Hands-on experience assessing risk, analyzing complex problems, or auditing processes
  • Must have legal authorization to work permanently in the United States for any employer without requiring a visa transfer or visa sponsorship

What Will Put You Ahead

  • Experience with one or more security frameworks (e.g., NIST CSF, ISO 27001, etc.) and experience applying them to evaluate controls and risk
  • Experience conducting cybersecurity risk assessments for third-party or internally developed products and driving them through to closure
  • Experience recording risk findings, decisions, and closure rationale in a risk register or GRC platform such as ZenGRC, OneTrust, or similar tools
  • Experience converting cybersecurity concepts into practical risk actions, control expectations, process improvements, or governance decisions
  • Industry security certifications such as Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), or Global Information Assurance Certification (GIAC)

About the company

All Koch companies value diversity of thought, perspectives, aptitudes, experiences, and backgrounds. We are Military Ready and Second Chance employers. Learn more about our hiring philosophy here., As a Koch company and a leading manufacturer of bath tissue, paper towels, paper-based packaging, cellulose, specialty fibers, building products and much more, Georgia-Pacific works to meet evolving needs of customers worldwide with quality products. In addition to the products we make, we operate one of the largest recycling businesses. Our more than 30,000 employees in over 150 locations are empowered to innovate every day - to make everyday products even better. At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.

Apply for this position