Sr Security (GRC) Analyst
Role details
Job location
Tech stack
Job description
The Senior Cyber Security GRC Analyst helps operationalize and mature a comprehensive enterprise Governance, Risk & Compliance capability. This role coordinates security activities with GP operating units and third-party infrastructure providers in a complex, multi-business, multi-platform IT environment. You will be a working team member focused on security frameworks; the cyber security program, policies, and standards; defining and refining security metrics and dashboards; managing the cyber security risk register and risk profile; audit and assurance activities; security awareness; and vendor risk assessment processes.
This role can be based in either our Wichita, KS HQ or GP HQ in Atlanta, GA. This is a hybrid role which requires more time in the office than out which typically translates to minimum 3x in office per week.
Our Team
The GP GRC team is a small but dynamic group dedicated to managing the security and compliance of our organization. Our key objectives include performing and tracking risk analysis, operationalizing cyber security standards, and operating a cyber awareness capability. We work collaboratively, continuously improving our processes and procedures, and you will help shape the future of our company's security posture.
What You Will Do
- Align the GP cyber security program to standard industry security frameworks, regulations, and best practices
- Collaborate to develop cyber dashboards and meaningful security metrics to monitor cyber posture and communicate risks to senior leadership
- Maintain, operationalize, and mature security policies, standards, and procedures
- Develop and mature the ongoing security audit program to monitor and verify the effectiveness of security; analyze data, develop trend analysis, and ensure compliance with existing standards, policies, and procedures
- Conduct risk assessments for third-party and internally developed products, keeping assessments moving to timely, well-documented closure and providing accurate status to stakeholders throughout
- Monitor regulatory compliance as required (CFATS, MTSA, GDPR, PCI)
- Work with GP cyber customers to identify business needs and tailor risk assessments to business risk profiles
- Help mature GP cyber awareness, tabletop simulation, and security review capabilities
Requirements
- Experience in cybersecurity, information technology, or a closely related technical field, with a working understanding of core cybersecurity concepts and how they affect business operations
- Experience translating technical information into clear updates, documentation, or presentations for both technical and non-technical audiences
- Experience building working relationships and partnering across teams to gather information, align stakeholders, and move work forward without direct authority
- Experience independently managing multiple concurrent assignments to completion within committed timelines - including tracking your own progress, proactively surfacing at-risk deadlines, and following through without being prompted
- Experience quickly learning unfamiliar technology, processes, or subject area and becoming effective in it
- Hands-on experience assessing risk, analyzing complex problems, or auditing processes
- Must have legal authorization to work permanently in the United States for any employer without requiring a visa transfer or visa sponsorship
What Will Put You Ahead
- Experience with one or more security frameworks (e.g., NIST CSF, ISO 27001, etc.) and experience applying them to evaluate controls and risk
- Experience conducting cybersecurity risk assessments for third-party or internally developed products and driving them through to closure
- Experience recording risk findings, decisions, and closure rationale in a risk register or GRC platform such as ZenGRC, OneTrust, or similar tools
- Experience converting cybersecurity concepts into practical risk actions, control expectations, process improvements, or governance decisions
- Industry security certifications such as Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), or Global Information Assurance Certification (GIAC)