GRC Security Analyst Job at The Aspen Group (TAG), Chicago, IL

WDh3VXpQUjhDaEhWM3picUV3Mm5laWtUQkE9PQ==
  • The Aspen Group (TAG)
  • Chicago, IL

Job Description

The governance, risk and compliance (GRC) security analyst is a highly respected, influential and in-demand role within the business. The position is responsible supporting the security direction of the business and elevating the company’s security posture. The GRC security analyst is expected to support the security strategy of the business within new and existing information system capabilities. Consequently, the position requires both an understanding of legacy systems, as well as new technologies and requirements. The GRC security analyst is also responsible for the planning and design of policies and maintenance. The ideal candidate is technical and possesses at least three years of experience in security, compliance, or risk management. The role oversees the business’ security requirements and obligations mandated by standards and regulations such as the Sarbanes-Oxley Act (SOX), General Data Protection Regulation (GDPR), Health Information Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI DSS). In tandem with security leadership, the GRC security analyst consistently assesses and validates the assurance of the security program. As a primary point of contact for internal and external auditors, the GRC security analyst monitors progress and enforces resolution of outstanding issues that may lead to non-compliance or security threats to the business. As a key member of the security team, the GRC security analyst must focus on strong risk management and corporate resiliency, and not be driven solely by compliance. Responsibilities include conducting enterprise-wide, ongoing risk analysis in tandem with compliance and security; maintaining oversight in a GRC-related platform; identifying strengths and weaknesses in the security program as they relate to privacy, security, business resiliency and compliance frameworks; documenting, formulating and enforcing areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation; maintaining strong oversight of third parties, vendors and business partners to safeguard against undue risk presented by external entities; analyzing findings, and documenting, recommending and reporting program gaps to security leadership; monitoring current and proposed security changes impacting regulatory, privacy and security industry best practice guidance; ensuring security and technology teams maintain up-to-date configuration documentation for systems and processes; acting as a key participant in incident response to track occurrence and resolution; working in tandem with security, audit and risk management leadership to perform ongoing security program assessments and create annual strategic technology and budgetary directives; attending and fully engaging in change and project management meetings; liaising with auditors, both internal and external, to maintain and implement controls for compliance and privacy laws; acting as a point of contact for disaster recovery and business continuity as it relates to security frameworks, compliance and privacy laws; and performing other duties as assigned. Experience & Qualifications include a Bachelor’s degree in computer science, information assurance, MIS or related field, or equivalent industry experience; at least 2 years’ experience in cybersecurity as a practitioner and with at least 2 to 3 years exposure with various security frameworks; strong business acumen and security technology skills; experience and understanding of various regulatory requirements and laws including PCI, SOX, HIPAA, GDPR and GLBA; exceptional written and verbal communication skills; capacity to understand legacy and progressive technology and security controls; up-to-date understanding of incident response, system configuration, vulnerability management and hardening guidelines; prior experience with leading GRC systems; demonstrated problem-solving capabilities; self-motivated and well-organized; successful track record of managing external entities’ contracts and relationships; familiarity with state, federal and international privacy laws; and highly trustworthy with leadership qualities.

By applying, you consent to your information being transmitted by Jooble to the Employer, as data controller, through the Employer’s data processor SonicJobs.
See aspendental Privacy Policy at and Terms & Conditions at and SonicJobs Privacy Policy at and Terms of Use at

Job Tags

Full time,

Similar Jobs

Blue Pooch Inc

Receptionist at Dog Grooming Salon Job at Blue Pooch Inc

 ...team member for a full or part time receptionist position at our grooming salon. Our receptionists must have positive attitude, friendly,...  ...service experience is preferred but not required. Knowledge of dog breeds are a big plus. Must have some basic computer skills.... 

CT Healthcare Services LLC

Pharmacy Technician Part Time Job at CT Healthcare Services LLC

 ...An ideal candidate is a recently graduated pharmacy technician student with no experience or retail store cashier with customer service...  ...deliveries Bilingual Candidates are preferred Job Types: Part-time Schedule: Monday to Friday Weekend availability... 

Ascension

Radiology Tech Job at Ascension

 ...Details Department: Diagnostic Radiology Schedule: Full-time Days, Monday - Friday, 7am - 3:30pm Hospital: Dell Children's Medical Center Location: Austin, Texas Benefits Paid time off (PTO) Various health insurance options & wellness plans... 

The Equinox Resort

Maintenance Technician - $250 Sign on Bonus/$250 Retention Bonus after 1 Year Job at The Equinox Resort

 ...Description Overview We are looking for a experienced Maintenance person, who is highly motivated, and detail oriented to join...  ...Your role: Performs general maintenance of building and facility mechanical, electrical, and plumbing systems. Performs general... 

Foley & Lardner LLP

Entry-Level Commercial Litigation Associate SF Fall 2026 (San Francisco) Job at Foley & Lardner LLP

 ...A leading law firm in San Francisco is accepting applications for an entry-level associate position in the Commercial Litigation Practice Group. The ideal candidate will have strong legal writing and oral communication skills, a strong work ethic, and preferably prior...