Sr. Analyst, Cybersecurity Governance, Risk & Compliance

Chicago, IL

Direct Hire

Salary Range: $95,000 - $130,000

Senior Analyst, Cyber Security Governance, Risk & Compliance

Location: Chicago, IL

Position Summary:

We are seeking a seasoned Cyber Security GRC Senior Analyst to contribute to the development and enhancement of our cyber security GRC program. You will collaborate closely with the Chief Information Security Officer (CISO) and play a vital role in our cyber security team.


  • Develop, refine, and implement enterprise-wide cyber security policies, standards, and controls to manage risks and ensure compliance with relevant regulations.
  • Establish and execute a robust cyber security risk management program, identifying risks, providing mitigation recommendations, and collaborating with stakeholders to implement controls.
  • Maintain a cyber security risk register and collaborate with stakeholders to develop action plans for risk mitigation.
  • Conduct ongoing compliance reviews in alignment with security policies, regulations (SOX, GDPR), and frameworks (NIST CSF, MITRE, PCI-DSS), working closely with IT and business units.
  • Design and implement security training and awareness initiatives.
  • Collaborate on data classification efforts and develop and operationalize a data loss prevention program.
  • Participate in incident response exercises, business continuity planning, penetration testing, and compliance activities, tracking progress on remediation efforts.
  • Stay informed about emerging cyber security threats and provide guidance to stakeholders on response strategies.
  • Develop and maintain key performance indicators (KPIs) and key risk indicators (KRIs) for the cyber security program.
  • Manage security projects and tasks as assigned by management within the cyber security team.


  • Minimum of 3 years of hands-on experience in cyber security GRC.
  • Bachelor’s Degree or higher in an Information Technology discipline; equivalent combination of education and experience considered.
  • Preferred professional certifications: CRISC, CISM, CGEIT, GRCP.
  • Proficiency in industry frameworks such as NIST, ISO, MITRE, OWASP, PCI-DSS, SOX.
  • Thorough understanding of data privacy regulations like CCPA, GDPR.
  • Experience conducting cyber security risk assessments.
  • Ability to translate technical language into business risks effectively.
  • Strong analytical and problem-solving skills.
  • Excellent verbal and written communication skills, with the ability to collaborate effectively with stakeholders.
  • Demonstrated ability to deliver results in a fast-paced environment with shifting priorities.
  • Passion for cyber security.

Core Competencies:

  • Action Orientation
  • Drive for Results
  • Business Acumen
  • Problem Solving
  • Risk Management

Success Measures:

  • Within ninety (90) days:
    • Initiate assessment and documentation of cyber security risks.
    • Begin establishing relationships with stakeholders across the enterprise.
  • Within six (6) months:
    • Establish a cyber risk management program to address enterprise and third-party risks.
    • Develop cyber security policies and standards.
    • Commence establishment of a cyber security compliance program.
  • Within one (1) year:
    • Effectively track cyber security risks and collaborate with stakeholders on remediation efforts.
    • Establish and report on KPIs and KRIs.

Share This Job

Apply Now

We help people find the next step in their careers in technology, marketing, sales, human resources, finance, accounting, and real estate. Check out what jobs we have available today.

Follow the hottest hiring trends. #IYKYK

Talent Insights is THE place to keep up with the latest trends in hiring. From market analysis to hot takes on talent practices, tune in to learn (and maybe be entertained).

drop us a line

Need help with hiring? Turns out, we'd love to help. Contact us below.
If you're looking for a new job, check out the job openings for our clients here.