Jobs · Information Technology · California

Associate Analyst, IT Governance Risk & Compliance

Neurocrine Biosciences · San Diego, CA · 2 days ago
Information Technology$30.97–$41.37/hrFull-time
Who We Are Neurocrine Biosciences is a leading biopharmaceutical company with a simple purpose: to relieve suffering for people with great needs. We are dedicated to discovering, developing and commercializing life-changing treatments for patients with under-addressed neurological, psychiatric, endocrine and immunological disorders. The company's diverse portfolio includes FDA-approved treatments for tardive dyskinesia, chorea associated with Huntington's disease, classic congenital adrenal hyperplasia, hyperphagia in Prader-Willi syndrome, endometriosis* and uterine fibroids*, as well as a robust pipeline including multiple compounds in mid- to late-phase clinical development across our core therapeutic areas. For more than three decades, we have applied our unique insight into neuroscience and the interconnections between brain and body systems to treat complex conditions. We relentlessly pursue medicines to ease the burden of debilitating diseases and disorders, because you deserve brave science. For more information, visit neurocrine.com, and follow the company on LinkedIn, X, Facebook and YouTube. (*in collaboration with AbbVie) About The Role Provides entry-level support for the Cyber Security Governance, Risk, and Compliance (GRC) program, under regular guidance and direction from the GRC Lead. Supports risk assessments, third-party reviews, audit and compliance support, policy administration, evidence collection, issue tracking, and reporting. Builds practical knowledge of GRC processes, business objectives, regulatory requirements, and cybersecurity frameworks while delivering accurate, timely work. _ Your Contributions (include, But Are Not Limited To) Assist with routine IT and Cyber Security risk assessments by gathering evidence, documenting results in established templates, and escalating questions, exceptions or potential concerns for reviewSupports third-party risk activities by tracking requests and questionnaires, organizing vendor evidence, completing initial completeness checks, and maintaining assessment recordsSupports framework assessments, audits and compliance reviews by coordinating evidence requests, organizing artifacts, reviewing submissions for completeness against established requirements, and documenting follow-up itemsMaintains accurate GRC records, including risk registries, controls, issues, action plans, exceptions, and assessment status, in approved systems and repositoriesAssists with mapping policies, controls, and evidence to requirements and frameworks, such as NIST CSF 2.0, ISO 27001, and CIS Controls, using documented proceduresTracks assigned remediation activities and due dates, follows up with action owners, documents updates, and escalates overdue or unclear itemsSupports policy and procedure administration through formatting, review routing, version control, publication, and maintenance of communication or training recordsPrepares routine metrics, dashboards, and status reports using established templates; validates data accuracy and supports investigation of identified data variances under guidanceParticipates in meetings, training, assigned research and process improvements activities; communicates professionally, protects confidential information, and performs assigned GRC support duties Requirements Bachelor's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field and 0-2 years of related experience; internships, co-ops, academic projects, labs, or equivalent practical experience qualify ORAssociate's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field and 1+ year of related experience, including internships, co-ops, military service, or equivalent practical experienceCertification is not required; relevant coursework, training, or a foundational certification is preferredUnderstands Neurocrine's objectives and begins to develop knowledge of its business, services, customers, and operating environmentAbility to work collaboratively, follow direction, ask questions, and apply feedbackProficiency with Microsoft 365 applicationsGood communication, problem-solving, and analytical skillsDetail oriented, with a focus on data quality, accuracy, and follow-throughAbility to organize work, follow established priorities, and meet deadlines with guidanceFoundational understanding of IT cybersecurity, governance, risk, compliance and IT controls gained through education, training, internships, projects or related experience.Interest in pursuing relevant foundational cybersecurity or GRC certifications as part of ongoing professional development.Familiarity with NIST CSF, ISO 27001, CIS Controls, or SOC 2 through coursework or experienceAbility to collect, organize, and review evidence against defined criteria under supervisionBasic spreadsheet skills to sort, filter, reconcile, and summarize information accuratelyAbility to document processes, notes, and findings clearly using established templatesAbility to handle confidential information with discretion and follow established proceduresAbility and willingness to learn GRC processes, tools, and authoritative guidance; receive coaching and apply feedback; and pursue ongoing professional development. Familiarity with automation tools and Artificial Intelligence (A.I.) concepts, including responsible use, privacy, and security Neurocrine Biosciences is an EEO/Disability/Vets employer. We are committed to building a workplace of belonging, respect, and empowerment, and we recognize there are a variety of ways to meet our requirements. We are looking for the best candidate for the job and encourage you to apply even if your experience or qualifications don’t line up to exactly what we have outlined in the job description. _ The hourly rate we reasonably expect to pay is $30.97-$41.37. Individual pay decisions depend on various factors, such as primary work location, complexity and responsibility of role, job duties/requirements, and relevant experience and skills. In addition, this position offers an annual bonus with a target of 15% of the earned base salary and eligibility to participate in our equity based long term incentive program. Benefits offered include a retirement savings plan (with company match), paid vacation, holiday and personal days, paid caregiver/parental and medical leave, and health benefits to include medical, prescription drug, dental and vision coverage in accordance with the terms and conditions of the applicable plans.

Similar jobs