Governance Risk and Compliance Analyst
Ice Miller LLP · New York, NY · 2 days ago
LegalFull-time
About the role
As a GRC Analyst, you will leverage knowledge of security policies, standards, controls, and industry best practices to consult with others in the firm and inform on risk to systems and data. You will play a critical role in ensuring that GRC functions are incorporated into key firm programs while validating that risk‑mitigation functions are operating correctly.
Responsibilities
- Governance: Develop and manage cyber security policies, standards, procedures, and overall governance based on the NIST Cyber Security Framework, NIST 800‑53, and CIS controls.
- Assess current platforms against security and configuration standards.
- Interface with key security personnel to align expectations and remediation activities with best practices.
- Collaborate with the IT team to identify, address, and resolve key cybersecurity risks and issues promptly.
- Assist in developing and deploying information security awareness, training, and communication capabilities related to governance changes.
- Evaluate and process exceptions to information security policies and standards.
- Support administration of identity governance and administration activities.
- Incorporate audit findings, legal obligations, compliance, and regulatory requirements into policy development.
- Manage lateral transfers of data in and out of the firm and implement ethical walls.
- Risk: Measure and monitor cybersecurity risk; manage and prioritize the risk exception queue.
- Perform risk assessments in alignment with methodologies and provide timely feedback to stakeholders.
- Assist in conducting business impact analyses for systems, applications, and processes.
- Help develop cyber‑resilience plans, including incident response, business continuity, and disaster recovery.
- Participate in Third‑Party Risk Management Program activities.
- Compliance: Maintain awareness of existing and proposed security standards, state and federal legislation, and regulations affecting information security.
- Identify regulatory changes and recommend appropriate policy, standard, and procedure updates.
- Participate in internal and external compliance audits and respond to security questionnaires.
- Provide guidance to management and business stakeholders on the security impact of regulations, policies, applicable laws, and key risks.
- Participate in compliance reviews as assigned by management.
Requirements
- Understanding of common security regulations (e.g., HIPAA, Meaningful Use, PCI DSS, ISO 2700x, FDA, etc.).
- Understanding of common industry security frameworks (e.g., ISO 2700x, NIST CSF, NIST SP 800‑53, HITRUST, etc.).
- Familiarity with security auditing and risk assessment processes.
- Skills in documenting risk and compliance activities.
- Excellent written and verbal communication, interpersonal, and collaborative skills; ability to convey strategic information‑security topics to both technical and non‑technical audiences.
- Proficiency in developing and delivering incident‑response playbooks and tabletop exercises.
- Sound knowledge of business management and expert knowledge of information/cybersecurity risk management and governance.
- Experience responding to, analyzing, and communicating information‑security audits.
- Basic understanding of general security concepts, including cryptography, DLP, SOC, managed services, SIEM, firewalls, cloud security, mobile security, etc.
Other Expectations
- Strong ability to follow instructions, ask intelligent questions, and apply critical‑thinking skills.
- Self‑starter capable of working independently with minimal supervision.
- Effective team player with maturity to accept direction and confidence to give direction.
- Ability to quickly identify risks that require escalation to senior leadership.
- Consistent daily progress while managing multiple tasks without missing deadlines.
- Adaptability to changing priorities without frustration.
- Strong attention to detail and high commitment to quality.
- Positive attitude and courteous demeanor in a small, fast‑paced team.
- Efficiency‑focused, seeking ways to gain efficiencies and maximize time.
Other Requirements
- Extensive use of a computer, telephone, and standard office equipment (printing, copying, faxing, scanning).
- Physical: occasional sitting, standing, talking, seeing, and hearing.
- Mental: ability to communicate effectively, verbally and in writing, with a diverse group of people.
- Work environment may include moderate noise levels and occasional exposure to weather conditions while traveling.
- Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.
Benefits
- Paid time off
- Health insurance
- Vision and dental insurance
- 401(k) with employer match
- Life insurance
- Additional benefits available upon request