IT GRC Analyst II
SECU · Raleigh-Durham-Chapel Hill Area · 2 wk ago
Information TechnologyFull-time
About the Role
The IT GRC Analyst II assesses, tests, documents, and monitors the SECU technology ecosystem to ensure the IT control environment effectively mitigates risks associated with an ever-changing threat landscape. This role requires a blend of technical and interpersonal skills to bridge technology organizations and the business, a big-picture perspective, and the ability to execute end-to-end risk management processes while building productive relationships across multiple departments.
Responsibilities
- Identify, document, and monitor technology risks present across both internal and external (vendor/cloud) environments (20%)
- Quantify inherent and residual IT risk levels to enhance analytics, inform prioritizations, and support management reporting (20%)
- Work with risk remediation owners to establish remediation plans with milestones and target dates, and monitor progress toward remediation, escalating as appropriate (20%)
- Execute technology risk management processes and provide input to support continuous improvement of process and program design (20%)
- Perform risk and controls assessments while aggregating reporting for Audit and/or Regulatory issues (10%)
- Partner with relevant stakeholders to establish clear and consistent IT risk reporting, metrics, KRIs, and KPIs to inform decision-making (10%)
Requirements
- Minimum 5 years of relevant experience
- 5 years of IT Security and/or IT Risk Management experience in a mid-to-large size company
- Basic proficiency or ability to learn one or more of the following:
- Risk and controls assessments
- Documenting and maintaining IT Policies/Standards
- IT Risk aggregation, reporting, KPIs/KRIs
- Issues management
- Third-party risk management
- Working knowledge of industry security standards and frameworks, including NIST, ISO 27001, ISF Standard of Good Practice (SoGP), etc.
Skills
- Teamwork, collaboration, and self-driven with effective communication skills (both written and verbal)
- Desired (not required):
- 5+ years working in a financial institution
- Knowledge of modern enterprise and security architectures, their challenges, and common approaches to overcome them
- Professional certifications such as CISSP, CISA, CISM, GIAC, CGEIT, CRISC, OSCE, or other relevant industry certification
- Experience working within a DevOps environment