Lead Technical GRC Analyst
4 days ago
Job DescriptionThe Lead IT GRC Analyst will be a key team member within the NBCUniversal Cyber organization and shape, manage, and evolve NBCUniversal’s security governance framework while driving the development of secure configuration baselines across diverse technical environments. This role requires a unique blend of deep policy and governance framework understanding, hands-on technical collaboration, and proactive engagement to help define security governance throughout the lifecycle of small initiatives to large-scale programs. The ideal candidate brings a strong foundation in information security governance, hands-on technical collaboration, and the ability to translate security principles into actionable, business-friendly requirements.Responsibilities:Key areas of focus for the Cyber Governance Lead include maintaining the organization’s governance framework, designing and developing new cyber governance processes, and helping to design enterprise-scale policy. The successful candidate will be responsible for the following activities: Manage the organization’s security governance program, including participating in Cyber-led projects and programs to design and develop cyber governance processes.Maintaining an effective feedback loop with business partners – seeking and integrating business area feedback into cyber governance processes.Contribute to overall program enhancements and drive automation with various IT and Cybersecurity stakeholders.Participate in development, review, and implementation of security policies, standards, procedures, and guidelines in alignment with industry frameworks (, ISO 27001, NIST, CIS).Serve as point of contact for internal audits, certifications, and compliance initiatives related to policy and governance.Actively consult with stakeholders throughout the development lifecycle of small projects and large-scale programs to help establish, refine, and validate governance processes.Conduct technical assessments of configurations to ensure security effectiveness.Monitor regulatory changes and emerging risks to ensure policies remain compliant and adaptive to future threats.Use advanced technologies—, robotic process automation and AI/machine learning—to improve operation.Provide hands-on technical control review to support guidance of enterprise configurations of tools like M365, Slack, Microsoft Defender for Cloud, etc.Design and develop GRC metrics including KPIs and KRIs.QualificationsRequirements:4+ years of experience in information security, governance, risk, or compliance roles.Strong and proven communication (both verbal and written) and customer engagement skills with experience in briefing corporate executives and professionals. Familiarity with industry standards and frameworks (, NIST CSF, ISO 27001, CIS Benchmarks, SOC 2).Ability to read and interpret technical documentation and translate it into governance mandates.Strong analytical and communication skills with the ability to translate complex security concepts into business language.Experience performing system integration, system management, and configuring native controls in modern enterprise IT tooling.Experience working with technical teams to implement and validate secure configurations.Comfortable working in fast-paced, ambiguous, or evolving environments with a solution-oriented mindset.Ability to balance governance rigor with creativity and adaptability in a business-centric approach.Bachelor’s Degree in an IT related field and/or equivalent work experience. Desired Characteristics:Previous experience working in multiple large complex environments and specifically within the Governance, Risk, and Compliance functions. Previous experience working in Governance, Risk, and Compliance functions in the media, entertainment, federal, and/or advanced technology industries. Experience with other enterprise technologies (, Active Directory/Azure AD, cloud platforms, configuration assessment tools)Experience with GRC platforms (, OneTrust, ServiceNow GRC, Archer).Background working with legal, procurement, or privacy teams.Industry certifications such as CRISC, CISA, CISSP, or technical certifications (, Microsoft 365 Certified, AWS Security Specialist) are a plus.Additional Requirements: Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $110,000 - $140,000 (bonus eligible)Additional InformationAs part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law. If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access as a result of your disability. You can request reasonable accommodations by emailing AccessibilityS.For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
-
Lead Technical GRC Analyst
4 days ago
New York, United States NBCUniversal Full timeJob DescriptionThe Lead IT GRC Analyst will be a key team member within the NBCUniversal Cyber organization and shape, manage, and evolve NBCUniversal’s security governance framework while driving the development of secure configuration baselines across diverse technical environments. This role requires a unique blend of deep policy and governance...
-
Lead Security Risk Analyst
2 hours ago
New York, United States Justworks Full timeWho We AreAt Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people. We’re helping businesses get off the ground by enabling them to focus on...
-
Senior GRC Analyst
2 weeks ago
New York, United States Kendall And Davis, Inc. Full timePosition Title: Senior GRC Analyst FTE/Direct Hire Hybrid Work Schedule Long Island, NY Company Story: Large financial institution with over $110+ billion in assets Over 2 Centuries of providing service to the community Family-oriented environment that respects their employees and promotes a work-life balance. Technology driven environment Benefits and...
-
Senior Analyst, Cybersecurity GRC
2 weeks ago
New York, United States Next Step Systems LTD Full timeSenior Analyst, Cybersecurity GRC, New York, NY The Senior Analyst, Cybersecurity GRCwill administer the completion of compliance-related client requests to assess security policies and procedures. The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well...
-
Senior GRC Analyst
2 weeks ago
New York, NY, United States Kendall And Davis, Inc. Full timePosition Title: Senior GRC Analyst FTE/Direct Hire Hybrid Work Schedule Long Island, NY Company Story: Large financial institution with over $110+ billion in assets Over 2 Centuries of providing service to the community Family-oriented environment that respects their employees and promotes a work-life balance. Technology driven environment Benefits...
-
Cybersecurity Sr. GRC Analyst
2 weeks ago
New York, United States RIT Solutions, Inc. Full timeCybersecurity Sr. GRC Analyst Location: 3-day Hybrid (Tue-Thu) in King of Prussia, PA or Denver, PA - Locals only Duration: 3-6 months, Contract-to-Hire (CTH) Rate: Best possible, but keep at the lower end (Oil & Gas client budget) Overview Our client, a top-tier Management Consulting firm, has partnered with an Oil & Natural Gas company to identify a Global...
-
Senior Business Analyst, GRC
4 weeks ago
New York, United States SoFi Full timeBase pay range $86,400.00/yr - $162,000.00/yr The role Were building a modern, integrated ServiceNow IRM platform to improve how we manage risk and compliance across the enterprise. As a Business Analyst on the GRC Business Systems team, you will play a key role in shaping the way we define, adopt, and optimize risk processes and supporting technology both...
-
Senior Business Analyst, GRC
4 weeks ago
New York, United States SoFi Full timeBase pay range $86,400.00/yr - $162,000.00/yr The role Were building a modern, integrated ServiceNow IRM platform to improve how we manage risk and compliance across the enterprise. As a Business Analyst on the GRC Business Systems team, you will play a key role in shaping the way we define, adopt, and optimize risk processes and supporting technology both...
-
GRC Analyst
5 days ago
New York, New York, United States Provident Bank Full time $65,000 - $85,000 per yearHow would you like to join one of the most highly regarded financial institutions in New Jersey with deep roots in the community? Provident is a successful and highly regarded multi-billion dollar bank that continues to grow with branches in New Jersey, Eastern Pennsylvania and New York. Our longevity is a testament to our commitment to placing our...
-
GRC Analytics
2 weeks ago
New York, United States Sciata Full timeThe GRC Analytics & Automation Analyst builds and maintains data pipelines, automation, and dashboards that enable measurable compliance and continuous monitoring across the Compliance Governance Program. This role integrates GovCloud intake sources (SharePoint intake registry, AuditBoard exports, APIs) into Power BI, automates evidence collection where...