The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a subject matter expert, mentor to junior staff, and liaison to executive leadership and external stakeholders while advancing ICCU’s mission of Helping Members Achieve Financial Success.
Duties & Responsibilities
Lead and execute enterprisewide cyber and information security risk assessments and audits.
A primary contributor to setting strategy and direction in strengthening and reinforcing ICCUs technology defenses and identifying and remedying weaknesses and control gaps within the ICCU environment.
Manage thirdâparty cyber risk assessments, vendor reviews, and remediation tracking.
Oversee compliance frameworks including NIST CSF, FFIEC, PCIâDSS, CIS Controls, FedLine, and SWIFT.
Develop and maintain IT policies, standards, and procedures aligned with regulatory mandates.
Act as lead liaison and coordinator of internal and external IT audits.
Build and maintain IT GRC dashboards, risk registers, and executive reports.
Scope and draft statements of work and proposals for new IT GRC initiatives.
Lead tabletop exercises, Pen Test reviews, and incident response planning in partnership with stakeholders.
Provide mentorship and guidance to junior GRC Cybersecurity analysts.
Collaborate with IT, Compliance, and Risk teams to align GRC efforts.
Serve as a primary IT point of contact for auditors, regulators, and certification bodies.
Monitor and report on compliance gaps, risk mitigation plans, and audit readiness.
Stay current on regulatory developments, compliance frameworks, and emerging governance risks impacting cybersecurity programs.
Support strategic planning and budgeting for GRC tools and capabilities.
Other duties as assigned.
Qualifications:
Education & Certifications
A bachelor’s degree in Information Assurance, Cyber Security, Computer Science, Computer Information Technology, or similar field of study, or equivalent work experience is required.
A master’s degree or equivalent certificate in information assurance or computer related fields such as Computer Science, Computer Security or Software Development is strongly preferred. A masters degree may substitute for 1 year of required experience.
One Level I certification, One Level II, and One Level III certification from the DoD 8140 (8570) Cyber Workforce Qualification Matrix pertaining to GRC (eg, SSCP, CISSP, CISM, CISA, CRISC, GSEC, CGRC, CCSP, CSSLP, GSE, or equivalent).
Experience
9+ years of work experience in roles with significant Information Security duties.
6+ years of work experience in senior level IT technical roles in Security, Infrastructure, Application Development, Operations, Cloud Management, Ecommerce, or similar areas.
3+ years of experience in senior roles with cyber / infosec GRC projects or teams.
Proven experience with regulatory compliance and certification programs.
Experience in regulated industries such as financial services or healthcare.
Familiarity with enterprise risk management (ERM) frameworks.
Tools & Technologies
Security Information and Event Management (SIEM) tools for log aggregation, monitoring, and analysis.
Vulnerability Scanning Platforms for identifying, reporting, and tracking security weaknesses.
Enterprise GRC systems (or equivalent) for assessment distribution and tracking.
Internal dashboards (for metrics, assessments, audit readiness, and executive reporting).
Familiarity with project management tools.
Microsoft Office Suite (Excel, Word).
Understanding of cloud technologies and SaaS platforms.
Skills & Competencies
Strong leadership, communication, and stakeholder management skills.
Ability to manage complex projects and crossâfunctional teams.
Strategic thinking with strong attention to detail.
Ability to simplify complexity and drive results.
High sense of urgency and initiative.
Ability to work independently and collaboratively.
Physical & Operational Requirements
This role is primarily officeâbased and requires extended periods of sitting, computer use, and interaction with standard office equipment. Occasional lifting of up to 15 pounds may be required. The employee must have sufficient vision to read documents and screens, and hearing ability to communicate effectively in person and via telephone. Flexibility may be required during organizational changes or highâpriority audit cycles.
The above statements reflect the general details considered necessary to describe the essential functions of the job and should not be construed as a detailed description of all the work requirements that may be inherent of the job.
Must be eligible for membership at ICCU to obtain employment.
ICCU is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, age, disability, protected veteran status or other characteristics protected by law.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!