Jobs and Careers
AB

Senior GRC Analyst

Abnormal AI
Remote - USA, United StatesRemotefull_timeVerifiedPosted 14 Jan 2025
💰 $149,500/yr($127,100/yr$149,500/yr)

About the role

About the Role

Abnormal Security is looking for a Senior GRC Analyst (Governance, Risk, and Compliance) to join the Security & Privacy team. The Security & Privacy team owns the information and cybersecurity program for the company, including IT, Security Operations, GRC, Privacy, and Customer Trust. The GRC team aims to facilitate information security and data governance processes, enable risk-based decision-making, and deliver a compliance foundation to achieve and maintain compliance certifications. 

This role will support the execution of the GRC program. The role will be focused on evaluating technology controls, performing audit readiness, leading external audits, and acting as a compliance domain advisor to the business. This role will also be the lead for Issues Management to drive remediation of issues across the company that are identified through the GRC programs. In addition, this role will support governance and risk management activities such as policy management/operations and risk operations. 

The ideal candidate will have the mindset of an auditor with keen attention to detail,  possess exceptional skills in project management, be a good communicator who excels at explaining complex technology to diverse audiences in a way that fosters understanding and ownership, has strong collaboration and business sense, and an adept awareness of our customers’ requirements of Abnormal as a leading cybersecurity SaaS provider. 

Who you are

  • Proven security experience in an audit or advisory capacity
  • Analytical thinker who exercises good business judgment
  • Confidence and willingness to ask questions, raise issues, and concerns in a timely manner
  • High attention to detail, process, and organization with strong project management skills to ensure accountability and results
  • Strong communication skills with the ability to quickly build rapport with internal and external stakeholders including auditors; demonstrated experience presenting technical concepts to diverse audiences
  • Proficient in managing results and achievements, even when faced with ambiguity or competing approaches regarding the best path to success.
  • Ability to adapt to change, including evolving business and technical environments, and manage multiple priorities while meeting deadlines in a fast-paced environment
  • Team player, collaborative work style
  • Self-motivated and able to work efficiently with minimal oversight/direction

 

What you will do 

  • Keep abreast of regulatory and industry developments and advise leadership on the potential impact on the program strategy and plans.
  • Ensure program activities align with strategy and manage the timely and high-quality execution of GRC landmarks.
  • Drive internal control effectiveness through crafting the control matrix, rigorous internal control monitoring, implementing control enhancements, and providing thought leadership on control design, operations, and supporting processes and policies. 
  • Perform compliance readiness assessments and provide updates, recommendations, and roadmap to senior management both within Security and to our business partners.
  • Develop the audit plan in partnership with leadership and lead internal and external audit engagements according to plan, while supervising the work of external auditors and internal audit contractors and working with relevant control owners to minimize disruption while successfully completing the efforts in a timely manner.
  • Advise, educate, and train process  and control owners with the preparation and ongoing maintenance of controls and control documentation (e.g., policies, procedures, narratives, and matrices) to better understand the security controls framework and their responsibilities.
  • Recommend, develop, and manage the company’s risk register, including the definition and reporting on key risk indicators (KRIs) and key performance indicators (KPIs)
  • Conduct regular risk assessments and work with relevant departments to identify, evaluate, and mitigate risks across the organization.
  • Define, develop, and implement capabilities to manage third-party cybersecurity risks
  • Manage review, testing, and improvements to business continuity plans. 
  • Advise, educate, and train risk owners with the identification, assessment, mitigation, and monitoring of risks to better understand the risk management process and their responsibilities.
  • Maintain the policy repository and support effective policy communication
  • Proactively identify gaps or conflicts in ex

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Abnormal AI

View company profile →