Global Cybersecurity Senior GRC Analyst
UGI CorporationAbout the role
Requisition Number: 29670
At UGI Utilities, Inc. we believe in providing a superior range of energy products and services to our customers in a safe, affordable manner. As our energy needs evolve, UGI will be there providing safe and reliable service that brings warmth and comfort to our 750,000 customers in 45 counties in Pennsylvania and 1 county in Maryland.
We strive to reflect the communities we serve by attracting and retaining top talent, while maintaining a diverse workforce that embraces our culture of safety, service, and integrity. As an employee of UGI Utilities, you can expect a competitive total compensation plan and comprehensive benefits. Employees work in a collaborative environment, have upward mobility opportunities, and the ability to enjoy a true work life balance.
To learn more about UGI's workplace culture, sustainability efforts, and commitment to inclusivity, we invite you to visit our UGI Corporate sustainability page.
Apply to UGI Utilities today to share in our mission and support countless neighbors, friends, and families in providing best-in-class products and services!
Job Summary:
The Global Cybersecurity Senior GRC Analyst plays a critical role in ensuring that the organization operates within its regulatory, legal, and compliance obligations while managing risk effectively. The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design, implement, and maintain governance, risk, and compliance processes. The ideal candidate is detail-oriented, analytical, and experienced in regulatory compliance, risk management frameworks, and governance best practices and must develop and apply continuous improvement strategies in all aspects of the job function.
Key Responsibilities:
Governance:
• Develop and maintain corporate policies, procedures, and frameworks to align with industry best practices (e.g., NIST CSF, SOX, PCI, etc.).
- Assist with the development and maintenance of GRC process and procedure documentation.
• Ensure IT functions are in compliance with best practices and company policies and standards through assessments (i.e. peer reviews, audits, etc.)
- Track key risk indicators and security metrics
Risk Management:
• Assist with conducting gap assessments to identify threats, vulnerabilities, and potential impacts on the organization.
• Develop and maintain the risk register, ensuring risks are documented, prioritized, and mitigated.
• Perform third-party/vendor risk assessments to evaluate potential risks associated with external partnerships and perform on-going monitoring to assess risk of engagement.
- Maintain centralized documentation, continuous monitoring for vendors, formal escalation protocols for non-compliance to ensure alignment with enterprise risk tolerance.
- Document risk acceptance decisions and compensating controls
- Develop and maintain templates for consistent risk documentation
- Assist in evaluating cybersecurity risk on incoming projects.
- Assist and support team in performing cybersecurity due diligence on merger/acquisition targets.
Compliance:
• Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS) and industry standards through monitoring and reporting metrics, security exceptions and using other methods to monitor compliance
•Drive compliance by maintaining the compliance framework to ensure policies and standards align to regulatory requirements, laws and best practices.
Stakeholder Engagement
- Collaborate with business units to understand critical processes
- Educate stakeholders on risk management concepts and frameworks
- Partner with technical teams to validate remediation plans
- Present risk findings to appropriate governance committees
- Coordinate and collaborate with stakeholders to establish and track metrics for governance programs.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s