Sr. Security Analyst – GRC; Risk & Reporting
Listed on 2026-01-20
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Business Analyst
JOB TITLE: Sr Security Analyst – GRC (Risk & Reporting)
MODALITY: Remote in DR
SCHEDULE: Mon - Fri 09:00 AM - 06:00 PM
GENERAL DESCRIPTION OR PURPOSE OF JOB:The Senior Security Analyst – GRC (Risk & Reporting) is responsible for overseeing risk management processes, tracking issues, and ensuring remediation efforts are effective. This role also involves managing the security metrics and reporting program. The position requires a detail-oriented individual with expertise in IT compliance, risk management, and internal controls.
The analyst will work collaboratively with various teams to gather and evaluate evidence necessary to meet security requirements. A successful candidate will be a proactive team player with strong interpersonal skills, the ability to take ownership of their responsibilities, and the initiative to work independently in a high‑paced environment.
RESPONSIBILITIES /ESSENTIAL FUNCTIONS:
Risk Registry and Issues Management
- Lead the development and maintenance of the Information Security risk registry, ensuring that all identified risks are properly recorded, assessed, and monitored.
- Track issues and action plans related to risk mitigation and compliance findings.
- Follow up with control owners to ensure timely resolution of issues and deficiencies.
- Support the development and maintenance of the organizational risk appetite statement and risk tolerance levels.
- Jostens Information Security Program:
Assist in the development, maintenance, and communication of policies, standards, and procedures. - Audit/Assessments:
Facilitate audits and assessments of IT programs and individual components to determine compliance with published standards (e.g., SOC2, SOX, ISO
27000, PCI, etc.). - Vendor Management:
Assist in Third‑Party Risk Management as needed. - Training:
Develop, plan, coordinate, deliver, and/or evaluate training courses. - Privacy:
Coordinate with legal and IT teams on privacy requests. - Incident response: ensure proper documentation and post‑incident analysis.
Required:
- Bachelor’s degree in Business or Accounting, Information Security, Information Management Systems, Cybersecurity, or other applicable area, or related work experience.
- Minimum 5 years in Information Security, IT Compliance, IT Audit, or related role.
- Hands‑on experience with risk management.
- Experience with GRC/third‑party management tools (e.g., Archer, One Trust, ZenGRC, etc.).
- Strong understanding and working knowledge of risk management principles, issue tracking, and risk reporting.
- Understanding of metrics and reporting.
- Excellent analytical and problem‑solving skills.
- Strong written and verbal communication skills.
- Ability to work with technical and non‑technical teams.
- Ability to collaborate with cross‑functional teams and external partners.
- Attention to detail with experience prioritizing and managing multiple projects with competing priorities.
- Certification applicable to a role in Information Security Governance, Risk and Compliance (e.g., CISSP, CISA, CISM, CRISC, CRMA).
- Weekly Payment
- Law medical insurance and AFP
- Complementary Medical Insurance
- Life Insurance
- Internal Bank
- Credit in pharmacy and optic center
- Referral Program
- Remote Role
Jostens leads the student commemoration market and has been serving local communities for over 125 years. We work with thousands of K-12 schools, colleges and universities each year, and have the honor of partnering with beloved sports teams and esteemed organizations across the country. Our iconic products—like yearbooks, letter jackets, class jewelry and championship rings—keep meaningful traditions alive and inspire millions of people to celebrate their unique stories, milestone moments and biggest accomplishments every year.
We have 13 first‑class facilities across the globe, from North America to the Caribbean. Watch a short video about ushere.
Jostens is an Equal Opportunity Employer and complies with applicable employment laws. EOE/M/F/Vet/Disabled are encouraged to apply. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).