Senior IT GRC Policy AnalystThe Senior IT Policy Analyst works to provide IT policies aligned with NIST security controls for the Company. This position will helm all policy work including tracking and updating current policies, managing policy exceptions, and providing metrics and reporting on policy work. This position will also manage the cybersecurity awareness training program which includes annual training, phishing training, and specialty training for specific groups within the Company.Responsibilities:Oversee and manage all policies including revisionsDevelop and manage the policy exception process including metrics and reportingCoordinate with key stakeholders on policies and standards across the CompanyResearch and evaluate policies to ensure they are current and follow all applicable laws, regulations, and guidelinesIdentify and implement GRC security controls based on the NIST frameworkManage the cybersecurity awareness program including annual training, phishing training, and special group trainingCollaborate within the GRC team on larger GRC projects around risk analysis and compliance requirementsPreferred Skills:3-to-5 years experience working with NIST Cybersecurity Framework, and familiarity with NIST 800-53 Rev.
53-to-5 years experience managing a policy program including updating current policies, tracking exceptions, and developing and reporting out metrics3 -to-5 years experience working with security content platforms and developing curricula for cybersecurity training