About this role
The Sr. IT Cybersecurity Governance Analyst is responsible for establishing, maintaining, and maturing the enterprise cybersecurity governance framework. This role provides structure, consistency, and oversight across policies, standards, control frameworks, and regulatory requirements to ensure alignment with business objectives, risk appetite, and external obligations. The individual leads policy and standards management, maintains the cybersecurity control framework and controls library, oversees regulatory change management, and ensures governance processes are integrated into enterprise decision-making and risk management activities.
What will you do?
- Lead development, maintenance, and periodic review of enterprise cybersecurity policies, standards, and procedures to ensure alignment with regulatory requirements, industry frameworks, and business objectives.
- Maintain the enterprise cybersecurity control framework and centralized controls library aligned to standards such as ISO/IEC 27001 and NIST SP 800-53.
- Ensure traceability between regulatory, legal, and contractual requirements and internal control objectives through structured compliance control mapping.
- Support regulatory change management activities, including identification, tracking, impact assessment, and coordination of required updates to policies, controls, procedures, and documentation.
- Maintain a centralized repository of cybersecurity requirements and governance artifacts to support auditability and regulatory examinations.
- Manage governance processes that support consistent execution of GRC activities across cybersecurity, IT, and business functions.
- Ensure cybersecurity governance practices align with enterprise risk appetite, strategic objectives, and enterprise risk management (ERM) processes.
- Partner with Risk, Compliance, Security Operations, IT, Legal, and Enterprise Risk teams to ensure governance requirements are understood and implemented effectively.
- Support leadership and executive committees by providing governance-related reporting, updates, and decision support.
- Promote consistency, accountability, and ownership across cybersecurity governance activities.
What do you need for this role?
- Associates Degree required, major in Computer and Information Science, or Management Information Systems. Bachelors Degree preferred.
- 3+ years experience in cybersecurity governance, risk, compliance, or related disciplines. .
- Strong knowledge of ISO/IEC 27001, NIST CDF, NIST SP 800-53, COBIT, or similar governance framework
- Microsoft 365
- US -ITIL V3 – Other preferred
- Experience managing regulatory requirements and supporting regulatory examinations or audits.
- Strong organizational and documentation skills with attention to detail.
- Excellent written and verbal communication skills, with ability to engage senior leadership and cross-functional stakeholders.