Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Governance and Compliance Analyst image - Rise Careers
Job details

Governance and Compliance Analyst

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Fast Facts

Exciting opportunity for a Governance and Compliance Analyst to lead cybersecurity governance programs and ensure compliance with security standards at Elsevier, a global leader in information and analytics.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Responsibilities: The analyst will design and implement cybersecurity governance frameworks, ensure compliance with laws and regulations, monitor internal policies, and collaborate with IT and legal teams.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Skills: Deep understanding of cybersecurity frameworks, risk management, compliance standards, advanced problem-solving, and strong communication skills.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Qualifications: Experience in cybersecurity governance frameworks like ISO 27001, regulatory compliance, and enterprise GRC programs; certifications like CISSP or CISM are preferred.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Location: Home based - Georgia, United States of America

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Compensation: Not provided by employer. Typical compensation ranges for this position are between $90,000 - $130,000.



Are you looking to utilize your compliance and governance expertise as a critical member of our GRC team?

About the role: We are seeking an experienced Governance, Risk, and Compliance (GRC) Analyst to lead the development and implementation of our cybersecurity governance program and maintain compliance with our information security standards and frameworks. The successful candidate will have a deep understanding of cybersecurity frameworks, risk management, and compliance standards, and will work collaboratively with cross-functional teams to ensure alignment with business objectives and regulatory requirements.

About the team: This diverse team is ensuring that the GRC policy landscape is being adhered to and ensuring that all necessary protections are in place.

Key Responsibilities: 

  • Designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry’s best practices (e.g., ISO 27001, NIST, COBIT).
  • Creating, reviewing, and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Monitoring compliance with internal policies and external regulations and prepare for audits and assessments.
  • Establishing enterprise level security governance structure, charters, participants and roles, and perform periodic role reviews to ensure appropriate accountability is maintained. 
  • Working closely with IT, legal, and business units to ensure cybersecurity governance initiatives are integrated into overall business processes.
  • Driving security-related certification efforts such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.  Drive communication and upwards reporting of the highest risk initiatives to Director of GRC, VP GRC and other key stakeholders. Generate regular reporting including KPIs, metrics and SLAs reporting, executive reporting, and other ad hoc reporting as required by management. 
  • Responsible for resolution of cybersecurity GRC issues. 
  • Serving as a trusted advisor to the business and technology stakeholders across the enterprise to partner on security issues and stay aligned on common goals.   

Requirements:

  • Experience designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry best practices (e.g., ISO 27001, NIST, COBIT).
  • Experiencing creating, reviewing and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Experience implementing cybersecurity and compliance related frameworks such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.  
  • Experience managing an enterprise cybersecurity GRC program. Experience in defining cybersecurity controls, particularly related to regulatory, legislative, and industry specific compliance requirements.
  • Ability to develop and implement security programs. 
  • Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating the resources necessary to effectively troubleshoot/diagnose complex project issues; prior success extracting/translating findings into alternatives/solutions; and identifying risks/impacts and schedule adjustments to facilitate management decision-making.
  • Advanced communication (verbal and written) and customer service skills. Strong interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management, customers, etc., including diction/terminology and presenting information in a concise and effective manner to clients, management, and various departments using assorted communication mediums.
  • Excellent stakeholder management skills. Ability to cultivate and maintain solid relationships with key stakeholders across organizational teams and third-party suppliers.

Helpful Licensing/Certifications

  • Certified Information System Security Professional (CISSP)  
  • Certified Information Security Manager (CISM) 
  • Certified Information Systems Auditor (CISA)

Work in a way that works for you

 We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.

  • Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.

Working for you

We know that your wellbeing and happiness are key to a long and successful career. These are some of the benefits we are delighted to offer:

- Health Benefits: Comprehensive, multi-carrier program for medical, dental and vision benefits

- Retirement Benefits: 401(k) with match and an Employee Share Purchase Plan

- Wellbeing: Wellness platform with incentives, Headspace app subscription, Employee Assistance and Time-off Programs

- Short-and-Long Term Disability, Life and Accidental Death Insurance, Critical Illness, and Hospital Indemnity

- Family Benefits, including bonding and family care leaves, adoption and surrogacy benefits

- Health Savings, Health Care, Dependent Care and Commuter Spending Accounts

- Up to two days of paid leave each to participate in Employee Resource Groups and to volunteer with your charity of choice

About the Business

A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. At Elsevier, your work contributes to the world’s grand challenges and a more sustainable future. We harness innovative technologies to support science and healthcare to partner for a better world.

-----------------------------------------------------------------------

Elsevier is an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form: https://forms.office.com/r/eVgFxjLmAK , or please contact 1-855-833-5120.

Please read our Candidate Privacy Policy.

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Governance and Compliance Analyst, Elsevier

Are you ready to take on an exciting role as a Governance and Compliance Analyst with Elsevier, a leader in information and analytics? In this remote position, you’ll have the opportunity to lead robust cybersecurity governance programs and ensure compliance with key security standards, making a real impact in the cybersecurity landscape. The role is designed for someone who embodies a deep understanding of cybersecurity governance frameworks like ISO 27001, and has experience in regulatory compliance. You’ll be tasked with designing and implementing comprehensive governance frameworks while collaborating with IT and legal teams to ensure successful adherence to compliance regulations. Your day-to-day will involve creating and reviewing cybersecurity policies, monitoring compliance, and preparing for audits to ensure that all aspects of governance are met. Your analytical nature will help in driving security-related certification efforts across various frameworks while also resolving GRC-related issues as they arise. Strong communication skills will be key as you interact with diverse teams, providing guidance and serving as a trusted advisor to stakeholders. Elsevier values work-life balance and offers flexible working hours, making this role perfect for those who wish to thrive in a supportive and well-rounded environment. If you’re eager to utilize your expertise and contribute to an organization that focuses on advancing science and improving health for society, we encourage you to apply today!

Frequently Asked Questions (FAQs) for Governance and Compliance Analyst Role at Elsevier
What are the key responsibilities of a Governance and Compliance Analyst at Elsevier?

As a Governance and Compliance Analyst at Elsevier, your responsibilities will include designing and implementing comprehensive cybersecurity governance frameworks aligned with best practices such as ISO 27001 and NIST. You’ll also create and update cybersecurity policies, monitor compliance with internal and external regulations, and support audit preparations. Collaboration with IT, legal, and business teams is essential to ensure that governance initiatives are effectively integrated into business processes.

Join Rise to see the full answer
What qualifications do I need to become a Governance and Compliance Analyst at Elsevier?

To become a Governance and Compliance Analyst at Elsevier, candidates should possess a deep understanding of cybersecurity frameworks and regulatory compliance. Experience with cybersecurity governance frameworks like ISO 27001 is critical, along with certifications such as CISSP or CISM being preferred. Additionally, strong problem-solving and communication skills are essential to effectively address the challenges that arise in the governance landscape.

Join Rise to see the full answer
How does Elsevier promote a healthy work/life balance for Governance and Compliance Analysts?

Elsevier is committed to promoting a healthy work/life balance for its employees, including Governance and Compliance Analysts. The company offers flexible working hours and numerous wellness initiatives, allowing you to manage your time efficiently. With benefits like wellness platforms, employee assistance programs, and various family benefits, Elsevier ensures employees can maintain both their professional and personal lives effectively.

Join Rise to see the full answer
What kind of cybersecurity frameworks should I be familiar with for the Governance and Compliance Analyst role at Elsevier?

For the Governance and Compliance Analyst role at Elsevier, familiarity with various cybersecurity frameworks is essential. Key frameworks to know include ISO 27001, FedRamp, HIPAA, and PCI. Experience in designing, implementing, and maintaining these frameworks will be highly beneficial, as they form the cornerstone of establishing effective cybersecurity governance and compliance within the organization.

Join Rise to see the full answer
What skills are most important for a successful Governance and Compliance Analyst at Elsevier?

A successful Governance and Compliance Analyst at Elsevier should have advanced problem-solving skills, a deep understanding of cybersecurity governance frameworks, and strong communication abilities. These skills will enable you to navigate complex compliance issues, collaborate with diverse teams, and serve as a reliable advisor to stakeholders to foster a secure and compliant business environment.

Join Rise to see the full answer
Common Interview Questions for Governance and Compliance Analyst
Can you describe your experience with cybersecurity governance frameworks?

When answering this question, emphasize specific frameworks you have worked with, like ISO 27001 or NIST. Share examples of how you have implemented these frameworks, any challenges faced, and how you successfully overcame them, showcasing your analytical and problem-solving skills.

Join Rise to see the full answer
How do you monitor compliance with internal policies and external regulations?

Discuss your approach to compliance monitoring, including the tools and methodologies you use. Provide an example of a compliance initiative you spearheaded, highlighting the results and adjustments made based on findings, which shows your proactive nature in governance.

Join Rise to see the full answer
What steps do you take to prepare for audits?

Outline a systematic approach to audit preparation, such as conducting pre-audit assessments, reviewing documentation, and organizing compliance records. Share a specific instance where your preparation led to a successful audit outcome, underscoring your detail-oriented approach.

Join Rise to see the full answer
Describe a time when you had to collaborate with IT and legal teams. How did you manage this?

Highlight your interpersonal and communication skills by describing a project where cross-departmental collaboration was key. Explain the strategies you used to align goals and ensure smooth communication, illustrating your ability to bridge gaps between technical and legal perspectives.

Join Rise to see the full answer
What certifications do you hold relevant to this position?

Mention any relevant certifications, such as CISSP, CISM, or CISA. Explain how these qualifications enhance your expertise in governance and compliance, and how they have equipped you to handle complex cybersecurity challenges effectively.

Join Rise to see the full answer
How do you stay updated on changes in compliance regulations?

Explain your method for keeping informed about evolving regulations, such as joining professional organizations, attending webinars, or subscribing to industry publications. Highlight the importance of continuous learning in your professional development and compliance practice.

Join Rise to see the full answer
What challenges do you foresee in the role of Governance and Compliance Analyst?

Discuss potential challenges such as rapidly changing regulations or emerging cybersecurity threats. Describe how you would proactively address these challenges by emphasizing flexibility and innovative solutions, demonstrating your forward-thinking mindset.

Join Rise to see the full answer
How do you handle conflicts or disagreements among stakeholders?

Illustrate your conflict resolution skills by providing an example of a previous conflict. Highlight your strategies for listening, empathizing, and seeking common ground to foster a collaborative environment, while also emphasizing the importance of maintaining respect and professionalism.

Join Rise to see the full answer
Can you give an example of a cybersecurity policy you developed?

Describe the process you followed to develop a specific cybersecurity policy. Focus on the research, stakeholder collaboration, and implementation steps, as well as any metrics used to measure its effectiveness post-implementation, showcasing your application of best practices.

Join Rise to see the full answer
How would you approach designing a new cybersecurity framework?

Discuss your understanding of key components needed in a cybersecurity framework, such as objectives, standards, and processes. Outline steps you would take to research, design, and implement a framework, ensuring it aligns with regulatory requirements and business goals for effectiveness.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join Elsevier as a Senior Product Manager II to shape the analytics strategy that empowers healthcare professionals with actionable insights.

Photo of the Rise User

Lead the Specialty Solutions product strategy at Elsevier, enhancing clinical decision-making in healthcare as a Senior Product Manager II.

Photo of the Rise User
Posted 5 days ago

St. Luke's Health System seeks a Systems Analyst to optimize IT solutions and improve user workflows in Boise, ID.

As a Technology Specialist (Data & AI) at Microsoft, you'll leverage data and AI to address customer challenges and foster innovation.

Photo of the Rise User

Technical Consulting Solutions is seeking a Senior Systems Administrator/Cyber Engineer to enhance NASA's IT operations at Stennis Space Center, MS.

Photo of the Rise User

Join Fever as a Cybersecurity Consultant and play a crucial role in securing our innovative tech platform that is revolutionizing live entertainment.

Photo of the Rise User
Uni Systems Remote No location specified
Posted 7 days ago

Innovate your career as a Senior Penetration Tester at Uni Systems, where technology and passion meet to secure digital visions.

Photo of the Rise User
Unistress Hybrid US, Berkshire County, MA; Massachusetts, Pittsfield, MA
Posted 12 days ago

Step into the role of Business Systems Analyst at Unistress Corporation and help bridge business objectives with technological solutions.

Photo of the Rise User
Posted 7 days ago

Join Schwab in a pivotal IT role focused on enhancing cyber security infrastructure and application support.

Photo of the Rise User
ManTech Hybrid US, Fairfax County, VA; Virginia, Herndon, VA
Posted 12 days ago

Join ManTech as an Oracle Cloud Engineer and play a key role in deploying and maintaining cloud solutions for national intelligence missions.

Photo of the Rise User
Collaboration over Competition
Growth & Learning
Work/Life Harmony
Unlimited Vacation
Learning & Development
Social Gatherings
Photo of the Rise User
Posted 2 months ago
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Lead the way in advancing science, technology and health.

67 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 6, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Chillicothe just viewed Area Manager at The Hemp Co by Curaleaf at Curaleaf
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP, B2B/Integrated Marketing at TEGNA Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director, Marketing and GTM Strategy at Aspen Dental
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Vice President, JLLIPT Marketing at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President of Marketing at Forum Health
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President of Marketing at Beacon
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director of Growth Marketing at Sundays for Dogs
P
Someone from OH, Cincinnati just viewed Vice President of Marketing at ProCaps Labs
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President, Marketing at Inmagine
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP of Marketing at IDIQ
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP of Marketing at Vultron
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Manager (Remote - US) at Jobgether
F
Someone from OH, Cincinnati just viewed Head of Marketing at FoodHealth Company
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP, Paid Marketing (Remote - US) at Jobgether
Photo of the Rise User
Someone from OH, Cincinnati just viewed Hospital Marketing at Datadog
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President, Institutional Marketing at Tutor.com
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director, Marketing Campaign Management at Humana
J
Someone from OH, Cleveland just viewed Sprinkler Service Technician IV at JCI
Photo of the Rise User
Someone from OH, Massillon just viewed Marketing Analyst at ITW
Photo of the Rise User
Someone from OH, West Chester just viewed Legal Manager IT & Privacy at Inter IKEA Group
Photo of the Rise User
18 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
14 people applied to Junior Security Engineer at Epic