Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Governance and Compliance Analyst image - Rise Careers
Job details

Governance and Compliance Analyst

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Fast Facts

Exciting opportunity for a Governance and Compliance Analyst to lead cybersecurity governance programs and ensure compliance with security standards at Elsevier, a global leader in information and analytics.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Responsibilities: The analyst will design and implement cybersecurity governance frameworks, ensure compliance with laws and regulations, monitor internal policies, and collaborate with IT and legal teams.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Skills: Deep understanding of cybersecurity frameworks, risk management, compliance standards, advanced problem-solving, and strong communication skills.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Qualifications: Experience in cybersecurity governance frameworks like ISO 27001, regulatory compliance, and enterprise GRC programs; certifications like CISSP or CISM are preferred.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Location: Home based - Georgia, United States of America

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Compensation: Not provided by employer. Typical compensation ranges for this position are between $90,000 - $130,000.



Are you looking to utilize your compliance and governance expertise as a critical member of our GRC team?

About the role: We are seeking an experienced Governance, Risk, and Compliance (GRC) Analyst to lead the development and implementation of our cybersecurity governance program and maintain compliance with our information security standards and frameworks. The successful candidate will have a deep understanding of cybersecurity frameworks, risk management, and compliance standards, and will work collaboratively with cross-functional teams to ensure alignment with business objectives and regulatory requirements.

About the team: This diverse team is ensuring that the GRC policy landscape is being adhered to and ensuring that all necessary protections are in place.

Key Responsibilities: 

  • Designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry’s best practices (e.g., ISO 27001, NIST, COBIT).
  • Creating, reviewing, and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Monitoring compliance with internal policies and external regulations and prepare for audits and assessments.
  • Establishing enterprise level security governance structure, charters, participants and roles, and perform periodic role reviews to ensure appropriate accountability is maintained. 
  • Working closely with IT, legal, and business units to ensure cybersecurity governance initiatives are integrated into overall business processes.
  • Driving security-related certification efforts such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.  Drive communication and upwards reporting of the highest risk initiatives to Director of GRC, VP GRC and other key stakeholders. Generate regular reporting including KPIs, metrics and SLAs reporting, executive reporting, and other ad hoc reporting as required by management. 
  • Responsible for resolution of cybersecurity GRC issues. 
  • Serving as a trusted advisor to the business and technology stakeholders across the enterprise to partner on security issues and stay aligned on common goals.   

Requirements:

  • Experience designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry best practices (e.g., ISO 27001, NIST, COBIT).
  • Experiencing creating, reviewing and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Experience implementing cybersecurity and compliance related frameworks such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.  
  • Experience managing an enterprise cybersecurity GRC program. Experience in defining cybersecurity controls, particularly related to regulatory, legislative, and industry specific compliance requirements.
  • Ability to develop and implement security programs. 
  • Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating the resources necessary to effectively troubleshoot/diagnose complex project issues; prior success extracting/translating findings into alternatives/solutions; and identifying risks/impacts and schedule adjustments to facilitate management decision-making.
  • Advanced communication (verbal and written) and customer service skills. Strong interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management, customers, etc., including diction/terminology and presenting information in a concise and effective manner to clients, management, and various departments using assorted communication mediums.
  • Excellent stakeholder management skills. Ability to cultivate and maintain solid relationships with key stakeholders across organizational teams and third-party suppliers.

Helpful Licensing/Certifications

  • Certified Information System Security Professional (CISSP)  
  • Certified Information Security Manager (CISM) 
  • Certified Information Systems Auditor (CISA)

Work in a way that works for you

 We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.

  • Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.

Working for you

We know that your wellbeing and happiness are key to a long and successful career. These are some of the benefits we are delighted to offer:

- Health Benefits: Comprehensive, multi-carrier program for medical, dental and vision benefits

- Retirement Benefits: 401(k) with match and an Employee Share Purchase Plan

- Wellbeing: Wellness platform with incentives, Headspace app subscription, Employee Assistance and Time-off Programs

- Short-and-Long Term Disability, Life and Accidental Death Insurance, Critical Illness, and Hospital Indemnity

- Family Benefits, including bonding and family care leaves, adoption and surrogacy benefits

- Health Savings, Health Care, Dependent Care and Commuter Spending Accounts

- Up to two days of paid leave each to participate in Employee Resource Groups and to volunteer with your charity of choice

About the Business

A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. At Elsevier, your work contributes to the world’s grand challenges and a more sustainable future. We harness innovative technologies to support science and healthcare to partner for a better world.

-----------------------------------------------------------------------

Elsevier is an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form: https://forms.office.com/r/eVgFxjLmAK , or please contact 1-855-833-5120.

Please read our Candidate Privacy Policy.

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User

Take charge as the Senior Director of Solutions Marketing at Elsevier, where you'll drive product marketing strategies and team development in a remote setting.

Photo of the Rise User
Posted 4 days ago

The Implementation Analyst plays a crucial role in delivering top-tier support for the ClinicalPath oncology software at Elsevier, focusing on customer satisfaction and project management.

Photo of the Rise User
Thomson Reuters Remote IND-BLR-Salarpuria Sattva Knowledge Court
Posted 8 days ago

As an IAM Engineer at Thomson Reuters, you'll play a crucial role in managing and securing our Windows server environments.

Posted 6 days ago

Join Toyota Financial Services as an Insider Risk Management Lead and take charge of enhancing the security posture while collaborating with cross-functional teams.

Photo of the Rise User

Join Perchwell as a Senior Site Reliability Engineer to drive improvements in their modern real estate platform's technical foundation while collaborating with top-tier engineering teams.

Photo of the Rise User

Join The College Preparatory School as a Network and Systems Administrator, where you'll maintain IT infrastructure and support educational technology needs.

Photo of the Rise User
SentinelOne Remote Prague, Czech Republic
Posted 5 days ago

Enhance cyber security measures in a collaborative environment with SentinelOne, a leader in AI-driven cybersecurity solutions.

Photo of the Rise User
Nemera Remote Rheinwaldstraße 10, Neuenburg, Baden-Württemberg, Germany
Posted 6 days ago

Join Nemera as an IT Administrator where you'll oversee the integration and maintenance of innovative IT systems in a dynamic production environment.

Photo of the Rise User
Posted 5 days ago

As an IT Support Specialist, you will troubleshoot Microsoft 365 services and collaborate on projects to improve user and device management in our vibrant Manchester office.

Posted 12 days ago

Join Astor & Sanders Corporation as a Cybersecurity and Network Security Engineer to safeguard critical infrastructure with your expertise in cybersecurity frameworks.

A project to standardize email signatures across the company for improved consistency and branding.

Photo of the Rise User
GameStop Hybrid 625 Westport Pkwy Grapevine, TX 76051
Posted 12 days ago

Take on a pivotal Senior Network Engineer role at GameStop, where you'll enhance and maintain critical network services across the organization.

Photo of the Rise User
Posted 13 days ago

Join Ochsner Health as an IS Technology Specialist and contribute to their mission of excellence in healthcare technology and support.

Photo of the Rise User
Posted 12 days ago

Seeking an experienced Oracle Applications Specialist to enhance our enterprise application solutions within the IT environment for the Utilities department.

Join DDC-IT Services as a Senior Database Administrator, where you'll oversee critical DBMS environments in a fully remote role.

Lead the way in advancing science, technology and health.

75 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 6, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!