Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Governance and Compliance Analyst image - Rise Careers
Job details

Senior Governance and Compliance Analyst

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Fast Facts

Seeking an experienced Senior Governance, Risk, and Compliance (GRC) Analyst to develop and implement a cybersecurity governance program for our GRC team, ensuring compliance with information security standards.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Responsibilities: Lead the design and implementation of cybersecurity governance frameworks, ensure compliance with laws and regulations, and drive security-related certification efforts. Generate reporting on cybersecurity GRC initiatives and serve as a trusted advisor for security issues.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Skills: Deep understanding of cybersecurity frameworks (ISO 27001, NIST, COBIT), experience in compliance program management, and advanced communication and stakeholder management skills.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Qualifications: Certifications like CISSP, CISM, or CISA preferred, along with experience in managing enterprise GRC programs and defining cybersecurity controls for compliance.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Location: Home-based position located in Georgia, USA.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Compensation: Not provided by employer. Typical compensation ranges for this position are between $95,000 - $130,000.



Are you looking to utilize your Compliance and Governance expertise as a critical member of our GRC team?

About the role: We are seeking an experienced Senior Governance, Risk, and Compliance (GRC) Analyst to lead the development and implementation of our cybersecurity governance program and maintain compliance with our information security standards and frameworks. The successful candidate will have a deep understanding of cybersecurity frameworks, risk management, and compliance standards, and will work collaboratively with cross-functional teams to ensure alignment with business objectives and regulatory requirements.

About the team: This diverse team is ensuring that the GRC policy landscape is being adhered to and ensuring that all necessary protections are in place.

Key Responsibilities: 

  • Designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry’s best practices (e.g., ISO 27001, NIST, COBIT).
  • Creating, reviewing, and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Monitoring compliance with internal policies and external regulations and prepare for audits and assessments.
  • Establishing enterprise level security governance structure, charters, participants and roles, and perform periodic role reviews to ensure appropriate accountability is maintained. 
  • Working closely with IT, legal, and business units to ensure cybersecurity governance initiatives are integrated into overall business processes.
  • Driving security-related certification efforts such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.  Drive communication and upwards reporting of the highest risk initiatives to Director of GRC, VP GRC and other key stakeholders. Generate regular reporting including KPIs, metrics and SLAs reporting, executive reporting, and other ad hoc reporting as required by management. 
  • Responsible for resolution of cybersecurity GRC issues. 
  • Serving as a trusted advisor to the business and technology stakeholders across the enterprise to partner on security issues and stay aligned on common goals.   

Requirements:

  • Experience designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry best practices (e.g., ISO 27001, NIST, COBIT).
  • Experiencing creating, reviewing and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Experience implementing cybersecurity and compliance related frameworks such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.  
  • Experience managing an enterprise cybersecurity GRC program. Experience in defining cybersecurity controls, particularly related to regulatory, legislative, and industry specific compliance requirements.
  • Ability to develop and implement security programs. 
  • Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating the resources necessary to effectively troubleshoot/diagnose complex project issues; prior success extracting/translating findings into alternatives/solutions; and identifying risks/impacts and schedule adjustments to facilitate management decision-making.
  • Advanced communication (verbal and written) and customer service skills. Strong interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management, customers, etc., including diction/terminology and presenting information in a concise and effective manner to clients, management, and various departments using assorted communication mediums.
  • Excellent stakeholder management skills. Ability to cultivate and maintain solid relationships with key stakeholders across organizational teams and third-party suppliers.

Helpful Licensing/Certifications

  • Certified Information System Security Professional (CISSP)  
  • Certified Information Security Manager (CISM) 
  • Certified Information Systems Auditor (CISA)

Work in a way that works for you

 We promote a healthy work/life balance across the organization. We offer an appealing working prospect for our people. With numerous wellbeing initiatives, shared parental leave, study assistance and sabbaticals, we will help you meet your immediate responsibilities and your long-term goals.

  • Working flexible hours - flexing the times when you work in the day to help you fit everything in and work when you are the most productive.

Working for you

We know that your wellbeing and happiness are key to a long and successful career. These are some of the benefits we are delighted to offer:

- Health Benefits: Comprehensive, multi-carrier program for medical, dental and vision benefits

- Retirement Benefits: 401(k) with match and an Employee Share Purchase Plan

- Wellbeing: Wellness platform with incentives, Headspace app subscription, Employee Assistance and Time-off Programs

- Short-and-Long Term Disability, Life and Accidental Death Insurance, Critical Illness, and Hospital Indemnity

- Family Benefits, including bonding and family care leaves, adoption and surrogacy benefits

- Health Savings, Health Care, Dependent Care and Commuter Spending Accounts

- Up to two days of paid leave each to participate in Employee Resource Groups and to volunteer with your charity of choice

About the Business

A global leader in information and analytics, we help researchers and healthcare professionals advance science and improve health outcomes for the benefit of society. Building on our publishing heritage, we combine quality information and vast data sets with analytics to support visionary science and research, health education and interactive learning, as well as exceptional healthcare and clinical practice. At Elsevier, your work contributes to the world’s grand challenges and a more sustainable future. We harness innovative technologies to support science and healthcare to partner for a better world.

-----------------------------------------------------------------------

Elsevier is an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law. We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form: https://forms.office.com/r/eVgFxjLmAK , or please contact 1-855-833-5120.

Please read our Candidate Privacy Policy.

Average salary estimate

$112500 / YEARLY (est.)
min
max
$95000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Governance and Compliance Analyst, Elsevier

Join Elsevier as a Senior Governance and Compliance Analyst in a remote capacity and take your career to the next level! In this role, you'll be at the forefront of shaping and implementing our cybersecurity governance program. Your expertise will be essential in maintaining our compliance with highly-regarded information security standards and frameworks. Imagine designing and refining cybersecurity frameworks like ISO 27001, NIST, and COBIT to create safeguards that not only protect our organization but also pave the way for a secure environment in the healthcare and research sectors. As part of a diverse GRC team, your role will involve collaborating with IT, legal, and various business units to integrate security governance into our overall business processes. You’ll be reporting on our GRC initiatives while serving as a trusted advisor on security matters. If you have a passion for managing enterprise GRC programs, are familiar with compliance requirements, and possess excellent communication and stakeholder management skills, we want to hear from you! Your insights will drive our efforts in achieving critical security certifications and ensure that our governance policies meet the highest standards of compliance. At Elsevier, we believe in a healthy work/life balance, and we're excited to embrace the contributions you will bring in this vital position.

Frequently Asked Questions (FAQs) for Senior Governance and Compliance Analyst Role at Elsevier
What does a Senior Governance and Compliance Analyst do at Elsevier?

As a Senior Governance and Compliance Analyst at Elsevier, your primary responsibility will be to lead the design and implementation of our cybersecurity governance framework. This includes ensuring compliance with various laws and regulations, conducting audits, and generating reports on cybersecurity GRC initiatives. You will also act as a trusted advisor for security issues and collaborate with cross-functional teams to achieve our compliance objectives.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Governance and Compliance Analyst position at Elsevier?

To apply for the Senior Governance and Compliance Analyst position at Elsevier, candidates typically need a deep understanding of cybersecurity frameworks like ISO 27001 and NIST. Relevant certifications such as CISSP, CISM, or CISA are preferred. Additionally, experience in managing enterprise GRC programs and defining cybersecurity controls is crucial for success in this role.

Join Rise to see the full answer
How does the Senior Governance and Compliance Analyst contribute to Elsevier's mission?

The Senior Governance and Compliance Analyst plays a crucial role in furthering Elsevier's mission by ensuring that robust cybersecurity practices are in place. By developing and maintaining a comprehensive governance framework, you help protect sensitive information, facilitating better healthcare outcomes and innovative research that aligns with our goal of advancing science and improving health.

Join Rise to see the full answer
What skills are essential for a successful Senior Governance and Compliance Analyst at Elsevier?

Key skills for a Senior Governance and Compliance Analyst at Elsevier include a strong grasp of cybersecurity frameworks, problem-solving abilities, and advanced communication skills. You should also be adept at stakeholder management and possess a strategic mindset to drive alignment with business objectives while ensuring compliance with industry standards.

Join Rise to see the full answer
What is the work schedule like for a Senior Governance and Compliance Analyst at Elsevier?

The work schedule for a Senior Governance and Compliance Analyst at Elsevier is quite flexible, as the position is remote. We support a healthy work/life balance and empower you to work during hours when you are most productive while meeting organizational needs.

Join Rise to see the full answer
Common Interview Questions for Senior Governance and Compliance Analyst
What experience do you have with implementing cybersecurity frameworks?

In answering this question, emphasize specific frameworks you've worked with, such as ISO 27001 or NIST. Share examples where you've successfully led the implementation process, detailing the challenges faced and how you overcame them to foster a robust cybersecurity culture.

Join Rise to see the full answer
How do you ensure compliance with internal policies and external regulations?

When responding, highlight your methodical approach to compliance - including regular audits, reviews of policies, and proactive communication with stakeholders. Provide examples of how you've previously maintained compliance and the tools or strategies you've used.

Join Rise to see the full answer
Can you describe a time when you resolved a cybersecurity issue?

Share a specific instance where you identified a cybersecurity challenge and the steps you took to resolve it. Discuss the measures implemented and the outcome, focusing on any improvements made to existing processes as a result of that experience.

Join Rise to see the full answer
What strategies do you use for stakeholder management?

Discuss your approach to building and maintaining relationships with key stakeholders. Share strategies such as regular updates, collaborative meetings, and open communication channels to ensure alignment on cybersecurity initiatives and policies.

Join Rise to see the full answer
How would you approach generating regular reports on GRC initiatives?

Explain your methodology for data collection and analysis, and how you prioritize key performance indicators (KPIs) that align with the organization's goals. Provide examples of types of reports you've created, focusing on how they influenced decision-making.

Join Rise to see the full answer
What do you consider the most important compliance regulations in cybersecurity?

Discuss regulations such as GDPR, HIPAA, or PCI DSS and their impact on organizational practices. Show your understanding of these regulations and their relevance to the role of a Senior Governance and Compliance Analyst.

Join Rise to see the full answer
How do you stay current with cybersecurity trends and regulatory changes?

Share your methods for ongoing education, such as attending conferences, participating in webinars, or following industry thought leaders. Highlight your commitment to continuous learning and adapting best practices.

Join Rise to see the full answer
Describe your experience with conducting audits.

Talk about your specific experience in planning and executing audits, what standards you applied, and how you reported findings to management. Be sure to mention any improvements or changes that resulted from your audit experience.

Join Rise to see the full answer
Can you give an example of how you've collaborated with IT and legal teams?

Provide an example that illustrates your ability to work cross-functionally. Detail a project involving IT and legal where you navigated concerns from both sides, leading to a successful implementation of security policies.

Join Rise to see the full answer
What challenges do you see in the field of governance and compliance?

Discuss current challenges in the cybersecurity landscape, such as evolving threats or rapid regulatory changes. Share how you approach these challenges with proactivity and innovative strategies to mitigate risks.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago

Join Elsevier as a Publishing Ethics Expert and support the integrity of research and publishing ethics with a focus on STM Journals.

Photo of the Rise User
Posted 13 days ago

Join Elsevier as a Software Engineer II to leverage your Java/Python skills in developing cutting-edge healthcare solutions.

Photo of the Rise User
Posted 10 days ago

Become a key player in research administration at the University of Michigan as a Contracts Officer, negotiating agreements for innovative projects.

Photo of the Rise User
Posted 9 days ago

We are looking for a knowledgeable Manager of Global Regulatory Affairs to guide our regulatory strategy and ensure compliance for our diverse range of products.

Photo of the Rise User
Posted 4 days ago

Join Morrison Mahoney LLP as an Associate Attorney specializing in civil litigation, with the opportunity for a hybrid work model and professional growth.

Withings Remote No location specified
Posted 2 days ago

Join Withings as a Junior Legal Counsel and support legal processes in the dynamic field of connected health.

Photo of the Rise User

Walmart is looking for a Senior Analyst in Compliance to drive eCommerce policy enforcement and risk management.

Join a leading law firm as a Business Immigration Partner, where you can drive growth and shape the future of a dynamic immigration practice.

Photo of the Rise User

Join The Very Group as a Compliance Manager to lead compliance monitoring and reporting in a dynamic environment.

Photo of the Rise User

Memorial Hermann seeks a Director of Legal Operations to drive efficiency and manage legal department operations for high-quality healthcare delivery.

Photo of the Rise User
Homecare Gurus Remote No location specified
Posted last month

Join Homecare Gurus Ltd as a remote HR Coordinator and make a significant impact in the adult social care sector.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Lead the way in advancing science, technology and health.

69 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 6, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY