Hiring.Camp

Senior Analyst, Cyber Governance, Risk and Compliance (GRC)

Higcapital

·

Today

Location
Coral Gables, United States of America
Workplace
Hybrid
Type
Full-time
Department
Legal
Seniority
Senior
Education
High School
Source
Workday

Description

Firm Overview:


H.I.G. Capital is a leading global private equity investment firm with $75 billion of assets under management with a focus on the mid cap segment of the market. The H.I.G. family of funds includes private equity, growth equity, real estate, direct lending, special situation credit, and growth-stage healthcare. We focus on providing capital to businesses with attractive growth potential and align ourselves with committed management teams and entrepreneurs to help grow businesses of significant value. Our team of over 500 investment professionals has substantial operating, consulting, technology, and financial management experience, enabling us to contribute meaningfully to our portfolio companies. H.I.G. is based in Miami, with offices in Atlanta, Boston, Chicago, Los Angeles, New York, and San Francisco, and affiliate offices in Hamburg, London, Luxembourg, Madrid, Milan, and Paris in Europe as well as Bogotá, Rio de Janeiro, and São Paulo in Latin America, Dubai in the Middle East, and Hong Kong in Asia.



Role Overview:

The Senior Cyber Governance, Risk, and Compliance (GRC) Analyst is a key member of the Cyber GRC team and the broader Information Security organization. This full-time role is responsible for supporting and advancing the organization’s cybersecurity governance, risk management, and compliance initiatives. The Senior Analyst works closely with cross-functional teams to help ensure that cybersecurity risks are identified, assessed, and managed in alignment with business objectives, regulatory requirements, and industry best practices.

This role is designed for experienced professionals who are passionate about cybersecurity risk management and committed to strengthening enterprise security programs. The Senior Cyber GRC Analyst contributes to the development, implementation, and continuous improvement of governance processes, compliance activities, and cyber risk management practices that support an effective and resilient Information Security program.

A critical expectation of this role is a strong sense of ownership, dedication, commitment, and accountability. The Senior Analyst is expected to take responsibility for assigned workstreams and deliverables from initiation through completion, proactively manage deadlines and dependencies, maintain clear and timely communication with stakeholders, and appropriately escalate risks, blockers, or delays. The successful candidate will demonstrate consistent follow-through and accountability for the quality, timeliness, and completion of their work.

In this position, the Senior Analyst will collaborate with stakeholders across technology, risk, and business teams to support security assessments, policy and control development, regulatory and framework alignment, and risk remediation efforts. This role provides the opportunity to influence and enhance the organization’s security posture while working alongside experienced cybersecurity leaders and practitioners.

Through these responsibilities, the Senior Cyber GRC Analyst plays an important role in helping the organization maintain a strong cybersecurity governance structure and ensuring that the Information Security program effectively addresses evolving threats, regulatory expectations, and business priorities.

Role Responsibilities:

Governance and Compliance

  • Support the firm’s Cyber Governance, Risk, and Compliance (GRC) program by evaluating and enhancing security controls, policies, standards, procedures, and guidelines in alignment with the organization’s reference security framework.

  • Support the alignment of the firm’s Information Security Program with recognized security frameworks and regulatory expectations (e.g., NIST CSF, ISO 27001, CIS Controls, and applicable financial regulatory requirements) by mapping controls, identifying gaps, and recommending improvements.

  • Contribute to the ongoing development and maintenance of cybersecurity policies, standards, and governance documentation, ensuring they remain aligned with evolving threats, regulatory requirements, and industry best practices.

  • Provide support for internal and external audits by coordinating documentation requests, collecting control evidence, and ensuring timely delivery of required artifacts.

  • Participate in the execution of recurring GRC program activities, including quarterly access reviews, control validation activities, and other governance processes that support compliance and risk oversight.

Risk Management and Security Program Operations

  • Conduct and support the firm’s Third-Party Risk Management (TPRM) activities by performing vendor risk assessments, evaluating security documentation, and producing risk evaluations for both new and existing third-party vendors.

  • Identify, assess, and track cybersecurity risks affecting the firm and its third parties through the organization’s cyber risk monitoring platform, and collaborate with stakeholders to support risk mitigation and remediation efforts.

  • Collaborate with technology, risk, and business teams to support security risk assessments for new initiatives, systems, and third-party integrations, ensuring cybersecurity risks are identified and addressed during project planning and implementation.

  • Assist in the preparation of cyber risk reporting and metrics for security leadership and internal stakeholders, providing visibility into the organization’s cybersecurity risk posture and control effectiveness.

  • Proactively monitor assigned deadlines and commitments, identify potential delays, risks, or blockers, and ensure timely communication and appropriate escalation to Cyber GRC leadership and relevant stakeholders.

  • Coordinate with business and technology stakeholders to follow up on GRC-related action items, ensuring that risk remediation tasks and control activities are completed within defined timelines.

  • Support and enhance the firm’s Cybersecurity Awareness Program, including monitoring training completion, engaging with users on outstanding requirements, and identifying opportunities for additional targeted training where needed.

Requirements & Qualifications:

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Management Information Systems, Engineering, or a related technical discipline from an accredited university, or a high school diploma and equivalent professional experience.

  • Demonstrated knowledge of information security principles and logical security domains, including governance, risk management, compliance, and security control frameworks.

  • Familiarity with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, or similar industry-recognized security frameworks.

  • Experience or exposure to areas such as security governance, regulatory compliance, risk assessments, third-party risk management, or security program operations.

  • Strong analytical and problem-solving abilities, with the capacity to evaluate complex situations and apply sound judgment when assessing cybersecurity risks.

  • Excellent written and verbal communication skills, with the ability to clearly document security assessments, policies, and risk findings for both technical and non-technical audiences.

  • Demonstrated ability to organize, prioritize, and manage multiple tasks and deadlines in a dynamic environment.

  • Strong interpersonal skills with the ability to collaborate effectively with technology teams, business stakeholders, and risk management functions.

  • High level of professional initiative, accountability, and self-motivation, with the ability to work independently while contributing to a collaborative team environment.

  • Strong attention to detail and commitment to maintaining high standards of accuracy, documentation quality, and program integrity.

Skills

CybersecurityRisk ManagementComplianceISO 27001

Similar Jobs

30

Cyber Analyst - Senior

Bluehawk Intelligence Services · Washington, DC, US

6 days ago

Sr. Classified Cyber Assurance Analyst

Spacex · Washington, DC +1

Yesterday

Sr. Cyber Security Analyst

Vermilionenergy · Calgary, AB, Canada

2 days ago

Senior Cyber Threat Intelligence Analyst

Keybank · 4910 Tiedeman Road, Brooklyn, OH, United States of America +1 · Remote

2 days ago

Sr. Cyber Security Analyst

10 Percent Recruiting · Remote

4 days ago

Sr. Business Analyst, Global Cyber Security

CCL/ABG · Miami, FL, United States, US

5 days ago

Senior Cyber Defense Analyst (Blue Team Lead)

Akira Technologies · Reston, VA

5 days ago

Senior Cyber Security Network Analyst (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

6 days ago

Senior Cyber Security IAM Analyst

Oneadvanced · Bengaluru, KA, IN

6 days ago

Senior Cyber Security IAM Analyst

One Advanced · Bengaluru, KA, IN

6 days ago

Senior Cyber Security Operations Analyst

Version 1 · Bengaluru, KA, India · Hybrid

1 week ago

Senior Acquisition Analyst (Cyber Security) (TS/SCI)

Koniag Government Services · Pentagon City, Arlington, VA 22202, USA

1 week ago

Senior Cyber Operations Analyst

Murdoch Careers · South Street Campus, Australia

1 week ago

Senior Cyber Defense Analyst

Professional Kyndryl · AU152333 SYDNEY (AU152333), Australia · Remote

1 week ago

Senior Cyber Security Analyst

Avant · Sydney NSW, Australia

1 week ago

Sr. Analyst I - Cyber Defense

Invesco · Hyderabad - Ranga Reddy, India

1 week ago

Senior Cyber Threat Intelligence Analyst

Job Listings · Bangalore, India

1 week ago

Senior Cyber Defense Analyst / SOC Analyst (m/w/d) | CRSCSO

Atruvia · Karlsruhe, Deutschland · Hybrid

1 week ago

Senior Principal Cyber Network Analyst

Gdit · USA VA Arlington - 2733 Crystal Dr (VAC352), United States of America

1 week ago

Senior Principal Cyber Network Analyst

GDIT · USA VA Arlington - 2733 Crystal Dr (VAC352), United States of America

1 week ago

Cyber Security Analyst Senior Advisor

GDIT · USA FL Tampa - 6801 S Dale Mabry Hwy (FLC110), United States of America

2 weeks ago

Cyber Security Analyst Senior Advisor

Gdit · USA FL Tampa - 6801 S Dale Mabry Hwy (FLC110), United States of America

2 weeks ago

Senior Cyber Threat Analyst

Raymond James · FL - Saint Petersburg - 800 Carillon Pkwy, United States of America

2 weeks ago

Senior SecOps Analyst (Cyber Defence)

Gsknch · Poznan Business Garden, Poland

2 weeks ago

Senior Cyber Threat Intelligence (CTI) Analyst

Livenation · Remote - United Kingdom +1 · Remote

2 weeks ago

Senior Cyber Software Analyst

a.i. solutions · Huntsville, AL

2 weeks ago

Cyber / Tech 2nd LOD Senior Lead Analyst, Senior Vice President

Citi Bank · GRZYBOWSKA 60, Poland · Hybrid

3 weeks ago

Cyber / Tech 2nd LOD Senior Lead Analyst, Senior Vice President

citibank · Warsaw, Masovian Voivodeship,PL, PL

3 weeks ago

Cyber Technical Analyst Sr Principal (TS/SCI with Poly Required)

GCI · Chantilly, VA

3 weeks ago

Senior Cyber Intelligence Analyst

Peraton · Honolulu, HI, US

3 weeks ago