Cybersecurity Governance Analyst

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Cybersecurity governance analyst developing enterprise policies, vendor risk assessments, and compliance controls. Supporting Agero’s digital driver assistance services through audits, remediation, and security awareness.

Responsibilities:

  • Develop and maintain enterprise cybersecurity policies and standards
  • Partner with key IT leaders to ensure security information is updated and accurate
  • Drive security awareness across the organization
  • Coordinate security assessments, identify risks, and recommend appropriate corrective action
  • Align processes with frameworks such as ISO 27001, PCI-DSS, and SOC 2
  • Perform vendor security and privacy risk assessments
  • Evaluate control environments, monitor findings, and track vendor remediation efforts
  • Respond to client security questionnaires and coordinate evidence collection
  • Support customer trust reviews and external audits
  • Provide guidance on access management, data encryption, logging, and business continuity controls
  • Investigate control deficiencies and recommend and track corrective actions
  • Liaise between business units and IT/Engineering teams to support data security implementations
  • Drive enterprise-wide security awareness programs
  • Partner with IT and Engineering leaders to refine enterprise security architecture and support security control assessment strategies

Requirements:

  • 3-5 years in information security compliance
  • Hands-on experience with PCI-DSS, SOC 2, or ISO 27001
  • Experience maintaining compliance documentation
  • Ability to map controls to technical implementations and evaluate evidence quality
  • Ability to identify, evaluate, and mitigate security risks across application, network, endpoint, and cloud environments
  • Knowledge of DevSecOps practices and emerging technologies such as AI
  • Comprehensive understanding of ISO 27001, PCI-DSS, and SOC 2 control frameworks
  • Ability to build productive relationships with IT management, technical staff, external vendors, and consultants
  • Strong written and oral communication skills
  • Ability to author technical documentation, deliver security presentations, and complete complex client security questionnaires
  • Ability to rapidly learn and apply advanced technical security concepts
  • Strong analytical skills, attention to detail, independent judgment, and effective decision-making
  • Must be currently authorized to work in the United States on a full-time basis
  • Position is not eligible for employer visa sponsorship now or in the future

Benefits:

  • Healthcare, dental, vision, disability, life insurance, and mental health benefits for associates and their families
  • 401(k) plan with company match
  • Tuition assistance
  • Flexible time off
  • Paid sick leave
  • Ten paid holidays annually
  • Parental planning benefits
  • Bonus/Incentive Programs
  • Initial onboarding travel to Medford with travel arrangements and expenses handled by Agero