GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
(GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK
- Atlanta, GA
The Governance, Risk, and Compliance (GRC) Cybersecurity Analyst is responsible for leading the assessment and oversight of business policies, procedures, and operations to ensure the organization meets internal requirements and government regulations for the protection of sensitive and critical information. GRC Analysts own complex legal, regulatory, and operational risk areas related to information assets, drive continuous risk assessment across business units, and design and implement policies, procedures, and training needed to meet or exceed internal and external requirements.
Cybersecurity Analysts are responsible for protecting the institution's information systems and data from cyber threats and vulnerabilities. This role involves monitoring security incidents, conducting risk assessments, and implementing security measures to ensure compliance with regulatory requirements and best practices in cybersecurity.
Key Responsibilities- Monitor the institution's information systems for security incidents and vulnerabilities, responding promptly to mitigate potential threats.
- Conduct regular risk assessments and security audits to identify weaknesses in the institution's cybersecurity posture and recommend remediation measures.
- Develop and implement security policies, procedures, and protocols to protect sensitive data and ensure compliance with regulatory requirements.
- Provide cybersecurity training and awareness programs for faculty, staff, and students to promote a culture of security within the institution.
- Analyze security incidents and breaches to determine their root causes and develop strategies to prevent future occurrences.
- Stay informed about emerging cybersecurity threats and trends, continuously updating security measures to address new challenges.
- Prepare and present reports on the status of cybersecurity efforts, highlighting incidents, vulnerabilities, and progress on remediation activities.
- Serve as a liaison with external agencies and partners on cybersecurity initiatives, collaborating on strategies to enhance the institution's security capabilities.
- Collaborate with IT teams to deploy security technologies, such as firewalls, intrusion detection systems, and encryption tools, to safeguard institutional data.
- Perform other duties as assigned.
- Serve as a primary point of contact for complex or sensitive cybersecurity and compliance inquiries from GTRI customers and leadership.
- Lead the development, review, and maintenance of:
- Enterprise-wide security policies, standards, practices, plans, and procedures, ensuring alignment with GTRI baseline cybersecurity requirements and University System of Georgia (USG) guidelines.
- Information technology risk assessments for systems, software, architectures, and configurations (compute, hardware/virtual, OS, storage, networking, security).
- Requests for changes to critical information systems and guide implementation of approved configuration changes.
- Cybersecurity documentation, including system security plans, and disaster recovery plans, and impact analyses (privacy, business, and security), ensuring completeness, accuracy, and currency.
- Validate security control implementation and configuration on systems to ensure compliance with requirements such as NIST, DFARS, CMMC, and related frameworks.
- Direct the creation and refinement of cybersecurity training content for GTRI personnel (e.g., security awareness, CUI training), ensuring alignment with current threats and regulatory expectations.
- Lead the development and ongoing improvement of departmental website content (articles, processes, procedures, FAQs, contacts, organizational charts,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).