×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity GRC Analyst

Job in Edina, Hennepin County, Minnesota, USA
Listing for: Western National Mutual Insurance Co
Full Time position
Listed on 2026-07-08
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 66300 - 114290 USD Yearly USD 66300.00 114290.00 YEAR
Job Description & How to Apply Below

Who are we?

Western National Insurance Group is a private mutual insurance company with over 120 years of experience serving customers' property-and-casualty insurance needs in the Midwestern, Northwestern, and Southwestern United States. Known as “The Relationship Company”, we define success as a measure of the relationships we’ve built over time. In everything that we do, we know that delivering a friendly and helpful interaction makes for a better experience for everyone involved.

That’s the power of “nice”. At Western National, nice is something we work to bring to every person and organization with whom we partner and serve.

Does this opportunity interest you?

Western National is seeking a Cybersecurity GRC Analyst to join our team!

The individual in this role will have the opportunity to strengthen the organization’s information security program by supporting regulatory compliance, managing third‑party security risk, advancing security framework maturity, leading security awareness initiatives, and delivering meaningful security metrics that enable informed business decisions.

What are the responsibilities and opportunities of this role?
  • Supports insurance‑related regulatory compliance by maintaining audit‑ready documentation and coordinating timely and accurate regulatory filings across multiple states.
  • Partners with vendor management, legal, and business stakeholders to integrate security requirements throughout the vendor lifecycle.
  • Performs security risk assessments of third‑party vendors and service providers and tracks remediation activities.
  • Maintains the vendor risk register and monitors progress toward risk mitigation objectives.
  • Serves as the Information Security Team’s primary point of contact for state insurance departments, auditors, and compliance‑related inquiries.
  • Designs, coordinates, and executes the organization’s security awareness training program.
  • Develops targeted awareness campaigns focused on phishing, social engineering, and secure behaviors across the organization.
  • Creates and distributes security awareness communications, including newsletters, alerts, and announcements.
  • Tracks training participation, measures program effectiveness, and recommends continuous improvements.
  • Maps existing security controls to recognized frameworks, such as NIST Cybersecurity Framework (CSF), CIS Controls, and NYDFS requirements.
  • Conducts security framework gap assessments and develops recommendations to improve organizational maturity.
  • Supports evidence collection for internal audits, regulatory reviews, and annual maturity assessments.
  • Defines, tracks, and reports key risk indicators (KRIs) and key performance indicators (KPIs) for the information security program.
  • Develops dashboards and reports that provide leadership visibility into security compliance, awareness, incident response, and program performance.
  • Assists information security leadership with executive reporting and board presentation materials.
  • Exercises sound judgment when identifying compliance gaps, prioritizing work, and escalating security risks.
  • Recommends process improvements that strengthen governance, documentation, compliance activities, and security awareness efforts.
  • Consistently acts according to our customer experience standards, including responding quickly, maintaining a positive attitude, building rapport, demonstrating empathy, managing the customer’s expectations, using the proper communication channel for the situation, and taking ownership to ensure the customer’s issue is resolved.
  • Performs special projects and other duties as assigned.
Requirements What are the must‑have qualifications for a candidate?
  • Two‑plus years of experience in governance, risk, and compliance (GRC); compliance; cybersecurity; or security awareness roles.
  • Strong understanding of security and regulatory frameworks, such as NIST CSF, CIS Controls, COBIT, and similar standards.
  • Experience supporting regulatory audits, evidence collection, or third‑party compliance assessments.
  • Experience conducting vendor security risk assessments and documenting remediation activities.
  • Strong understanding of governance, risk, and compliance concepts.
  • Excellent…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary