GRC Analyst Intermediate
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Information Security
Job Description - GRC Analyst Intermediate (260246)
Job Number: 260246 Organization Information Technology Schedule Full-timeWork Schedule :
Normal Business Hours are 8:00am-5:00pm, M - F
Work Type :
Hybrid
Salary Range :
Targeted salary: $55,000 - $70,000 annually, based on experience
Benefits Provided :
Yes
Required Attachments :
Resume
Responsible for ensuring the organization's information systems and processes align with established cybersecurity, privacy, and regulatory standards. This role conducts in-depth security consultations and risk assessments to evaluate the effectiveness of security controls, identify vulnerabilities, and recommend mitigation strategies.
Duties- Plan, coordinate, and facilitate IT disaster recovery (DR) tests and tabletop exercises; evaluate results against requirements and document findings.
- Develop and maintain auditable evidence of implemented security measures to support compliance and assurance activities.
- Conduct privacy impact assessments (PIAs), document risks, and prepare formal reports with recommendations.
- Collect, examine, and preserve forensic images and other digital evidence using validated investigative techniques in support of research integrity investigations and incident response.
- Collaborate with vendors to coordinate incident response activities and ensure timely resolution of security events.
- Analyze digital evidence from security incidents to identify root causes, assess vulnerabilities, and recommend corrective actions.
- Review contracts, data governance requests, and system security plans (SSPs) to ensure alignment with cybersecurity, privacy, and regulatory requirements.
- Monitor relevant cybersecurity, data privacy, and legal regulations to provide informed recommendations and support compliance initiatives.
- Performs other duties as assigned.
Required
:
Bachelors Degree in Computer Science, Information Technology, or related discipline,
AND
:
- 3 years of experience in governance, risk, and compliance (GRC), cybersecurity, information assurance or related field
Equivalency/Substitution
:
Experience or a combination of education & related experience can be considered in lieu of degree. A one-to-one ratio is used to determine the number of years of experience required in place of a degree.
Skills
:
- Ability to perform effectively in high-pressure, fast-paced environment.
- In-depth understanding of cybersecurity frameworks and standards.
- Strong verbal and written communication skills, with the ability to convey complex information clearly to both technical and non-technical audiences.
- Excellent interpersonal and mentoring skills, with the ability to teach and guide others.
- Familiarity with regulatory and compliance requirements.
- Understanding of network and system architecture, including common security configurations and vulnerabilities.
- Strong analytical and problem-solving skills for identifying security risks and evaluating mitigation strategies.
- Skilled in using risk assessment and compliance tools, vulnerability scanners, and GRC platforms.
- Ability to effectively interpret and apply security policies, procedures, and technical standards.
- Ability to assess technical environments for compliance with security and privacy requirements.
- Ability to maintain confidentiality and handle sensitive information with discretion.
- Ability to adapt to changing technologies, threats, and regulatory landscapes.
Certifications
:
None
- Requires extended periods of sitting, working at a computer, and using a phone.
- Requires sound judgment under pressure and the ability to manage multiple competing priorities effectively.
- Office Work Environment.
- Occasional evening, weekend, or on-call availability during critical incidents or high-severity events.
Departmental Preferences
:
None
Special Instructions
:
If you are selected as a final candidate for this position, you will be subject to The University of Oklahoma Norman Campus Tuberculosis Testing policy. To view the policy, visit (Use the "Apply for this Job" box below). .
Why You Belong at the University of Oklahoma
:
The University of Oklahoma values our community's unique talents, perspectives,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).